Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

187 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)2.8%⚠ Explotación activaMotex Lanscope Endpoint Manager20/10/202517/6/2026
Lanscope Endpoint Manager (On-Premises) (Client program (MR) and Detection agent (DA)) improperly verifies the origin of incoming requests, allowing an attacker to execute arbitrary code by sending specially crafted packets.
AplazadaAlta (8.6)44%💥 ExploitFreepbx Endpoint ManagerAI14/10/202517/6/2026
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains an authenticated arbitrary file upload vulnerability affecting the fwbrand parameter. The fwbrand…
AplazadaAlta (8.6)38%💥 ExploitFreepbx Endpoint ManagerAI14/10/202517/6/2026
FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. In versions prior to 16.0.92 for FreePBX 16 and versions prior to 17.0.6 for FreePBX 17, the Endpoint Manager module contains authenticated SQL injection vulnerabilities affecting multiple parameters in the basestation, model,…
AplazadaAlta (8.6)0.53%—Freepbx Endpoint ManagerAI14/10/202517/6/2026
The FreePBX Endpoint Manager module includes a Network Scanning feature that provides web-based access to nmap functionality for network device discovery. In Endpoint Manager 16 before 16.0.92 and 17 before 17.0.6, insufficiently sanitized user-supplied input allows authenticated OS command execution as the asterisk…
AnalizadaMedia (5.5)0.62%—Ivanti Endpoint Manager Mobile14/10/202517/6/2026
Path traversal in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to write data in unintended locations on disk.
AnalizadaAlta (7.2)20%—Ivanti Endpoint Manager Mobile14/10/202517/6/2026
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)20%—Ivanti Endpoint Manager Mobile14/10/202517/6/2026
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)20%—Ivanti Endpoint Manager Mobile14/10/202530/9/2026
OS command injection in the admin panel of Ivanti EPMM before version 12.6.0.2, 12.5.0.4, and 12.4.0.4 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)1.7%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)1.7%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)1.7%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.83%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.83%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaMedia (6.5)0.83%—Ivanti Endpoint Manager13/10/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaAlta (7.8)0.78%—Ivanti Endpoint Manager13/10/202517/6/2026
Insecure deserialization in Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to escalate their privileges.
ModificadaMedia (6.5)0.82%—Ivanti Endpoint Manager13/10/202530/9/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database.
ModificadaAlta (8.8)15%—Ivanti Endpoint Manager13/10/202530/9/2026
Path traversal in Ivanti Endpoint Manager before version 2024 SU4 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
AnalizadaAlta (8.8)21%—Ivanti Endpoint Manager9/9/202517/6/2026
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
AnalizadaAlta (8.8)14%—Ivanti Endpoint Manager9/9/202525/9/2026
Insufficient filename validation in Ivanti Endpoint Manager before 2024 SU3 SR1 and 2022 SU8 SR2 allows a remote unauthenticated attacker to achieve remote code execution. User interaction is required.
AnalizadaAlta (7.2)20%—Ivanti Endpoint Manager Mobile8/7/202517/6/2026
OS command injection in Ivanti Endpoint Manager Mobile (EPMM) before version 12.5.0.2,12.4.0.3 and 12.3.0.3 allows a remote authenticated attacker with high privileges to achieve remote code execution
AnalizadaAlta (7.2)1.1%—Ivanti Endpoint Manager8/7/202517/6/2026
SQL injection in Ivanti Endpoint Manager before version 2024 SU3 and 2022 SU8 Security Update 1 allows a remote authenticated attacker with admin privileges to read arbitrary data from the database
Orbitaley — Vulnerabilidades