Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.3) | 0.22% | — | Fortinet Forticlient | 14/1/2025 | 17/6/2026 | A use of hard-coded cryptographic key in Fortinet FortiClientWindows version 7.4.0, 7.2.x all versions, 7.0.x all versions, and 6.4.x all versions may allow a low-privileged user to decrypt interprocess communication via monitoring named piped. | |
| Analizada | Media (5.3) | 0.73% | — | Fortinet ForticlientemsFortinet Fortisoar | 14/1/2025 | 17/6/2026 | An observable response discrepancy vulnerability [CWE-204] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, and FortiSOAR 7.5.0, 7.4.0 through 7.4.4, 7.3.0 through 7.3.2, 7.2 all versions, 7.0 all versions, 6.4 all versions may allow an unauthenticated attacker to enumerate valid users via observing… | |
| Analizada | Media (5.3) | 0.51% | — | Fortinet ForticlientemsFortinet Forticlientems Cloud | 14/1/2025 | 17/6/2026 | An improper verification of source of a communication channel vulnerability [CWE-940] in FortiClientEMS 7.4.0, 7.2.0 through 7.2.4, 7.0 all versions, 6.4 all versions may allow a remote attacker to bypass the trusted host feature via session connection. | |
| Analizada | Crítica (9.8) | 0.96% | — | Fortinet Forticlientems | 14/1/2025 | 17/6/2026 | An improper restriction of excessive authentication attempts [CWE-307] in FortiClientEMS version 7.2.0 through 7.2.4 and before 7.0.10 allows an unauthenticated attacker to try a brute force attack against the FortiClientEMS console via crafted HTTP or HTTPS requests. | |
| Analizada | Media (5.3) | 0.65% | — | Revmakx Infinitewp Client | 8/1/2025 | 17/6/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to Path Traversal in all versions up to, and including, 1.13.0 via the 'historyID' parameter of the ~/debug-chart/index.php file. This makes it possible for unauthenticated attackers to read .txt files outside of the intended directory. | |
| Aplazada | Alta (7.2) | 1.6% | — | 501 Wireless Client BridgeAI | 7/1/2025 | 17/6/2026 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Aplazada | Alta (7.2) | 1.6% | — | 501 Wireless Client BridgeAI | 7/1/2025 | 17/6/2026 | Multiple command injection vulnerabilities exist in the web interface of the 501 Wireless Client Bridge which could lead to authenticated remote command execution. Successful exploitation of these vulnerabilities result in the ability of an attacker to execute arbitrary commands as a privileged user on the underlying… | |
| Analizada | Alta (7.8) | 0.23% | — | Fortinet Forticlient | 19/12/2024 | 17/6/2026 | An execution with unnecessary privileges vulnerability in the VCM engine of FortiClient for Linux versions 6.2.7 and below, version 6.4.0. may allow local users to elevate their privileges to root by creating a malicious script or program on the target machine. | |
| Analizada | Media (5) | 0.14% | — | Fortinet Forticlient | 18/12/2024 | 17/6/2026 | A Cleartext Storage of Sensitive Information vulnerability [CWE-312] in FortiClientWindows 7.4.0 through 7.4.1, 7.2.0 through 7.2.6, 7.0.0 through 7.0.13 and FortiClientLinux 7.4.0 through 7.4.2, 7.2.0 through 7.2.7, 7.0.0 through 7.0.13 may permit a local authenticated user to retrieve VPN password via memory dump,… | |
| Aplazada | Alta (7.3) | 0.23% | — | CA Client AutomationAICA ItcmAI | 17/12/2024 | 17/6/2026 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf… | |
| Aplazada | Alta (8.1) | 0.33% | — | Chunghwa Telecom Topm-clientAI | 16/12/2024 | 17/6/2026 | The topm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing.… | |
| Aplazada | Media (6.5) | 0.30% | — | Chunghwa Telecom Topm-clientAI | 16/12/2024 | 17/6/2026 | The topm-client from Chunghwa Telecom has an Arbitrary File Read vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection for the APIs, unauthenticated remote attackers could use these APIs through phishing.… | |
