Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
3323 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.17% | — | Paloaltonetworks Idira Privilege Cloud Connector | 12/6/2026 | 23/6/2026 | Idira Vendor PAM - Self-Hosted Connector versions prior 1.1.100504 under specific conditions and configuration scenarios, TLS certificate validation may not be fully enforced. CyberArk Security Bulletin: CA26-17 | |
| Analizada | Media (4.7) | 0.24% | — | Connectwise Screenconnect | 10/6/2026 | 18/8/2026 | In ScreenConnect™ versions prior to 26.2, input validation within the Host Pass creation functionality could allow an authenticated user with Host Pass creation privileges the ability to specify a token expiration duration beyond the intended maximum when generating delegated access tokens. | |
| Pendiente de análisis | Alta (7.3) | 0.16% | — | Lenovo Smart ConnectAI | 10/6/2026 | 17/6/2026 | A potential authentication bypass was reported in Lenovo Smart Connect for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Aplazada | Alta (8.4) | 0.13% | — | Slate Digital ConnectAI | 10/6/2026 | 17/6/2026 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by obtaining the client's process identifier and using it to retrieve… | |
| Aplazada | Alta (8.4) | 0.12% | — | Slate Digital ConnectAI | 10/6/2026 | 17/6/2026 | Slate Digital Connect 1.37.0 for macOS installs a privileged helper tool, com.slatedigital.connect.privileged.helper.tool, which exposes the XPC service com.slatedigital.connect.privileged.helper.tool2. The helper validates connecting XPC clients by checking only the subject.OU value of the client's signing… | |
| Analizada | Crítica (9.8) | 77% | ⚠ Explotación activa💥 Exploit | Progress Connection Manager FOR ObjectscaleProgress ECS Connection ManagerProgress Moveit WEB Application FirewallProgress Loadmaster | 4/6/2026 | 1/10/2026 | OS Command Injection Remote Code Execution Vulnerability in API in Progress ADC Products allows an un-authenticated attacker to execute arbitrary commands on the LoadMaster appliance by exploiting unsanitized input in multiple command endpoints | |
| Analizada | Media (6.9) | 0.31% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Fixed AES-128-CBC keys inside the AcerConnect OTA application let attackers forge authorization credentials for arbitrary IMEI numbers. This allows unauthorized actors to list catalog items and extract protected binaries from pre-signed cloud links. | |
| Analizada | Alta (8.8) | 0.44% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The registration path /v1/account/register provides no bot mitigation mechanisms, allowing malicious automated systems to flood the database. | |
| Analizada | Media (6.9) | 0.40% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The web administration panel binds broadly to the public IPv6 address space on port [::]:8080 without default firewall limits, making internal API endpoints reachable over the WAN. | |
| Analizada | Crítica (9.3) | 0.25% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The /v1/Plan service relies entirely on a shared global API token for full administrative management, allowing arbitrary creation of zero-cost network access plans. | |
| Analizada | Alta (8.7) | 0.39% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The account validation endpoint /v1/User/validate returns comprehensive user profile data sheets, which can be crawled by iterating predictable identification strings. | |
| Analizada | Alta (7.1) | 0.27% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Weak validation logic within device dissociation API routines allows a remote entity to forcefully unbind unrelated user endpoints, causing severe denial of service. | |
| Analizada | Alta (8.8) | 0.52% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Leftover engineering diagnostics and factory-level diagnostic software remain exposed on retail builds, giving malicious apps write privileges to internal NVRAM registers. | |
| Analizada | Media (6.9) | 0.42% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The device encrypts data using AES-CBC with static zero-filled Initialization Vectors (IVs), making it susceptible to replay attacks and known-plaintext decryption. | |
| Analizada | Crítica (9.3) | 0.14% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Broadcast events allow malicious software to rewrite the device's default Mobile Device Management (MDM) endpoint address, shifting administrative ownership to an external attacker. | |
| Analizada | Crítica (9.2) | 0.24% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | High-risk TrustAllCerts routines disable standard TLS certificate validation. Combined with hard-coded DES symmetric encryption keys, a Man-in-the-Middle (MITM) actor could decrypt network traffic. | |
| Analizada | Alta (8.5) | 0.18% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The system Binder boundary accepts unverified pass-through AT commands, giving local applications the power to read baseband files or disable cellular connectivity. | |
| Analizada | Alta (8.5) | 1.6% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Incoming VPN network profile settings fail to process special characters safely, enabling command injection via malicious config files. | |
| Analizada | Alta (8.8) | 0.41% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | System log files output unencrypted SMTP server authentication passwords alongside sensitive employee corporate identification data. | |
| Analizada | Media (6.9) | 0.27% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Leftover debug modules contain fixed credentials for internal AWS Cognito test sandboxes, risking asset exploitation. | |
| Analizada | Alta (7.2) | 0.28% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Crucial management API endpoints for cellular eSIM allocation do not validate caller authorization, allowing remote profiles to be rewritten or deleted. | |
| Analizada | Alta (8.8) | 0.45% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Internal multimedia session archives are accessible without authentication, exacerbated by loose Cross-Origin Resource Sharing (CORS) rules that allow cross-site theft. | |
| Analizada | Crítica (9.4) | 0.42% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The debugging routine SCREEN_CLICK(5053) enables a connection to skip the standard device login prompt entirely and directly enter an interactive shell interface. | |
| Analizada | Alta (8.7) | 0.42% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | Overly permissive configuration settings on cloud storage containers expose active telemetry information publicly to the internet. | |
| Analizada | Media (5.3) | 0.23% | — | Acer Connect M6E 5G Firmware | 4/6/2026 | 22/7/2026 | The summary service endpoint suffers from an IDOR vulnerability where it fails to verify user ownership of hardware serial numbers, exposing device data to scraping. |