Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.3) | 0.35% | — | Netmod VPN ClientAI | 6/2/2025 | 17/6/2026 | NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries. | |
| Aplazada | Alta (7.8) | 0.17% | — | Omnissa Horizon Client MacosAI | 4/2/2025 | 17/6/2026 | Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed. | |
| Aplazada | Alta (7.8) | 0.19% | 💥 PoC | Omnissa Horizon Client FOR MacosAI | 4/2/2025 | 17/6/2026 | Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed. | |
| Analizada | Media (6.1) | 0.18% | — | Phptechie WP Projects Portfolio With Client Testimonials | 4/2/2025 | 17/6/2026 | The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack. | |
| Analizada | Media (6.1) | 0.58% | 💥 Exploit | Phptechie WP Projects Portfolio With Client Testimonials | 4/2/2025 | 17/6/2026 | The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Aplazada | Media (6.4) | 0.30% | — | Clinked Client PortalAI | 30/1/2025 | 17/6/2026 | The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-login-button' shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated… | |
| Aplazada | Media (5.2) | 0.18% | — | RegclientAI | 29/1/2025 | 17/6/2026 | regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1. | |
| Aplazada | Media (6.4) | 0.27% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 27/1/2025 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.1. | |
| Aplazada | Alta (8.5) | 0.15% | — | Gdata Security ClientAI | 25/1/2025 | 17/6/2026 | Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in execution by the… | |
| Aplazada | Crítica (9.1) | 0.81% | — | Northern.tech Mender ClientAI | 21/1/2025 | 17/6/2026 | Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions. | |
| Aplazada | Alta (7.1) | 0.17% | — | Cstoltenkamp Free Mailclient FMCAI | 16/1/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in cstoltenkamp Free MailClient FMC mailclient allows Stored XSS.This issue affects Free MailClient FMC: from n/a through <= 1.0. | |
| Aplazada | Alta (7.7) | 0.51% | — | Amazon WorkspacesAIAmazon Appstream 2.0AIAmazon DCV ClientsAI | 15/1/2025 | 17/6/2026 | An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle. | |
| Analizada | Baja (3.3) | 0.22% | — | Fortinet Forticlient | 14/1/2025 | 17/6/2026 | A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped. | |
| Analizada | Media (5.3) | 0.73% | — | Fortinet ForticlientemsFortinet Fortisoar | 14/1/2025 | 17/6/2026 | An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing… | |
| Analizada | Media (5.3) | 0.51% | — | Fortinet ForticlientemsFortinet Forticlientems Cloud | 14/1/2025 | 17/6/2026 | An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection. | |
| Analizada | Crítica (9.8) | 0.96% | — | Fortinet Forticlientems | 14/1/2025 | 17/6/2026 | An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests. | |
| Analizada | Media (5.3) | 0.65% | — | Revmakx Infinitewp Client | 8/1/2025 | 17/6/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory. | |
| Aplazada | Alta (7.2) | 1.6% | — | 501 Wireless Client BridgeAI | 7/1/2025 | 17/6/2026 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Aplazada | Alta (7.2) | 1.6% | — | 501 Wireless Client BridgeAI | 7/1/2025 | 17/6/2026 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Analizada | Alta (7.8) | 0.23% | — | Fortinet Forticlient | 19/12/2024 | 17/6/2026 | An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine. | |
| Analizada | Media (5) | 0.14% | — | Fortinet Forticlient | 18/12/2024 | 17/6/2026 | A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local authenticated user to retrieve VPN password via memory dump,… | |
| Aplazada | Alta (7.3) | 0.23% | — | CA Client AutomationAICA ItcmAI | 17/12/2024 | 17/6/2026 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf… | |
| Aplazada | Alta (8.1) | 0.33% | — | Chunghwa Telecom Topm-clientAI | 16/12/2024 | 17/6/2026 | The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing.… | |
| Aplazada | Media (6.5) | 0.30% | — | Chunghwa Telecom Topm-clientAI | 16/12/2024 | 17/6/2026 | The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing.… | |
| Aplazada | Alta (7.1) | 0.30% | — | Chunghwa Telecom Tbm-clientAI | 16/12/2024 | 17/6/2026 | The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally,… |