Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

1881 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)0.42%—Lerouxyxchire Client Database Management System9/5/202517/6/2026
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter.
AnalizadaCrítica (9.8)1.2%—Lerouxyxchire Client Database Management System9/5/202517/6/2026
Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload…
AnalizadaCrítica (9.8)0.42%—Lerouxyxchire Client Database Management System9/5/202517/6/2026
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter.
AnalizadaCrítica (9.8)0.76%—Lerouxyxchire Client Database Management System9/5/202517/6/2026
SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php.
AnalizadaCrítica (9.8)0.52%—Lerouxyxchire Client Database Management System9/5/202517/6/2026
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter.
AnalizadaCrítica (9.8)0.67%—Lerouxyxchire Client Database Management System9/5/202517/6/2026
SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php.
AplazadaAlta (8.1)0.23%—Ixon VPN ClientAI7/5/202517/6/2026
IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.
AplazadaAlta (8.1)0.18%—Ixon VPN ClientAI7/5/202517/6/2026
IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten.
AplazadaMedia (6.5)0.39%—Full ClienteAI2/5/202517/6/2026
The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 to 3.1.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with…
AplazadaMedia (6.4)0.30%—Kiwichat NextclientAI2/5/202517/6/2026
The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject…
AnalizadaMedia (5.7)0.25%—Catonetworks Cato Client27/4/202517/6/2026
An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component.
AplazadaMedia (5.1)0.19%—Filez ClientAI25/4/202517/6/2026
A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user.
AnalizadaAlta (7.5)0.95%—Apache HttpclientNetapp Ontap Tools24/4/202517/6/2026
A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release
AplazadaAlta (8.1)0.14%—Filewave Windows ClientAI21/4/202517/6/2026
The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM.
AplazadaAlta (8.2)0.16%—Pritunl ClientAI19/4/202517/6/2026
In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root.
AplazadaAlta (7.1)0.29%—Clinked Client PortalAI17/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clinked Clinked Client Portal clinked-client-portal allows Reflected XSS.This issue affects Clinked Client Portal: from n/a through <= 1.10.
AplazadaAlta (7.8)0.15%—Omnissa Horizon Client FOR WindowsAI16/4/202517/6/2026
Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges.
AplazadaMedia (5.4)0.44%—Service2client LLC Dynamic PostAI16/4/202517/6/2026
Missing Authorization vulnerability in Service2Client LLC Dynamic Post dynamic-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamic Post: from n/a through <= 5.03.
ModificadaMedia (6.8)0.50%—Oracle Mysql ClusterOracle Mysql ClientNetapp Active IQ Unified ManagerNetapp Snapcenter15/4/202517/6/2026
Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client.…
AplazadaMedia (5.2)0.15%—Netskope ClientAI15/4/202517/6/2026
Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the path of the file “nsinstallation”. A standard user could potentially create a symlink of the file “nsinstallation” to escalate the privileges of a different file on the system. This issue affects…
AnalizadaMedia (6.7)0.17%—Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+2579/4/202517/6/2026
Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution.
AnalizadaAlta (8)1.5%—Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+138/4/202517/6/2026
Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network.
AnalizadaMedia (4.8)0.36%—Fortinet Forticlientems8/4/202517/6/2026
An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code.
AplazadaMedia (5.3)0.37%—FCJ Venture Builder AppclientefielAI8/4/202517/6/2026
A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /rest/cliente/ObterPedido/ of the component HTTP GET Request Handler. The manipulation of the argument ORDER_ID leads to improper control…
AplazadaMedia (6.4)0.34%—Think201 ClientsAI3/4/202517/6/2026
Missing Authorization vulnerability in Think201 Clients clients allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clients: from n/a through <= 1.1.4.