| Aplazada | Alta (7.1) | 0.30% | — | Chunghwa Telecom Tbm-clientAI | 16/12/2024 | 17/6/2026 | The tbm-client from Chunghwa Telecom has an Arbitrary File vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing. Additionally,… | |
| Aplazada | Alta (8.1) | 0.33% | — | Chunghwa Telecom Tbm-clientAI | 16/12/2024 | 17/6/2026 | The tbm-client from Chunghwa Telecom has an Arbitrary File Delete vulnerability. The application sets up a simple local web server and provides APIs for communication with the target website. Due to the lack of CSRF protection in the APIs, unauthenticated remote attackers could use these APIs through phishing.… | |
| Aplazada | Media (6.5) | 0.41% | — | Think201 ClientsAI | 13/12/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Think201 Clients clients allows Stored XSS.This issue affects Clients: from n/a through <= 1.1.4. | |
| Aplazada | Crítica (9) | 1.3% | — | Mullvad VPN ClientAI | 12/12/2024 | 17/6/2026 | In the Mullvad VPN client 2024.6 (Desktop), 2024.8 (iOS), and 2024.8-beta1 (Android), the exception-handling alternate stack can be exhausted, leading to heap-based out-of-bounds writes in enable() in exception_logging/unix.rs, aka MLLVD-CR-24-01. NOTE: achieving code execution is considered non-trivial. | |
| Analizada | Alta (8.4) | 1.5% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1507Microsoft Windows 10 1607+13 | 12/12/2024 | 17/6/2026 | Remote Desktop Client Remote Code Execution Vulnerability | |
| Aplazada | Baja (3.3) | 0.19% | — | SAP Product Lifecycle Costing ClientAI | 10/12/2024 | 17/6/2026 | SAP Product Lifecycle Costing Client (versions below 4.7.1) application loads on demand a DLL that is available with Windows OS. This DLL is loaded from the computer running SAP Product Lifecycle Costing Client application. That particular DLL could be replaced by a malicious one, that could execute commands as being… | |
| Aplazada | Media (4.2) | 0.24% | — | Redhat Single Sign ONAIRedhat Jboss Enterprise Application PlatformAIRedhat Oidc ClientAI | 9/12/2024 | 4/8/2026 | A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a… | |
| Aplazada | Media (6.8) | 0.18% | — | Altair Graphql ClientAI | 9/12/2024 | 17/6/2026 | Altair is a GraphQL client for all platforms. Prior to version 8.0.5, Altair GraphQL Client's desktop app does not validate HTTPS certificates allowing a man-in-the-middle to intercept all requests. Any Altair users on untrusted networks (eg. public wifi, malicious DNS servers) may have all GraphQL request and… | |
| Aplazada | Media (5.3) | 0.49% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 9/12/2024 | 17/6/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.0. | |
| Aplazada | Crítica (9.2) | 0.64% | — | AsynchttpclientAI | 2/12/2024 | 17/6/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When making any HTTP request, the automatically enabled and self-managed CookieStore (aka cookie jar) will silently replace explicitly defined Cookies with any that have the same name… | |
| Aplazada | Alta (8.2) | 0.14% | — | IBM ZhmcclientAI | 29/11/2024 | 17/6/2026 | zhmcclient is a pure Python client library for the IBM Z HMC Web Services API. In affected versions the Python package "zhmcclient" writes password-like properties in clear text into its HMC and API logs in the following cases: 1. The 'boot-ftp-password' and 'ssc-master-pw' properties when creating or updating a… | |
| Aplazada | Media (5.5) | 0.19% | — | Withsecure Elements AgentAIWithsecure MDRAIWithsecure Elements Client SecurityAI | 29/11/2024 | 17/6/2026 | WithSecure Elements Agent for Mac before 24.3, MDR before 24.3, and Elements Client Security for Mac before 16.10 allow a remote Denial of Service. | |
| Aplazada | Media (4.6) | 0.20% | — | Easy TAX Client SoftwareAI | 29/11/2024 | 17/6/2026 | A XML External Entity (XXE) vulnerability has been identified in Easy Tax Client Software 2023 1.2 and earlier across multiple platforms, including Windows, Linux, and macOS. |