Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.42% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_payment_update.php via the order_id POST parameter. | |
| Analizada | Crítica (9.8) | 1.2% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | Arbitrary File Upload in user_payment_update.php in SourceCodester Client Database Management System 1.0 allows unauthenticated users to upload arbitrary files via the uploaded_file_cancelled field. Due to the absence of proper file extension checks, MIME type validation, and authentication, attackers can upload… | |
| Analizada | Crítica (9.8) | 0.42% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_delivery_update.php via the order_id POST parameter. | |
| Analizada | Crítica (9.8) | 0.76% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to Remote code execution via Arbitrary file upload in user_proposal_update_order.php. | |
| Analizada | Crítica (9.8) | 0.52% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in user_order_customer_update.php via the order_id POST parameter. | |
| Analizada | Crítica (9.8) | 0.67% | — | Lerouxyxchire Client Database Management System | 9/5/2025 | 17/6/2026 | SourceCodester Client Database Management System 1.0 is vulnerable to SQL Injection in superadmin_phpmyadmin.php. | |
| Aplazada | Alta (8.1) | 0.23% | — | Ixon VPN ClientAI | 7/5/2025 | 17/6/2026 | IXON VPN Client before 1.4.4 on Windows allows Local Privilege Escalation to SYSTEM because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten. | |
| Aplazada | Alta (8.1) | 0.18% | — | Ixon VPN ClientAI | 7/5/2025 | 17/6/2026 | IXON VPN Client before 1.4.4 on Linux and macOS allows Local Privilege Escalation to root because there is code execution from a configuration file that can be controlled by a low-privileged user. There is a race condition in which a temporary configuration file, in a world-writable directory, can be overwritten. | |
| Aplazada | Media (6.5) | 0.39% | — | Full ClienteAI | 2/5/2025 | 17/6/2026 | The FULL – Cliente plugin for WordPress is vulnerable to SQL Injection via the 'formId' parameter in all versions 3.1.5 to 3.1.25 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Media (6.4) | 0.30% | — | Kiwichat NextclientAI | 2/5/2025 | 17/6/2026 | The KiwiChat NextClient plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘url’ parameter in all versions up to, and including, 6.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Contributor-level access and above, to inject… | |
| Analizada | Media (5.7) | 0.25% | — | Catonetworks Cato Client | 27/4/2025 | 17/6/2026 | An issue in CatoNetworks CatoClient before v.5.8.0 allows attackers to escalate privileges and achieve a race condition (TOCTOU) via the PrivilegedHelperTool component. | |
| Aplazada | Media (5.1) | 0.19% | — | Filez ClientAI | 25/4/2025 | 17/6/2026 | A cross-site scripting vulnerability was reported in the FileZ client that could allow execution of code if a crafted url is visited by a local user. | |
| Analizada | Alta (7.5) | 0.95% | — | Apache HttpclientNetapp Ontap Tools | 24/4/2025 | 17/6/2026 | A bug in PSL validation logic in Apache HttpClient 5.4.x disables domain checks, affecting cookie management and host name verification. Discovered by the Apache HttpClient team. Fixed in the 5.4.3 release | |
| Aplazada | Alta (8.1) | 0.14% | — | Filewave Windows ClientAI | 21/4/2025 | 17/6/2026 | The FileWave Windows client before 16.0.0, in some non-default configurations, allows an unprivileged local user to escalate privileges to SYSTEM. | |
| Aplazada | Alta (8.2) | 0.16% | — | Pritunl ClientAI | 19/4/2025 | 17/6/2026 | In Pritunl Client before 1.3.4220.57, an administrator with access to /Applications can escalate privileges after uninstalling the product. Specifically, an administrator can insert a new file at the pathname of the removed pritunl-service file. This file then is executed by a LaunchDaemon as root. | |
| Aplazada | Alta (7.1) | 0.29% | — | Clinked Client PortalAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Clinked Clinked Client Portal clinked-client-portal allows Reflected XSS.This issue affects Clinked Client Portal: from n/a through <= 1.10. | |
| Aplazada | Alta (7.8) | 0.15% | — | Omnissa Horizon Client FOR WindowsAI | 16/4/2025 | 17/6/2026 | Omnissa Horizon Client for Windows contains an LPE Vulnerability. A malicious actor with local access where Horizon Client for Windows is installed may be able to elevate privileges. | |
| Aplazada | Media (5.4) | 0.44% | — | Service2client LLC Dynamic PostAI | 16/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Service2Client LLC Dynamic Post dynamic-post allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Dynamic Post: from n/a through <= 5.03. | |
| Modificada | Media (6.8) | 0.50% | — | Oracle Mysql ClusterOracle Mysql ClientNetapp Active IQ Unified ManagerNetapp Snapcenter | 15/4/2025 | 17/6/2026 | Vulnerability in the MySQL Client product of Oracle MySQL (component: Client: mysqldump). Supported versions that are affected are 8.0.0-8.0.41, 8.4.0-8.4.4 and 9.0.0-9.2.0. Difficult to exploit vulnerability allows low privileged attacker with network access via multiple protocols to compromise MySQL Client.… | |
| Aplazada | Media (5.2) | 0.15% | — | Netskope ClientAI | 15/4/2025 | 17/6/2026 | Netskope Client on Mac OS is impacted by a vulnerability in which the postinstall script does not properly validate the path of the file “nsinstallation”. A standard user could potentially create a symlink of the file “nsinstallation” to escalate the privileges of a different file on the system. This issue affects… | |
| Analizada | Media (6.7) | 0.17% | — | Dell Latitude 3140 2in1 FirmwareDell Latitude 3320 FirmwareDell Latitude 3330 FirmwareDell Latitude 3340 Firmware+257 | 9/4/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Stack-based Buffer Overflow Vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to arbitrary code execution. | |
| Analizada | Alta (8) | 1.5% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 8/4/2025 | 17/6/2026 | Heap-based buffer overflow in Remote Desktop Client allows an authorized attacker to execute code over a network. | |
| Analizada | Media (4.8) | 0.36% | — | Fortinet Forticlientems | 8/4/2025 | 17/6/2026 | An improper neutralization of input during web page generation ('Cross-site Scripting') [CWE-79] vulnerability in Fortinet FortiClient before 7.4.1 may allow the EMS administrator to send messages containing javascript code. | |
| Aplazada | Media (5.3) | 0.37% | — | FCJ Venture Builder AppclientefielAI | 8/4/2025 | 17/6/2026 | A vulnerability was found in FCJ Venture Builder appclientefiel 3.0.27. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /rest/cliente/ObterPedido/ of the component HTTP GET Request Handler. The manipulation of the argument ORDER_ID leads to improper control… | |
| Aplazada | Media (6.4) | 0.34% | — | Think201 ClientsAI | 3/4/2025 | 17/6/2026 | Missing Authorization vulnerability in Think201 Clients clients allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clients: from n/a through <= 1.1.4. |