Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

805 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7)0.20%—Microsoft Defender FOR Endpoint14/7/202622/7/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.5)0.40%—Microsoft Defender FOR Endpoint14/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Microsoft Defender allows an authorized attacker to disclose information locally.
Pendiente de análisisAlta (8.5)0.17%—Citrix Secure Access ClientAICitrix Endpoint Analysis ClientAI14/7/202615/7/2026
Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.
ModificadaMedia (5.3)0.30%—Elastic Endpoint Security1/7/20264/9/2026
Incorrect Authorization (CWE-863) in Kibana can lead to unauthorized information disclosure via Accessing Functionality Not Properly Constrained by ACLs (CAPEC-1). Under certain conditions, a low-privileged authenticated user can access response action data that they are not authorized to view.
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the DMG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in DMG files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the ALZ file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in ALZ files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the PESpin file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PESpin files during…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the InstallShield file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to improper handling of temporary resources during file scanning. An attacker could exploit this vulnerability by submitting a…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the 7z file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in 7z files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the FSG file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in FSG files during scanning,…
AnalizadaAlta (7.5)0.57%—Cisco Secure EndpointClamav1/7/20269/7/2026
A vulnerability in the PE file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition, or possibly other expanded impacts, resulting from memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in PE files during scanning,…
Pendiente de análisisAlta (7.5)0.41%—Safetica Endpoint ClientAI26/6/202626/6/2026
Kernel driver ProcessMonitorDriver.sys in Safetica's endpoint client x64 , versions 10.5.75.0 and 11.11.4.0, allows unprivileged user to abuse IOCTL path and terminate protected system processes.
AplazadaMedia (6.5)0.40%—Steeltoe Management EndpointAISteeltoe Management EndpointcoreAIVmware Spring BootAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, all Steeltoe actuator endpoints default to `EndpointPermissions.Restricted`,…
AplazadaAlta (7.5)0.31%—Steeltoe Management EndpointAISteeltoe Management EndpointcoreAI17/6/202622/6/2026
Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. In Steeltoe.Management.Endpoint prior to version 4.2.0 and Steeltoe.Management.EndpointCore prior to version 3.4.0, the `Sanitizer` component in the Environment actuator redacts configuration…
AnalizadaMedia (6.1)0.37%—Aqara Cloud Oauth Authorization Endpoint12/6/20269/7/2026
The Aqara Cloud OAuth Authorization Endpoint (open-cn.aqara.com/oauth/authorize) is vulnerable to a redirect bypass due to lax controls on domain matching, which is an instance of "CWE-1289: Improper Validation of Unsafe Equivalence in Input" and has an estimated CVSS of CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:C/C:H/I:H/A:N…
AnalizadaAlta (8.5)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Linux Agent versions prior to 26.5 allow a local attacker to potentially compromise the agent daemon initialization. CyberArk Security Bulletin: CA26-19
AnalizadaAlta (8.5)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within internal agent validation processes. A local attacker could potentially bypass built-in security controls or cryptographic validations. Under specific circumstances, this could allow the attacker to circumvent agent…
AnalizadaAlta (8.9)0.17%—Paloaltonetworks Idira Endpoint Privilege Manager11/6/202622/6/2026
Idira Endpoint Privilege Manager Agent versions prior to 26.5 exhibit improper access control within high-privileged agent components. A local, low-privileged attacker could exploit this by manipulating an internal communication mechanism or file operation. Under specific circumstances, this could potentially allow…
AnalizadaAlta (7)0.23%—Microsoft Defender FOR Endpoint9/6/202623/7/2026
Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (6.5)0.45%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential arbitrary file read in the asperahttpd component. An authenticated user may be able to take advantage…
AnalizadaAlta (7.5)0.48%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a potential denial of service in the asperahttpd component. An unauthenticated user can cause the asperahttpd…
AnalizadaAlta (8.8)0.61%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could allow an authenticated user to execute…
AnalizadaCrítica (9.8)0.94%—IBM Aspera High-speed Transfer EndpointIBM Aspera High-speed Transfer Server27/5/202617/6/2026
IBM Aspera High-Speed Transfer Endpoint 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Server 3.7.4 through 4.4.7 Fix Pack 1 and IBM Aspera High-Speed Transfer Endpoint are affected by a buffer overflow in the asperahttpd component. This vulnerability could be exploited to cause a denial of service…
AnalizadaAlta (8.7)0.22%—Intel Endpoint Management Assistant12/5/202621/7/2026
Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This…
AnalizadaAlta (8.8)1.6%—Ivanti Endpoint Manager12/5/202617/6/2026
SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution.