Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
1877 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.3) | 0.27% | — | IBM I Access FamilyAIIBM I Access Client SolutionsAI | 14/9/2026 | 17/9/2026 | IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command. | |
| Pendiente de análisis | Alta (7.5) | 0.13% | — | Zscaler Client ConnectorAI | 14/9/2026 | 18/9/2026 | On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture. | |
| Pendiente de análisis | Alta (8.1) | 0.18% | — | Zscaler Client ConnectorAIGoogle AndroidAIGoogle ChromeosAI | 14/9/2026 | 18/9/2026 | An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls. | |
| Pendiente de análisis | Alta (8.1) | 0.38% | — | Zscaler Client ConnectorAI | 14/9/2026 | 18/9/2026 | A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process. | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Netskope ClientAI | 11/9/2026 | 18/9/2026 | An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation,… | |
| Aplazada | Alta (8.5) | 0.10% | — | Lenovo Filez ClientAI | 10/9/2026 | 11/9/2026 | A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges. | |
| Pendiente de análisis | Media (6) | 0.11% | — | Netskope ClientAINetskope Endpoint DLPAI | 10/9/2026 | 18/9/2026 | Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could… | |
| Pendiente de análisis | Media (5) | 0.20% | — | Okta Privileged Access ClientAIOkta ScaleftAI | 8/9/2026 | 10/9/2026 | The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended… | |
| Aplazada | Crítica (9.2) | 0.34% | — | Eclipse Ditto Javascript Client NodeAIEclipse Ditto Javascript Client Node 1AI | 8/9/2026 | 9/9/2026 | In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the… | |
| Analizada | Alta (7.5) | 0.64% | — | Microsoft Remote Desktop Client | 8/9/2026 | 16/9/2026 | Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.82% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (8.8) | 0.86% | — | Microsoft Remote Desktop Client | 8/9/2026 | 22/9/2026 | Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Pendiente de análisis | Media (5.1) | 0.14% | — | Fortinet Forticlient WindowsAI | 8/9/2026 | 2/10/2026 | A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port. | |
| Aplazada | Alta (8.6) | 0.19% | — | Siemens Desigo CC Clickonce ClientAISiemens Desigo CC Flex ClientAISiemens Desigo CC Installed ClientAISiemens Desigo CCAI | 8/9/2026 | 14/9/2026 | A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All… | |
| Pendiente de análisis | Alta (7.8) | 0.36% | — | SAP Netweaver Business ClientAI | 8/9/2026 | 9/9/2026 | SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is… | |
| Pendiente de análisis | Crítica (9.4) | 0.67% | — | Ixon VPN ClientAI | 4/9/2026 | 8/9/2026 | Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows… | |
| Pendiente de análisis | Alta (8.7) | 1.5% | — | Yast2 Auth ClientAI | 1/9/2026 | 2/9/2026 | A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba net ads join, net ads lookup -S and net ads testjoin invocations… | |
| Pendiente de análisis | Alta (7.5) | 0.48% | — | Yast2-samba-clientAI | 1/9/2026 | 2/9/2026 | Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being… | |
| Aplazada | Alta (7.8) | 0.33% | — | Backblaze ClientAIMicrosoft WindowsAI | 1/9/2026 | 11/9/2026 | A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls.… | |
| Aplazada | Alta (7.5) | 0.39% | — | Surefeedback Client SiteAI | 27/8/2026 | 28/8/2026 | Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions. | |
| Aplazada | Alta (8.8) | 2.0% | — | Teamviewer Full ClientAITeamviewer HostAI | 26/8/2026 | 1/9/2026 | A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking… | |
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Aplazada | Media (5.8) | 0.61% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… |