Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
5089 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.8) | 0.31% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in the IKEv2 feature of Cisco Secure Firewall ASA Software and Cisco Secure FTD Software could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device that may also impact the availability of services to devices elsewhere in the network. This vulnerability is due to… | |
| Analizada | Media (5.3) | 0.40% | — | Cisco Adaptive Security Appliance Software | 4/3/2026 | 17/6/2026 | A vulnerability in the implementation of the proprietary SSH stack with SSH key-based authentication in Cisco Secure Firewall Adaptive Security Appliance (ASA) Software could allow an unauthenticated, remote attacker to log in to a Cisco Secure Firewall ASA device and execute commands as a specific user. This… | |
| Analizada | Media (6) | 0.14% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 4/3/2026 | 11/8/2026 | A vulnerability in a small subset of CLI commands that are used on Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an authenticated, local attacker to craft Lua code that could be used on the underlying operating system as root.… | |
| Analizada | Crítica (9.8) | 0.41% | — | Renren-security | 3/3/2026 | 17/6/2026 | renren-secuity before v5.5.0 is vulnerable to SQL Injection in the BaseServiceImpl.java component | |
| En análisis | Media (6.2) | 0.10% | — | Trellix Endpoint Security | 24/2/2026 | 17/6/2026 | A vulnerability identified in the HX Agent driver file fekern.sys allowed a threat actor with local user access the ability to gain elevated system privileges. Utilization of a Bring Your Own Vulnerable Driver (BYOVD) was leveraged to gain access to the critical Windows process memory lsass.exe (Local Security… | |
| Analizada | Media (5.7) | 0.37% | — | Tenable Security Center | 23/2/2026 | 17/6/2026 | An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. | |
| Analizada | Baja (2.1) | 0.38% | — | Tenable Security Center | 23/2/2026 | 17/6/2026 | An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. | |
| Aplazada | Media (6.5) | 0.41% | — | Getshieldsecurity Shield SecurityAI | 19/2/2026 | 17/6/2026 | The Shield Security plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 21.0.8. This is due to the plugin allowing nonce verification to be bypassed via user-supplied parameter in the 'isNonceVerifyRequired' function. This makes it possible for unauthenticated… | |
| Aplazada | Media (6.1) | 0.58% | 💥 Exploit | Getshieldsecurity Shield SecurityAI | 19/2/2026 | 17/6/2026 | The Shield Security plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'message' parameter in all versions up to, and including, 21.0.8 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Aplazada | Media (4.3) | 0.21% | — | Getshieldsecurity Shield SecurityAI | 19/2/2026 | 17/6/2026 | The Shield Security: Blocks Bots, Protects Users, and Prevents Security Breaches plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the `MfaEmailDisable` action in all versions up to, and including, 21.0.9. This makes it possible for authenticated attackers,… | |
| Analizada | Alta (8.8) | 0.20% | — | IBM Security Qradar EDR | 17/2/2026 | 17/6/2026 | IBM Security QRadar EDR 3.12 through 3.12.23 does not invalidate session after a session expiration which could allow an authenticated user to impersonate another user on the system. | |
| Aplazada | Alta (7.4) | 1.8% | — | Tenable Security CenterAI | 17/2/2026 | 17/6/2026 | A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted. | |
| Aplazada | Media (6.5) | 0.28% | — | Shield Security Custom Content BY CountryAI | 17/2/2026 | 17/6/2026 | Missing Authorization vulnerability in Paul Custom Content by Country (by Shield Security) custom-content-by-country.This issue affects Custom Content by Country (by Shield Security): from n/a through 3.1.2. | |
