Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4639 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.15% | — | Outline ServiceAI | 30/1/2026 | 17/6/2026 | Outline Service 1.3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted binary path in C:\Program Files (x86)\Outline to inject malicious code that would execute with LocalSystem permissions… | |
| Analizada | Alta (7.1) | 0.22% | — | Danofficeit Local Admin Service | 30/1/2026 | 17/6/2026 | Improper access control in the WCF endpoint in Edgemo (now owned by Danoffice IT) Local Admin Service 1.2.7.23180 on Windows allows a local user to escalate their privileges to local administrator via direct communication with the LocalAdminService.exe named pipe, bypassing client-side group membership restrictions. | |
| Aplazada | Alta (8.5) | 0.18% | — | Forensit Appx Management ServiceAI | 28/1/2026 | 17/6/2026 | ForensiT AppX Management Service 2.2.0.4 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem… | |
| Aplazada | Alta (8.5) | 0.18% | — | Quick N Easy FTP ServiceAI | 27/1/2026 | 17/6/2026 | Quick 'n Easy FTP Service 3.2 contains an unquoted service path vulnerability that allows local attackers to execute arbitrary code during service startup. Attackers can exploit the misconfigured service binary path to inject malicious executables with elevated LocalSystem privileges during system boot or service… | |
| Aplazada | Alta (8.5) | 0.19% | — | Atheros Coex Service ApplicationAI | 27/1/2026 | 17/6/2026 | Atheros Coex Service Application 8.0.0.255 contains an unquoted service path vulnerability in its Windows service configuration. Attackers can exploit the unquoted path by placing malicious executables in the service path to gain elevated system privileges during service startup. | |
| Aplazada | Alta (8.5) | 0.20% | — | Wondershare Driver Install ServiceAI | 27/1/2026 | 17/6/2026 | Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to… | |
| Aplazada | Alta (8.5) | 0.18% | — | Acer Global Registration ServiceAI | 27/1/2026 | 17/6/2026 | Acer Global Registration Service 1.0.0.3 contains an unquoted service path vulnerability in its service configuration that allows local users to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Acer\Registration\ to inject malicious executables that would run with… | |
| Aplazada | Alta (8.5) | 0.17% | — | Dormakaba FwservicetoolAI | 26/1/2026 | 17/6/2026 | Dormakaba provides the software FWServiceTool to update the firmware version of the Access Managers via the network. The firmware in some instances is provided in an encrypted ZIP file. Within this tool, the password used to decrypt the ZIP and extract the firmware is set statically and can be extracted. This password… | |
| Aplazada | Media (5.1) | 0.59% | — | Altitude Authentication ServiceAIAltitude Communication ServerAI | 26/1/2026 | 17/6/2026 | Vulnerability in Altitude Authentication Service and Altitude Communication Server v8.5.3290.0 by Altitude, where manipulation of Host header in HTTP requests allows redirection to an arbitrary URL or modification of the base URL to trick the victim into sending login credentials to a malicious website. This behavior… | |
| Aplazada | Media (5.4) | 0.24% | — | Smartdatasoft Pool ServicesAI | 22/1/2026 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in SmartDataSoft Pool Services pool-services allows Server Side Request Forgery.This issue affects Pool Services: from n/a through <= 3.3. | |
| Aplazada | Alta (8.1) | 0.36% | — | Solvera Software Services Trade INC TeknoeraAI | 22/1/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Solvera Software Services Trade Inc. Teknoera allows File Content Injection. This issue affects Teknoera: through 01102025. | |
| Aplazada | Alta (7.5) | 0.42% | — | Solvera Software Services Trade TeknoeraAI | 22/1/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Solvera Software Services Trade Inc. Teknoera allows Exploitation of Trusted Identifiers. This issue affects Teknoera: through 01102025. | |
| Aplazada | Alta (8.5) | 0.15% | — | Hi-rez Studios HipatchserviceAI | 21/1/2026 | 17/6/2026 | Hi-Rez Studios 5.1.6.3 contains an unquoted service path vulnerability in the HiPatchService that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions. | |
| Analizada | Crítica (9.8) | 4.5% | ⚠ Explotación activa💥 PoC | Cisco Unified Communications ManagerCisco Unified Communications Manager IM AND Presence ServiceCisco Unity Connection | 21/1/2026 | 17/6/2026 | — | |
| Aplazada | Media (6.5) | 0.49% | — | Keycloak-servicesAI | 21/1/2026 | 17/6/2026 | A flaw was found in the keycloak-services component of Keycloak. This vulnerability allows the issuance of access and refresh tokens for disabled users, leading to unauthorized use of previously revoked privileges, via a business logic vulnerability in the Token Exchange implementation when a privileged client invokes… | |
| Aplazada | Media (4.2) | 0.13% | — | Oracle Planning AND Budgeting Cloud ServiceAIOracle HyperionAIOracle EPM AgentAI | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service… | |
| Analizada | Media (4.2) | 0.15% | — | Oracle Planning AND Budgeting Cloud Service | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Planning and Budgeting Cloud Service product of Oracle Hyperion (component: EPM Agent). The supported version that is affected is 25.04.07. Easily exploitable vulnerability allows high privileged attacker with logon to the infrastructure where Oracle Planning and Budgeting Cloud Service… | |
| Aplazada | Alta (8.5) | 0.18% | — | Acer Updater ServiceAI | 16/1/2026 | 17/6/2026 | Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during… | |
| Aplazada | Alta (8.5) | 0.17% | — | Diskboss ServiceAI | 16/1/2026 | 17/6/2026 | DiskBoss Service 12.2.18 contains an unquoted service path vulnerability in its binary path configuration that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path by placing malicious executables in potential path locations to gain system-level access during service… | |
| Modificada | Media (6.5) | 0.40% | — | Connectwise Professional Service Automation | 16/1/2026 | 17/6/2026 | In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values. | |
| Modificada | Media (5.4) | 0.28% | — | Connectwise Professional Service Automation | 16/1/2026 | 17/6/2026 | In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed. | |
| Aplazada | Alta (8.5) | 0.17% | — | IfunboxAIApple Mobile Device ServiceAI | 16/1/2026 | 17/6/2026 | iFunbox 4.2 contains an unquoted service path vulnerability in the Apple Mobile Device Service that allows local attackers to execute code with elevated privileges. Attackers can insert a malicious executable into the unquoted service path to run with LocalSystem privileges when the service restarts. | |
| Analizada | Media (4.8) | 0.27% | — | Cisco Identity Services Engine | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based… | |
| Analizada | Media (4.8) | 0.27% | — | Cisco Identity Services Engine | 15/1/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Identity Services Engine (ISE) and Cisco ISE Passive Identity Connector (ISE-PIC) could allow an authenticated, remote attacker to conduct cross-site scripting (XSS) attacks against a user of the interface. This vulnerability is due to insufficient… | |
| Analizada | Baja (2.9) | 0.46% | — | Redhat Hardened ImagesRedhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Enterprise Linux+3 | 15/1/2026 | 1/9/2026 | A flaw was found in the libxml2 library. This uncontrolled resource consumption vulnerability occurs when processing XML catalogs that contain repeated <nextCatalog> elements pointing to the same downstream catalog. A remote attacker can exploit this by supplying crafted catalogs, causing the parser to redundantly… |