Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.8)3.3%—Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 250331/10/202517/6/2026
Authentication bypass by spoofing in Microsoft Configuration Manager allows an authorized attacker to perform spoofing over an adjacent network.
ModificadaAlta (8.8)0.37%—Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 250314/10/202517/6/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an unauthorized attacker to elevate privileges over an adjacent network.
ModificadaMedia (6.8)0.68%—Microsoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 250314/10/202517/6/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to elevate privileges over an adjacent network.
AplazadaAlta (7.5)0.12%—GE Vernova S1 Agile Configuration SoftwareAI22/9/202517/6/2026
Improper Privilege Management vulnerability in GE Vernova S1 Agile Configuration Software on Windows allows Privilege Escalation.This issue affects S1 Agile Configuration Software: 3.1 and previous version.
AnalizadaAlta (8)2.7%—Microsoft Configuration Manager 25038/7/202517/6/2026
Improper neutralization of special elements used in an sql command ('sql injection') in Microsoft Configuration Manager allows an authorized attacker to execute code over an adjacent network.
AplazadaMedia (6.3)0.24%—Istar Configuration UtilityAI11/6/202517/6/2026
The iSTAR Configuration Utility (ICU) tool leaks memory, which could result in the unintended exposure of unauthorized data from the Windows PC that ICU is running on.
AplazadaMedia (4.3)0.25%—Zohocorp Manageengine OpmanagerAIZohocorp Manageengine Netflow AnalyzerAIZohocorp Manageengine Network Configuration ManagerAIZohocorp Manageengine Firewall AnalyzerAI+19/6/202517/6/2026
Zohocorp ManageEngine OpManager, NetFlow Analyzer, Network Configuration Manager, Firewall Analyzer and OpUtils versions 128565 and below are vulnerable to Reflected XSS on the login page.
AnalizadaMedia (6.5)2.1%—Apache Commons Configuration9/5/202517/6/2026
Uncontrolled Resource Consumption vulnerability in Apache Commons Configuration 1.x. There are a number of issues in Apache Commons Configuration 1.x that allow excessive resource consumption when loading untrusted configurations or using unexpected usage patterns. The Apache Commons Configuration team does not intend…
AplazadaCrítica (9.3)0.57%—Istar Configuration UtilityAI24/4/202517/6/2026
Under certain circumstances the iSTAR Configuration Utility (ICU) tool could have a buffer overflow issue
AplazadaMedia (6.8)0.17%—I-pro Configuration ToolAII-pro Surveillance CamerasAII-pro RecordersAI24/4/202517/6/2026
Use of hard-coded cryptographic key vulnerability in i-PRO Configuration Tool affects the network system for i-PRO Co., Ltd. surveillance cameras and recorders. This vulnerability allows a local authenticated attacker to use the authentication information from the last connected surveillance cameras and recorders.
AnalizadaMedia (6.8)0.19%—Nuvole Configuration Split31/3/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Drupal Configuration Split allows Cross Site Request Forgery.This issue affects Configuration Split: from 0.0.0 before 1.10.0, from 2.0.0 before 2.0.2.
ModificadaCrítica (9.8)0.43%—Vestel Evc04 Configuration Interface18/3/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Vestel EVC04 Configuration Interface allows SQL Injection. This issue affects EVC04 Configuration Interface: before V3.187, V4.53.
AnalizadaAlta (7.8)0.15%—Dell Utility Configuration Collector Edge11/2/202517/6/2026
Dell UCC Edge, version 2.3.0, contains a Blind SSRF on Add Customer SFTP Server vulnerability. An unauthenticated attacker with local access could potentially exploit this vulnerability, leading to Server-side request forgery
AplazadaAlta (8.6)0.19%—Configuration Wizard 2AI24/1/202517/6/2026
DLL hijacking vulnerabilities, caused by an uncontrolled search path in Configuration Wizard 2 installer can lead to privilege escalation and arbitrary code execution when running the impacted installer.
AnalizadaAlta (7.1)0.21%—Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+210/12/202417/6/2026
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
AplazadaMedia (5.4)0.14%—Intel Binary Configuration ToolAI13/11/202417/6/2026
Incorrect default permissions for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.18%—Intel Binary Configuration ToolAI13/11/202417/6/2026
Uncontrolled search path for some Intel(R) Binary Configuration Tool software for Windows before version 3.4.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaCrítica (9.8)81%⚠ Explotación activaMicrosoft Configuration Manager 2403Microsoft Configuration Manager 2409Microsoft Configuration Manager 25038/10/202417/6/2026
Microsoft Configuration Manager Remote Code Execution Vulnerability
AnalizadaMedia (6.5)0.28%—IBM Global Configuration Management20/8/202417/6/2026
IBM Global Configuration Management 7.0.2 and 7.0.3 could allow an authenticated user to archive a global baseline due to improper access controls.
AplazadaAlta (7.8)0.31%—NI I O Trace ToolAINI System ConfigurationAINI SPYAI23/7/202417/6/2026
A stack-based buffer overflow vulnerability due to a missing bounds check in the NI I/O Trace Tool may result in arbitrary code execution. Successful exploitation requires an attacker to provide a user with a specially crafted nitrace file. The NI I/O Trace tool is installed as part of the NI System Configuration…
ModificadaAlta (7.8)0.23%—Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+312/7/202417/6/2026
Improper privilege management in Jungo WinDriver 6.0.0 through 16.1.0 allows local attackers to escalate privileges and execute arbitrary code.
ModificadaAlta (7.8)0.18%—Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+312/7/202417/6/2026
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges and execute arbitrary code.
ModificadaMedia (5.5)0.25%—Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+312/7/202417/6/2026
Denial of Service (DoS) vulnerability in Jungo WinDriver before 12.7.0 allows local attackers to cause a Windows blue screen error.
ModificadaAlta (7.8)0.34%—Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+312/7/202417/6/2026
Improper privilege management in Jungo WinDriver before 12.2.0 allows local attackers to escalate privileges and execute arbitrary code.
ModificadaAlta (7.8)0.18%—Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+312/7/202417/6/2026
Improper privilege management in Jungo WinDriver before 12.5.1 allows local attackers to escalate privileges, execute arbitrary code, or cause a Denial of Service (DoS).