| Aplazada | Media (5.6) | 0.10% | — | Intel Converged Security AND Management Engine FirmwareAI | 10/2/2026 | 17/6/2026 | Out-of-bounds read in the firmware for some Intel(R) Converged Security and Management Engine (CSME) Firmware (FW) within Ring 0: Kernel may allow an information disclosure. System software adversary with a privileged user combined with a low complexity attack may enable data exposure. This result may potentially… | |
| Aplazada | Alta (8.8) | 0.27% | — | Ergosis Security Systems Computer Industry AND Trade INC Zeus PdksAI | 10/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Ergosis Security Systems Computer Industry and Trade Inc. ZEUS PDKS allows SQL Injection. This issue affects ZEUS PDKS: from <1.0.5.10 through 10022026. NOTE: The vendor was contacted early about this disclosure but… | |
| Analizada | Media (4.3) | 0.21% | — | SAP S/4hana Defense & Security | 10/2/2026 | 17/6/2026 | Due to a missing authorization check in the Disconnected Operations of the SAP S/4HANA Defense & Security, an attacker with user privileges could call remote-enabled function modules to do direct update on standard SAP database table . This results in low impact on integrity, with no impact on confidentiality or… | |
| Analizada | Media (6.3) | 0.39% | — | Stepsecurity Harden-runner | 9/2/2026 | 17/6/2026 | Harden-Runner is a CI/CD security agent that works like an EDR for GitHub Actions runners. Prior to 2.14.2, a security vulnerability has been identified in the Harden-Runner GitHub Action (Community Tier) that allows outbound network connections to evade audit logging. Specifically, outbound traffic using the sendto,… | |
| Aplazada | Alta (8.7) | 0.47% | — | ACE Security Wip-90113 HD CameraAI | 7/2/2026 | 17/6/2026 | ACE Security WiP-90113 HD Camera contains a configuration disclosure vulnerability that allows unauthenticated attackers to retrieve sensitive configuration files. Attackers can access the camera's configuration backup by sending a GET request to the /config_backup.bin endpoint, exposing credentials and system… | |
| Analizada | Alta (8.2) | 0.21% | — | F5 Big-ip Advanced WEB Application FirewallF5 Big-ip Application Security Manager | 4/2/2026 | 17/6/2026 | When a BIG-IP Advanced WAF or ASM security policy is configured on a virtual server, undisclosed requests along with conditions beyond the attacker's control can cause the bd process to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Baja (2.7) | 0.35% | — | Hillstone Networks Operation AND Maintenance Security GatewayAI | 4/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Hillstone Networks Operation and Maintenance Security Gateway on Linux allows Upload a Web Shell to a Web Server.This issue affects Operation and Maintenance Security Gateway: V5.5ST00001B113. | |
| Analizada | Alta (7.8) | 0.12% | — | Quickheal Total Security | 3/2/2026 | 17/6/2026 | A vulnerability exists in Quick Heal Total Security 23.0.0 in the quarantine management component where insufficient validation of restore paths and improper permission handling allow a low-privileged local user to restore quarantined files into protected system directories. This behavior can be abused by a local… | |
| Aplazada | Crítica (9.6) | 0.92% | 💥 PoC | Aliasrobotics Cybersecurity AIAI | 30/1/2026 | 17/6/2026 | Cybersecurity AI (CAI) is a framework for AI Security. In versions up to and including 0.5.10, the CAI (Cybersecurity AI) framework contains multiple argument injection vulnerabilities in its function tools. User-controlled input is passed directly to shell commands via `subprocess.Popen()` with `shell=True`, allowing… | |
| Analizada | Alta (7.5) | 0.52% | — | Redhat Open Security Issue Management | 29/1/2026 | 17/6/2026 | The $uri$args concatenation in nginx configuration file present in Open Security Issue Management (OSIM) prior v2025.9.0 allows path traversal attacks via query parameters. | |
| Analizada | Media (4.8) | 0.35% | — | Opensecurity Mobile Security Framework | 27/1/2026 | 17/6/2026 | MobSF is a mobile application security testing tool used. Prior to version 4.4.5, a Stored Cross-site Scripting (XSS) vulnerability in MobSF's Android manifest analysis allows an attacker to execute arbitrary JavaScript in the context of a victim's browser session by uploading a malicious APK. The `android:host`… |