Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.36% | — | Boldgrid Sprout ClientsAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in BoldGrid Sprout Clients sprout-clients allows Stored XSS.This issue affects Sprout Clients: from n/a through <= 3.2. | |
| Aplazada | Media (6.5) | 0.36% | — | Dxladner Client ShowcaseAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dxladner Client Showcase client-showcase allows Stored XSS.This issue affects Client Showcase: from n/a through <= 1.2.0. | |
| Aplazada | Media (5.1) | 0.75% | — | MydumperAILibmysqlclientAI | 1/4/2025 | 17/6/2026 | MyDumper is a MySQL Logical Backup Tool. The MySQL C client library (libmysqlclient) allows authenticated remote actors to read arbitrary files from client systems via a crafted server response to LOAD LOCAL INFILE query, leading to sensitive information disclosure when clients connect to untrusted MySQL servers… | |
| Analizada | Media (6.8) | 0.18% | — | Mskcc Oauth2 Client | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal OAuth2 Client allows Cross Site Request Forgery.This issue affects OAuth2 Client: from 0.0.0 before 4.1.3. | |
| Aplazada | Media (6.3) | 0.14% | — | Watchguard Mobile VPN With SSL ClientAI | 28/3/2025 | 8/8/2026 | The WatchGuard Mobile VPN with SSL Client on Windows does not properly configure directory permissions when installed in a non-default directory. This could allow an authenticated local attacker to escalate to SYSTEM privileges on a vulnerable system. | |
| Analizada | Media (6.1) | 0.29% | — | Fortinet Forticlientems | 28/3/2025 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation in FortiClientEMS version 6.2.0 may allow a remote attacker to execute unauthorized code by injecting malicious payload in the user profile of a FortiClient instance being managed by the vulnerable system. | |
| Aplazada | Media (5.9) | 0.29% | — | HCL Digital ExperienceAIHCL Ring APIAIHCL DxclientAI | 20/3/2025 | 17/6/2026 | HCL Digital Experience components Ring API and dxclient may be vulnerable to man-in-the-middle (MitM) attacks prior to 9.5 CF226. An attacker could intercept and potentially alter communication between two parties. | |
| Analizada | Alta (7.8) | 0.27% | — | Fortinet Forticlient | 14/3/2025 | 17/6/2026 | An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process. | |
| Analizada | Alta (8.8) | 3.2% | — | Microsoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+12 | 11/3/2025 | 17/6/2026 | Relative path traversal in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.30% | — | Ivanti Secure Access Client | 11/3/2025 | 17/6/2026 | Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. | |
| Aplazada | Alta (8.6) | 0.13% | — | Qnap Qvpn Device ClientAIQnap QsyncAIQnap Qfinder PROAI | 7/3/2025 | 17/6/2026 | A time-of-check time-of-use (TOCTOU) race condition vulnerability has been reported to affect several product versions. If exploited, the vulnerability could allow local attackers who have gained user access to gain access to otherwise unauthorized resources. We have already fixed the vulnerability in the following… | |
| Analizada | Alta (7.8) | 0.18% | — | Cisco Secure Client | 5/3/2025 | 17/6/2026 | A vulnerability in the interprocess communication (IPC) channel of Cisco Secure Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the Secure Firewall Posture Engine, formerly HostScan, is installed on Cisco Secure Client. This vulnerability is… | |
| Analizada | Alta (8.8) | 0.41% | — | Whmpress Whmcs Client Area | 28/2/2025 | 17/6/2026 | The WHMPress - WHMCS Client Area plugin for WordPress is vulnerable to unauthorized modification of data that can lead to privilege escalation due to a missing capability check on the update_settings case in the /admin/ajax.php file in all versions up to, and including, 4.3-revision-3. This makes it possible for… | |
| Aplazada | Media (5.4) | 0.28% | — | AVE System WEB ClientAI | 27/2/2025 | 17/6/2026 | AVE System Web Client v2.1.131.13992 was discovered to contain a cross-site scripting (XSS) vulnerability. | |
| Analizada | Media (5.9) | 0.16% | — | Citrix Secure Access Client | 20/2/2025 | 17/6/2026 | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac | |
| Analizada | Media (5.9) | 0.16% | — | Citrix Secure Access Client | 20/2/2025 | 17/6/2026 | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac | |
| Analizada | Alta (8.2) | 0.17% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M16 R2 Firmware+388 | 19/2/2025 | 17/6/2026 | Dell Client Platform BIOS contains a Weak Authentication vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Alta (8.5) | 0.17% | — | Bestinformed InfoclientAIBestinformed WEBAICordaware BestinformedAI | 18/2/2025 | 17/6/2026 | An attacker is able to escalate his privileges to "nt authority\system" on the Windows client running the "bestinformed Infoclient". This attack is not possible if a custom configuration ("Infoclient.ini") containing the flags "ShowOnTaskbar=false" or "DisabledItems=stPort,stAddress" is deployed. | |
| Aplazada | Media (4.5) | 0.19% | — | Freedom OF THE Press Foundation Securedrop ClientAI | 13/2/2025 | 17/6/2026 | The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to versions 0.14.1 and 1.0.1, an attacker who has already gained code execution in a virtual machine on the SecureDrop Workstation could gain code execution in the… | |
| Aplazada | Alta (8.1) | 1.0% | — | Securedrop ClientAI | 13/2/2025 | 17/6/2026 | The SecureDrop Client is a desktop application for journalists to communicate with sources and work with submissions on the SecureDrop Workstation. Prior to version 0.14.1, a malicious SecureDrop Server could obtain code execution on the SecureDrop Client virtual machine (`sd-app`). SecureDrop Server itself has… | |
| Analizada | Media (5.6) | 0.23% | — | Cisco Anyconnect Secure Mobility Client | 12/2/2025 | 17/6/2026 | A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by… | |
| Aplazada | Crítica (9.3) | 0.25% | — | Lexmark Print Management ClientAI | 11/2/2025 | 17/6/2026 | A Reliance on Untrusted Inputs in a Security Decision vulnerability has been identified in the Lexmark Print Management Client. | |
| Analizada | Alta (8.4) | 0.24% | — | Fortinet Forticlient | 11/2/2025 | 17/6/2026 | An improper authentication in Fortinet FortiClientMac 7.0.11 through 7.2.4 allows attacker to gain improper access to MacOS via empty password. | |
| Analizada | Media (6.7) | 0.25% | 💥 PoC | Fortinet Forticlient | 11/2/2025 | 17/6/2026 | An Improper Access Control vulnerability [CWE-284] in FortiClient Windows version 7.4.0, version 7.2.6 and below, version 7.0.13 and below may allow a local user to escalate his privileges via FortiSSLVPNd service pipe. | |
| Analizada | Alta (7.1) | 0.21% | — | Ivanti Secure Access Client | 11/2/2025 | 17/6/2026 | Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files. |