Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 1.8% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete specific type of files and/or cause denial of service. | |
| Analizada | Media (6.5) | 1.7% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. | |
| Analizada | Alta (8.1) | 1.8% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to delete arbitrary files, thereby leading to Denial-of-Service. | |
| Analizada | Alta (8.8) | 3.2% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (8.8) | 2.6% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An Use-after-free vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (8.8) | 3.0% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (8.8) | 2.9% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (8.8) | 3.2% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (8.8) | 3.2% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Crítica (9.8) | 32% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Heap overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to execute arbitrary commands. | |
| Analizada | Alta (7.5) | 2.4% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (8.8) | 68% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (7.5) | 2.4% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Race Condition (TOCTOU) vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (8.8) | 71% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Media (6.5) | 1.7% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Null Pointer Dereference vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. | |
| Analizada | Alta (8.8) | 68% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Path Traversal vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (8.8) | 2.7% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An Unrestricted File-upload vulnerability in web component of Ivanti Avalanche before 6.4.3 allows a remote authenticated attacker to execute arbitrary commands as SYSTEM. | |
| Analizada | Media (6.5) | 1.4% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an authenticated remote attacker to read sensitive information in memory. | |
| Analizada | Alta (7.5) | 1.8% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An out-of-bounds Read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows an authenticated remote attacker to perform denial of service attacks. In certain conditions this could also lead to remote code execution. | |
| Analizada | Alta (7.5) | 2.4% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An Integer Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows an unauthenticated remote attacker to perform denial of service attacks. In certain rare conditions this could also lead to reading content from memory. | |
| Analizada | Alta (7.5) | 1.9% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. | |
| Analizada | Alta (7.5) | 1.9% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. | |
| Analizada | Alta (7.5) | 1.9% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. | |
| Analizada | Alta (7.5) | 1.9% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. | |
| Analizada | Crítica (9.8) | 3.6% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands |