Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.16% | — | Netcloud Exchange ClientAI | 28/11/2024 | 17/6/2026 | The NetCloud Exchange client for Windows, version 1.110.50, contains an insecure file and folder permissions vulnerability. A normal (non-admin) user could exploit the weakness in file and folder permissions to escalate privileges, execute arbitrary code and maintain persistence on the compromised machine. It has been… | |
| Analizada | Media (5.4) | 0.27% | — | Phpgurukul Client Management System | 20/11/2024 | 17/6/2026 | Cross-Site Scripting (XSS) vulnerabilities in Anuj Kumar's Client Management System Version 1.2 allow local attackers to inject arbitrary web script or HTML via the search input field parameter to admin search invoice page and client search invoice page. | |
| Aplazada | Media (6.5) | 0.39% | — | Wordpresteem WE Client Logo CarouselAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wordpresteem WE – Client Logo Carousel we-client-logo-carousel allows Stored XSS.This issue affects WE – Client Logo Carousel: from n/a through <= 1.4. | |
| Analizada | Alta (7.8) | 0.46% | — | Fortinet Forticlient | 13/11/2024 | 17/6/2026 | A authentication bypass using an alternate path or channel in Fortinet FortiClientWindows version 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0, and 6.4.10 through 6.4.0 allows low privilege attacker to execute arbitrary code with high privilege via spoofed named pipe messages. | |
| Analizada | Media (4.4) | 0.28% | — | Ivanti Secure Access Client | 13/11/2024 | 17/6/2026 | Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service. | |
| Analizada | Alta (7.8) | 0.32% | — | Ivanti Secure Access Client | 13/11/2024 | 17/6/2026 | Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Media (4.7) | 0.30% | — | Ivanti Secure Access Client | 13/11/2024 | 17/6/2026 | A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files. | |
| Analizada | Media (6.7) | 0.13% | — | Fortinet Forticlient | 12/11/2024 | 17/6/2026 | An improper verification of cryptographic signature vulnerability [CWE-347] in FortiClient MacOS version 7.4.0, version 7.2.4 and below, version 7.0.10 and below, version 6.4.10 and below may allow a local authenticated attacker to swap the installer with a malicious package via a race condition during the… | |
| Analizada | Alta (8.8) | 0.22% | — | Fortinet Forticlient | 12/11/2024 | 17/6/2026 | A privilege context switching error vulnerability [CWE-270] in FortiClient Windows version 7.2.4 and below, version 7.0.12 and below, 6.4 all versions may allow an authenticated user to escalate their privileges via lua auto patch scripts. | |
| Analizada | Alta (7.8) | 0.28% | — | Fortinet Forticlient | 12/11/2024 | 17/6/2026 | A untrusted search path in Fortinet FortiClientWindows versions 7.4.0, versions 7.2.4 through 7.2.0, versions 7.0.12 through 7.0.0 allows an attacker to run arbitrary code via DLL hijacking and social engineering. | |
| Aplazada | Media (4.8) | 0.32% | — | Secusuite Secure Client Authentication SCA ServerAI | 12/11/2024 | 17/6/2026 | An insufficient entropy vulnerability in the SecuSUITE Secure Client Authentication (SCA) Server of SecuSUITE versions 5.0.420 and earlier could allow an attacker to potentially enroll an attacker-controlled device to the victim’s account and telephone number. | |
| Analizada | Media (5.5) | 0.26% | — | Ivanti Secure Access Client | 12/11/2024 | 17/6/2026 | A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service. | |
| Analizada | Baja (3.3) | 0.21% | — | Ivanti Secure Access Client | 12/11/2024 | 17/6/2026 | Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders. | |
| Analizada | Alta (7.1) | 0.22% | — | Ivanti Secure Access Client | 12/11/2024 | 17/6/2026 | Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files. | |
| Analizada | Alta (7.8) | 0.26% | — | Ivanti Secure Access Client | 12/11/2024 | 17/6/2026 | Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Media (4.3) | 0.47% | — | Sensiolabs Httpclient | 6/11/2024 | 17/6/2026 | symfony/http-client is a module for the Symphony PHP framework which provides powerful methods to fetch HTTP resources synchronously or asynchronously. When using the `NoPrivateNetworkHttpClient`, some internal information is still leaking during host resolution, which leads to possible IP/port enumeration. As of… | |
| Modificada | Media (6.1) | 0.31% | — | Samglover Client Power Tools | 29/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Sam Glover Client Power Tools Portal client-power-tools allows Reflected XSS.This issue affects Client Power Tools Portal: from n/a through <= 1.9.0. | |
| Analizada | Media (6.5) | 0.62% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 23/10/2024 | 17/6/2026 | A vulnerability in Internet Key Exchange version 2 (IKEv2) processing of Cisco Secure Client Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) of Cisco Secure Client. This vulnerability is due to an integer underflow condition. An attacker could exploit this vulnerability by… | |
| Analizada | Alta (7.5) | 0.51% | — | Phpgurukul Client Management System | 22/10/2024 | 17/6/2026 | Client Management System 1.0 was discovered to contain a SQL injection vulnerability via the Between Dates Reports parameter at /admin/bwdates-reports-ds.php. | |
| Aplazada | Media (6.1) | 0.39% | — | Full ClienteAI | 11/10/2024 | 17/6/2026 | The FULL – Cliente plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of add_query_arg & remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 3.1.22. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages… | |
| Analizada | Media (4.3) | 0.58% | — | SAP Hana-client | 8/10/2024 | 17/6/2026 | The SAP HANA Node.js client package versions from 2.0.0 before 2.21.31 is impacted by Prototype Pollution vulnerability allowing an attacker to add arbitrary properties to global object prototypes. This is due to improper user input sanitation when using the nestTables feature causing low impact on the availability of… | |
| Aplazada | Media (6.5) | 0.25% | — | Bplugins Logo Carousel Clients Logo Carousel FOR WPAI | 5/10/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in bPlugins Logo Carousel – Clients logo carousel for WP responsive-client-logo-carousel-slider allows Stored XSS.This issue affects Logo Carousel – Clients logo carousel for WP: from n/a through <= 1.2. | |
| Analizada | Crítica (9.3) | 0.51% | — | Shilpisoft Client Dashboard | 4/10/2024 | 17/6/2026 | This vulnerability exists in Shilpi Client Dashboard due to missing restrictions for incorrect login attempts on its API based login. A remote attacker could exploit this vulnerability by conducting a brute force attack on password, which could lead to gain unauthorized access to other user accounts. | |
| Analizada | Alta (8.6) | 0.69% | — | Shilpisoft Client Dashboard | 4/10/2024 | 17/6/2026 | This vulnerability exists in the Shilpi Client Dashboard due to improper validation of files being uploaded other than the specified extension. An authenticated remote attacker could exploit this vulnerability by uploading malicious file, which could lead to remote code execution on targeted application. | |
| Analizada | Alta (7.1) | 0.49% | — | Shilpisoft Client Dashboard | 4/10/2024 | 17/6/2026 | This vulnerability exists in Shilpi Client Dashboard due to lack of rate limiting and Captcha protection for OTP requests in certain API endpoint. An unauthenticated remote attacker could exploit this vulnerability by sending multiple OTP request through vulnerable API endpoints, which could lead to the OTP bombing on… |