Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.15% | — | Citrix Secure Access Client | 17/6/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows | |
| Analizada | Media (5.5) | 0.61% | — | Sourcecodester Downloading Client Database Management System | 17/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The… | |
| Aplazada | Baja (2) | 0.12% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code. | |
| Aplazada | Crítica (9.3) | 0.88% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the product. | |
| Aplazada | Media (6.9) | 0.42% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data. | |
| Analizada | Media (6.5) | 1.4% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 10/6/2025 | 17/6/2026 | Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Media (6.5) | 0.17% | — | Fortinet Forticlient | 10/6/2025 | 17/6/2026 | A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection. | |
| Analizada | Media (4.8) | 0.33% | — | Fortinet Forticlientems | 10/6/2025 | 17/6/2026 | An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests. | |
| Analizada | Media (4.3) | 0.34% | — | Fortinet Forticlientems | 10/6/2025 | 17/6/2026 | A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests. | |
| Analizada | Media (6.9) | 0.46% | 💥 PoC | Lerouxyxchire Client Database Management System | 7/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file leads to unrestricted upload. It is possible to initiate the attack remotely. | |
| Aplazada | Alta (7.3) | 0.10% | — | Zscaler Client ConnectorAI | 4/6/2025 | 17/6/2026 | An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges. | |
| Analizada | Media (6.9) | 0.63% | — | Lerouxyxchire Client Database Management System | 28/5/2025 | 17/6/2026 | A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_order_customer_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload. The attack can be initiated… | |
| Analizada | Alta (7.8) | 0.19% | — | Fortinet Forticlient | 28/5/2025 | 17/6/2026 | An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a local attacker to escalate privileges via crafted XPC messages. | |
| Modificada | Baja (3.7) | 0.55% | — | Fortinet Forticlient | 28/5/2025 | 17/6/2026 | A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured… | |
| Analizada | Media (5.1) | 0.42% | — | Lerouxyxchire Client Database Management System | 26/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. Affected by this issue is some unknown functionality of the file /superadmin_update_profile.php. The manipulation of the argument nickname/email leads to sql injection. The attack may be launched… | |
| Analizada | Media (5.5) | 0.16% | 💥 PoC | Itech-gmbh Ilabclient | 21/5/2025 | 17/6/2026 | The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client. | |
| Aplazada | Alta (7.7) | 0.16% | 💥 PoC | Itech-gmbh IlabclientAI | 21/5/2025 | 17/6/2026 | itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database. | |
| Analizada | Media (6.9) | 0.51% | — | Lerouxyxchire Client Database Management System | 20/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. The manipulation of the argument order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit… | |
| Analizada | Media (6.9) | 0.48% | — | Lerouxyxchire Client Database Management System | 19/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /user_void_transaction.php. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotely. The exploit has… | |
| Analizada | Media (6.9) | 0.49% | — | Lerouxyxchire Client Database Management System | 19/5/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_delivery_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload. The attack may be initiated… | |
| Analizada | Media (6.9) | 0.51% | — | Lerouxyxchire Client Database Management System | 19/5/2025 | 17/6/2026 | A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be… | |
| Analizada | Media (5.3) | 0.58% | — | Fortinet ForticlientemsFortinet Forticlientems Cloud | 13/5/2025 | 17/6/2026 | A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests. | |
| Analizada | Alta (7.8) | 0.14% | — | Fortinet ForticlientFortinet Fortifone Softclient | 13/5/2025 | 17/6/2026 | An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables. | |
| Aplazada | Media (6.6) | 0.27% | — | SAP Gateway ClientAI | 13/5/2025 | 17/6/2026 | Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on confidentiality,… | |
| Aplazada | Alta (7.3) | 0.20% | — | Shanghai Bairui Information Technology SunloginclientAI | 11/5/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Shanghai Bairui Information Technology SunloginClient 15.8.3.19819. This affects an unknown part in the library process.dll of the file sunlogin_guard.exe. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The… |