Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

1881 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.3)0.35%—Netmod VPN ClientAI6/2/202517/6/2026
NetMod VPN Client 5.3.1 is vulnerable to DLL injection, allowing an attacker to execute arbitrary code by placing a malicious DLL in a directory where the application loads dependencies. This vulnerability arises due to the improper validation of dynamically loaded libraries.
AplazadaAlta (7.8)0.17%—Omnissa Horizon Client MacosAI4/2/202517/6/2026
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a flaw in the installation process. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.
AplazadaAlta (7.8)0.19%💥 PoCOmnissa Horizon Client FOR MacosAI4/2/202517/6/2026
Omnissa Horizon Client for macOS contains a Local privilege escalation (LPE) Vulnerability due to a logic flaw. Successful exploitation of this issue may allow attackers with user privileges to escalate their privileges to root on the system where the Horizon Client for macOS is installed.
AnalizadaMedia (6.1)0.18%—Phptechie WP Projects Portfolio With Client Testimonials4/2/202517/6/2026
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not have CSRF check in some places, and is missing sanitisation as well as escaping, which could allow attackers to make logged in admin add Stored XSS payloads via a CSRF attack.
AnalizadaMedia (6.1)0.58%💥 ExploitPhptechie WP Projects Portfolio With Client Testimonials4/2/202517/6/2026
The WP Projects Portfolio with Client Testimonials WordPress plugin through 3.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaMedia (6.4)0.30%—Clinked Client PortalAI30/1/202517/6/2026
The Clinked Client Portal plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'clinked-login-button' shortcode in all versions up to, and including, 1.9 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated…
AplazadaMedia (5.2)0.18%—RegclientAI29/1/202517/6/2026
regclient is a Docker and OCI Registry Client in Go. A malicious registry could return a different digest for a pinned manifest without detection. This vulnerability is fixed in 0.7.1.
AplazadaMedia (6.4)0.27%—Webventures Client Invoicing BY Sprout InvoicesAI27/1/202517/6/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.1.
AplazadaAlta (8.5)0.15%—Gdata Security ClientAI25/1/202517/6/2026
Local privilege escalation in G DATA Security Client due to incorrect assignment of privileges to directories. This vulnerability allows a local, unprivileged attacker to escalate privileges on affected installations by placing an arbitrary executable in a globally writable directory resulting in execution by the…
AplazadaCrítica (9.1)0.81%—Northern.tech Mender ClientAI21/1/202517/6/2026
Northern.tech Mender Client 4.x before 4.0.5 has Insecure Permissions.
AplazadaAlta (7.1)0.17%—Cstoltenkamp Free Mailclient FMCAI16/1/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in cstoltenkamp Free MailClient FMC mailclient allows Stored XSS.This issue affects Free MailClient FMC: from n/a through <= 1.0.
AplazadaAlta (7.7)0.51%—Amazon WorkspacesAIAmazon Appstream 2.0AIAmazon DCV ClientsAI15/1/202517/6/2026
An issue in the native clients for Amazon WorkSpaces (when running Amazon DCV protocol), Amazon AppStream 2.0, and Amazon DCV Clients may allow an attacker to access remote sessions via man-in-the-middle.
AnalizadaBaja (3.3)0.22%—Fortinet Forticlient14/1/202517/6/2026
A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped.
AnalizadaMedia (5.3)0.73%—Fortinet ForticlientemsFortinet Fortisoar14/1/202517/6/2026
An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing…
AnalizadaMedia (5.3)0.51%—Fortinet ForticlientemsFortinet Forticlientems Cloud14/1/202517/6/2026
An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection.
AnalizadaCrítica (9.8)0.96%—Fortinet Forticlientems14/1/202517/6/2026
An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests.
AnalizadaMedia (5.3)0.65%—Revmakx Infinitewp Client8/1/202517/6/2026
The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory.
AplazadaAlta (7.2)1.6%—501 Wireless Client BridgeAI7/1/202517/6/2026
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying…
AplazadaAlta (7.2)1.6%—501 Wireless Client BridgeAI7/1/202517/6/2026
Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying…
AnalizadaAlta (7.8)0.23%—Fortinet Forticlient19/12/202417/6/2026
An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine.
AnalizadaMedia (5)0.14%—Fortinet Forticlient18/12/202417/6/2026
A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local authenticated user to retrieve VPN password via memory dump,…
AplazadaAlta (7.3)0.23%—CA Client AutomationAICA ItcmAI17/12/202417/6/2026
CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf…
AplazadaAlta (8.1)0.33%—Chunghwa Telecom Topm-clientAI16/12/202417/6/2026
The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing.…
AplazadaMedia (6.5)0.30%—Chunghwa Telecom Topm-clientAI16/12/202417/6/2026
The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing.…
AplazadaAlta (7.1)0.30%—Chunghwa Telecom Tbm-clientAI16/12/202417/6/2026
The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally,…