Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
330 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 3.3% | — | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 31/10/2025 | 17/6/2026 | Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network. | |
| Modificada | Alta (8.8) | 0.37% | — | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 14/10/2025 | 17/6/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network. | |
| Modificada | Media (6.8) | 0.68% | — | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 14/10/2025 | 17/6/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network. | |
| Aplazada | Alta (7.5) | 0.12% | — | GE Vernova S1 Agile Configuration SoftwareAI | 22/9/2025 | 17/6/2026 | Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S1 Agile Configuration Software: 3.1 and previous version. | |
| Analizada | Alta (8) | 2.7% | — | Microsoft Configuration Manager 2503 | 8/7/2025 | 17/6/2026 | Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network. | |
| Aplazada | Media (6.3) | 0.24% | — | Istar Configuration UtilityAI | 11/6/2025 | 17/6/2026 | The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on. | |
| Aplazada | Media (4.3) | 0.25% | — | Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine Network Configuration ManagerAIZohocorp Manageengine Firewall AnalyzerAI+1 | 9/6/2025 | 17/6/2026 | Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page. | |
| Analizada | Media (6.5) | 2.1% | — | Apache Commons Configuration | 9/5/2025 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend… | |
| Aplazada | Crítica (9.3) | 0.57% | — | Istar Configuration UtilityAI | 24/4/2025 | 17/6/2026 | Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue | |
| Aplazada | Media (6.8) | 0.17% | — | I-pro Configuration ToolAII-pro Surveillance CamerasAII-pro RecordersAI | 24/4/2025 | 17/6/2026 | Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders. | |
| Analizada | Media (6.8) | 0.19% | — | Nuvole Configuration Split | 31/3/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Configuration Split allows Cross Site Request Forgery.This issue affects Configuration Split: from 0.0.0 before 1.10.0, from 2.0.0 before 2.0.2. | |
| Modificada | Crítica (9.8) | 0.43% | — | Vestel Evc04 Configuration Interface | 18/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection. This issue affects EVC04 Configuration Interface: before V3.187, V4.53. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Utility Configuration Collector Edge | 11/2/2025 | 17/6/2026 | Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery | |
| Aplazada | Alta (8.6) | 0.19% | — | Configuration Wizard 2AI | 24/1/2025 | 17/6/2026 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. | |
| Analizada | Alta (7.1) | 0.21% | — | Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+2 | 10/12/2024 | 17/6/2026 | Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files. | |
| Aplazada | Media (5.4) | 0.14% | — | Intel Binary Configuration ToolAI | 13/11/2024 | 17/6/2026 | Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Binary Configuration ToolAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Crítica (9.8) | 81% | ⚠ Explotación activa | Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 2503 | 8/10/2024 | 17/6/2026 | Microsoft Configuration Manager Remote Code Execution Vulnerability | |
| Analizada | Media (6.5) | 0.28% | — | IBM Global Configuration Management | 20/8/2024 | 17/6/2026 | IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls. | |
| Aplazada | Alta (7.8) | 0.31% | — | NI I O Trace ToolAINI System ConfigurationAINI SPYAI | 23/7/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted nitrace file. The NI I/O Trace tool is installed as part of the NI System Configuration… | |
| Modificada | Alta (7.8) | 0.23% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.18% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code. | |
| Modificada | Media (5.5) | 0.25% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error. | |
| Modificada | Alta (7.8) | 0.34% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.18% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS). |