Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)1.8%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service.
AnalizadaMedia (6.5)1.7%—Ivanti Avalanche19/4/202417/6/2026
A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
AnalizadaAlta (8.1)1.8%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, thereby leading to Denial-of-Service.
AnalizadaAlta (8.8)3.2%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (8.8)2.6%—Ivanti Avalanche19/4/202417/6/2026
An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (8.8)3.0%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (8.8)2.9%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (8.8)3.2%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (8.8)3.2%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaCrítica (9.8)32%—Ivanti Avalanche19/4/202417/6/2026
A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands.
AnalizadaAlta (7.5)2.4%—Ivanti Avalanche19/4/202417/6/2026
A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (8.8)68%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (7.5)2.4%—Ivanti Avalanche19/4/202417/6/2026
A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (8.8)71%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaMedia (6.5)1.7%—Ivanti Avalanche19/4/202417/6/2026
A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks.
AnalizadaAlta (8.8)68%—Ivanti Avalanche19/4/202417/6/2026
A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaAlta (8.8)2.7%—Ivanti Avalanche19/4/202417/6/2026
An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM.
AnalizadaMedia (6.5)1.4%—Ivanti Avalanche19/4/202417/6/2026
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory.
AnalizadaAlta (7.5)1.8%—Ivanti Avalanche19/4/202417/6/2026
An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution.
AnalizadaAlta (7.5)2.4%—Ivanti Avalanche19/4/202417/6/2026
An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory.
AnalizadaAlta (7.5)1.9%—Ivanti Avalanche19/4/202417/6/2026
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
AnalizadaAlta (7.5)1.9%—Ivanti Avalanche19/4/202417/6/2026
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
AnalizadaAlta (7.5)1.9%—Ivanti Avalanche19/4/202417/6/2026
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
AnalizadaAlta (7.5)1.9%—Ivanti Avalanche19/4/202417/6/2026
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
AnalizadaCrítica (9.8)3.6%—Ivanti Avalanche19/4/202417/6/2026
A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
Orbitaley — Vulnerabilidades