Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

1877 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.3)0.27%—IBM I Access FamilyAIIBM I Access Client SolutionsAI14/9/202617/9/2026
IBM i Access Family 1.1.2.0 through 1.1.9.15 IBM i Access Client Solutions could allow an authenticated user to execute arbitrary commands with normal user privileges on the system due to improper validation of user supplied input in a STRPCCMD CL command.
Pendiente de análisisAlta (7.5)0.13%—Zscaler Client ConnectorAI14/9/202618/9/2026
On affected versions of Zscaler client connector, a pre-installed peer app can tear down the Zscaler tunnel, force user logout, and toggle packet capture.
Pendiente de análisisAlta (8.1)0.18%—Zscaler Client ConnectorAIGoogle AndroidAIGoogle ChromeosAI14/9/202618/9/2026
An improper input validation vulnerability in Zscaler Client Connector on Android and ChromeOS allows an attacker to potentially bypass Zscaler controls.
Pendiente de análisisAlta (8.1)0.38%—Zscaler Client ConnectorAI14/9/202618/9/2026
A race condition in the ZPA tunnel handler of affected versions of Zscaler Client Connector (ZCC) allows a heap corruption, resulting in a denial of service (client crash) and potentially arbitrary code execution in the context of the ZCC process.
Pendiente de análisisMedia (6.8)0.10%—Netskope ClientAI11/9/202618/9/2026
An information leakage vulnerability exists in the Endpoint DLP component (epdlpdrv.sys) of Netskope Client for Windows prior to version R141. An internal communication channel used by the user-space hook DLL to pass messages through the kernel driver to the daemon lacked proper token-based message validation,…
AplazadaAlta (8.5)0.10%—Lenovo Filez ClientAI10/9/202611/9/2026
A potential improper permissions vulnerability was reported in the Lenovo Filez Client application that could allow a local authenticated user to escalate privileges.
Pendiente de análisisMedia (6)0.11%—Netskope ClientAINetskope Endpoint DLPAI10/9/202618/9/2026
Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could…
Pendiente de análisisMedia (5)0.20%—Okta Privileged Access ClientAIOkta ScaleftAI8/9/202610/9/2026
The Okta Privileged Access client URL handler does not insert an option terminator before appending the target value to the command-line arguments. When a scaleft:// protocol handler link contains a value beginning with a hyphen, the underlying CLI framework interprets it as a command-line flag, causing unintended…
AplazadaCrítica (9.2)0.34%—Eclipse Ditto Javascript Client NodeAIEclipse Ditto Javascript Client Node 1AI8/9/20269/9/2026
In Eclipse Ditto's Node.js JavaScript client, all released versions of @eclipse-ditto/ditto-javascript-client-node from 2.0.0 to 3.9.0 and of its predecessor package @eclipse-ditto/ditto-javascript-client-node_1.0 from 1.0.0 to 2.1.0, the WebSocket transport hard-codes rejectUnauthorized: false when creating the…
AnalizadaAlta (7.5)0.64%—Microsoft Remote Desktop Client8/9/202616/9/2026
Improper verification of cryptographic signature in Windows RDP Client allows an unauthorized attacker to disclose information over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop Client8/9/202622/9/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop Client8/9/202622/9/2026
Heap-based buffer overflow in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (8.8)0.86%—Microsoft Remote Desktop Client8/9/202622/9/2026
Improper control of generation of code ('code injection') in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
Pendiente de análisisMedia (5.1)0.14%—Fortinet Forticlient WindowsAI8/9/20262/10/2026
A unverified ownership vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.7, FortiClientWindows 7.2 all versions may allow attacker to improper access control via via an exposed minifilter communication port.
AplazadaAlta (8.6)0.19%—Siemens Desigo CC Clickonce ClientAISiemens Desigo CC Flex ClientAISiemens Desigo CC Installed ClientAISiemens Desigo CCAI8/9/202614/9/2026
A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All…
Pendiente de análisisAlta (7.8)0.36%—SAP Netweaver Business ClientAI8/9/20269/9/2026
SAP NetWeaver Business Client does not perform sufficient validation when processing certain locally stored data during application startup. An attacker with low privileges on the local system could replace this data with specially crafted content. When the application is next launched, the crafted content is…
Pendiente de análisisCrítica (9.4)0.67%—Ixon VPN ClientAI4/9/20268/9/2026
Improper neutralization of CRLF sequences in IXON VPN Client before version 1.4.7 allows an attacker to execute commands as root or SYSTEM. Configuration values accepted by the local service are written to a file later consumed by a privileged subprocess, without line-ending sequences being neutralized, which allows…
Pendiente de análisisAlta (8.7)1.5%—Yast2 Auth ClientAI1/9/20262/9/2026
A OS command injection vulnerability in yast2-auth-client allows an attacker who controls Active Directory configuration values to execute arbitrary commands as root on the configured host. Auth::AuthConf in src/lib/auth/authconf.rb assembles the Samba net ads join, net ads lookup -S and net ads testjoin invocations…
Pendiente de análisisAlta (7.5)0.48%—Yast2-samba-clientAI1/9/20262/9/2026
Improper neutralization of special elements used in an OS command in yast2-samba-client allows an attacker who controls the content of an Active Directory directory tree - a rogue domain controller, or a directory user delegated the right to create objects - to execute arbitrary commands as root on a machine being…
AplazadaAlta (7.8)0.33%—Backblaze ClientAIMicrosoft WindowsAI1/9/202611/9/2026
A vulnerability in the Backblaze Client allows a local user to make the system not bootable by creating a link from Backblaze's folder to Windows OS system files during a backup. Successful exploitation requires an administrator-level system change that results in the absence of specific Windows OS security controls.…
AplazadaAlta (7.5)0.39%—Surefeedback Client SiteAI27/8/202628/8/2026
Subscriber Sensitive Data Exposure in SureFeedback Client Site <= 1.2.12 versions.
AplazadaAlta (8.8)2.0%—Teamviewer Full ClientAITeamviewer HostAI26/8/20261/9/2026
A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking…
AplazadaAlta (8.5)0.16%—Skysea Client ViewAISkymec IT ManagerAI25/8/202628/8/2026
SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege.
AplazadaMedia (5.8)0.61%—Skysea Client ViewAISkymec IT ManagerAI25/8/202628/8/2026
A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product…
AplazadaMedia (5.8)0.65%—Skysea Client ViewAISkygroup Skymec IT ManagerAI25/8/202628/8/2026
SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can…