Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1881 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.6)0.15%—Citrix Secure Access Client17/6/202517/6/2026
Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows
AnalizadaMedia (5.5)0.61%—Sourcecodester Downloading Client Database Management System17/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_customer_create_order.php. The manipulation of the argument user_id leads to sql injection. The attack may be initiated remotely. The…
AplazadaBaja (2)0.12%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code.
AplazadaCrítica (9.3)0.88%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the product.
AplazadaMedia (6.9)0.42%—Ricoh Streamline NX V3 PC ClientAI13/6/202517/6/2026
External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data.
AnalizadaMedia (6.5)1.4%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+1310/6/202517/6/2026
Out-of-bounds read in Remote Desktop Client allows an unauthorized attacker to disclose information over a network.
AnalizadaMedia (6.5)0.17%—Fortinet Forticlient10/6/202517/6/2026
A improper validation of certificate with host mismatch in Fortinet FortiClientWindows version 7.4.0, versions 7.2.0 through 7.2.6, and 7.0 all versions allow an unauthorized attacker to redirect VPN connections via DNS spoofing or another form of redirection.
AnalizadaMedia (4.8)0.33%—Fortinet Forticlientems10/6/202517/6/2026
An improper authentication vulnerability [CWE-287] in Fortinet FortiClientEMS version 7.4.0 and before 7.2.4 allows an unauthenticated attacker with the knowledge of the targeted user's FCTUID and VDOM to perform operations such as uploading or tagging on behalf of the targeted user via specially crafted TCP requests.
AnalizadaMedia (4.3)0.34%—Fortinet Forticlientems10/6/202517/6/2026
A server-side request forgery vulnerability [CWE-918] in Fortinet FortiClientEMS version 7.4.0 through 7.4.2 and before 7.2.6 may allow an authenticated attacker to perform internal requests via crafted HTTP or HTTPS requests.
AnalizadaMedia (6.9)0.46%💥 PoCLerouxyxchire Client Database Management System7/6/202517/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_update_customer_order.php. The manipulation of the argument uploaded_file leads to unrestricted upload. It is possible to initiate the attack remotely.
AplazadaAlta (7.3)0.10%—Zscaler Client ConnectorAI4/6/202517/6/2026
An improper verification of a loaded library in Zscaler Client Connector on Mac < 4.2.0.241 may allow a local attacker to elevate their privileges.
AnalizadaMedia (6.9)0.63%—Lerouxyxchire Client Database Management System28/5/202517/6/2026
A vulnerability was found in SourceCodester Client Database Management System 1.0. It has been declared as critical. This vulnerability affects unknown code of the file /user_order_customer_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload. The attack can be initiated…
AnalizadaAlta (7.8)0.19%—Fortinet Forticlient28/5/202517/6/2026
An Incorrect Authorization vulnerability [CWE-863] in FortiClient Mac 7.4.0 through 7.4.2, 7.2.0 through 7.2.8, 7.0.0 through 7.0.14 may allow a local attacker to escalate privileges via crafted XPC messages.
ModificadaBaja (3.7)0.55%—Fortinet Forticlient28/5/202517/6/2026
A exposure of sensitive system information to an unauthorized control sphere vulnerability in Fortinet FortiClientWindows 7.2.0 through 7.2.1, FortiClientWindows 7.0.13 through 7.0.14 may allow an unauthorized remote attacker to view application information via navigation to a hosted webpage, if Windows is configured…
AnalizadaMedia (5.1)0.42%—Lerouxyxchire Client Database Management System26/5/202517/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. Affected by this issue is some unknown functionality of the file /superadmin_update_profile.php. The manipulation of the argument nickname/email leads to sql injection. The attack may be launched…
AnalizadaMedia (5.5)0.16%💥 PoCItech-gmbh Ilabclient21/5/202517/6/2026
The local iLabClient database in itech iLabClient 3.7.1 allows local attackers to read cleartext credentials (from the CONFIGS table) for their servers configured in the client.
AplazadaAlta (7.7)0.16%💥 PoCItech-gmbh IlabclientAI21/5/202517/6/2026
itech iLabClient 3.7.1 relies on the hard-coded YngAYdgAE/kKZYu2F2wm6w== key (found in iLabClient.jar) for local users to read or write to the database.
AnalizadaMedia (6.9)0.51%—Lerouxyxchire Client Database Management System20/5/202517/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. This affects an unknown part of the file /user_proposal_update_order.php. The manipulation of the argument order_id leads to sql injection. It is possible to initiate the attack remotely. The exploit…
AnalizadaMedia (6.9)0.48%—Lerouxyxchire Client Database Management System19/5/202517/6/2026
A vulnerability, which was classified as critical, was found in SourceCodester Client Database Management System 1.0. Affected is an unknown function of the file /user_void_transaction.php. The manipulation of the argument order_id leads to sql injection. It is possible to launch the attack remotely. The exploit has…
AnalizadaMedia (6.9)0.49%—Lerouxyxchire Client Database Management System19/5/202517/6/2026
A vulnerability, which was classified as critical, has been found in SourceCodester Client Database Management System 1.0. This issue affects some unknown processing of the file /user_delivery_update.php. The manipulation of the argument uploaded_file_cancelled leads to unrestricted upload. The attack may be initiated…
AnalizadaMedia (6.9)0.51%—Lerouxyxchire Client Database Management System19/5/202517/6/2026
A vulnerability classified as critical was found in SourceCodester Client Database Management System 1.0. This vulnerability affects unknown code. The manipulation leads to exposure of information through directory listing. The attack can be initiated remotely. The exploit has been disclosed to the public and may be…
AnalizadaMedia (5.3)0.58%—Fortinet ForticlientemsFortinet Forticlientems Cloud13/5/202517/6/2026
A Relative Path Traversal vulnerability [CWE-23] in FortiClientEMS 7.4.0 through 7.4.1 and FortiClientEMS Cloud 7.4.0 through 7.4.1 may allow a remote unauthenticated attacker to perform a limited arbitrary file write on the system via upload requests.
AnalizadaAlta (7.8)0.14%—Fortinet ForticlientFortinet Fortifone Softclient13/5/202517/6/2026
An improper isolation or compartmentalization vulnerability [CWE-653] in FortiClientMac version 7.4.2 and below, version 7.2.8 and below, 7.0 all versions and FortiVoiceUCDesktop 3.0 all versions desktop application may allow an authenticated attacker to inject code via Electron environment variables.
AplazadaMedia (6.6)0.27%—SAP Gateway ClientAI13/5/202517/6/2026
Under certain conditions, SAP Gateway Client allows a high-privileged user to access restricted information beyond the scope of the application. Due to the possibility of influencing application behavior or performance through misuse of the exposed data, this may potentially lead to low impact on confidentiality,…
AplazadaAlta (7.3)0.20%—Shanghai Bairui Information Technology SunloginclientAI11/5/202517/6/2026
A vulnerability classified as critical has been found in Shanghai Bairui Information Technology SunloginClient 15.8.3.19819. This affects an unknown part in the library process.dll of the file sunlogin_guard.exe. The manipulation leads to uncontrolled search path. Local access is required to approach this attack. The…