Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2525 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.79% | — | Xcitium Client SecurityAIComodo Internet SecurityAI | 7/6/2026 | 23/7/2026 | Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected by 2026 Q3) contain an integer underflow vulnerability in the firewall driver Inspect.sys that allows remote unauthenticated attackers to crash the system by sending a crafted IPv6 packet with a… | |
| Analizada | Media (6.3) | 0.09% | — | Samsung Internet | 5/6/2026 | 30/6/2026 | Improper authorization in Samsung Internet prior to version 30.0.0.39 allows local attackers to access sensitive information. | |
| Pendiente de análisis | Alta (7.8) | 0.18% | — | PC Tools Internet SecurityAIPC Tools Pctcore64AI | 1/6/2026 | 22/7/2026 | Improper access control in the PCTCore64.sys Windows kernel driver from PC Tools Internet Security allows user-mode processes to access the PCTCoreDriver WDM device interface and invoke privileged IOCTL handlers. A local attacker with the ability to access or load the affected driver can exploit this vulnerability to… | |
| Aplazada | Crítica (9.3) | 0.26% | — | SketchupAIMicrosoft Internet ExplorerAI | 22/5/2026 | 23/7/2026 | A cross-site scripting (XSS) vulnerability in SketchUp 2026's Dynamic Components feature allows remote code execution and local file exfiltration through maliciously crafted SKP files. The vulnerability stems from improper input sanitization in the component options window, enabling attackers to execute arbitrary… | |
| Aplazada | Media (6.9) | 0.15% | — | Internet Download ManagerAI | 16/5/2026 | 29/9/2026 | Internet Download Manager 6.38.12 contains a buffer overflow vulnerability in the Scheduler component that allows local attackers to crash the application by supplying oversized input. Attackers can paste malicious data exceeding 5000 bytes into the 'Open the following file when done' field to trigger a denial of… | |
| Analizada | Crítica (9.3) | 6.2% | — | Topsecgroup Tianxin Internet Behavior Management System | 7/4/2026 | 17/6/2026 | Tianxin Internet Behavior Management System contains a command injection vulnerability in the Reporter component endpoint that allows unauthenticated attackers to execute arbitrary commands by supplying a crafted objClass parameter containing shell metacharacters and output redirection. Attackers can exploit this… | |
| Aplazada | Media (6.9) | 0.13% | — | Spotie Internet Explorer Password RecoveryAI | 11/3/2026 | 17/6/2026 | SpotIE Internet Explorer Password Recovery 2.9.5 contains a denial of service vulnerability in the registration key input field that allows local attackers to crash the application by supplying an excessively long string. Attackers can paste a 256-character payload into the Key field during registration to trigger a… | |
| Analizada | Baja (1.9) | 0.18% | — | Qianxin QAX Internet Control Gateway | 9/3/2026 | 17/6/2026 | A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter Driver. Executing a manipulation can lead to improper access controls. The attack is restricted to local execution. The… | |
| Analizada | Alta (8.1) | 0.57% | — | Internet Routing Registry Daemon Project Internet Routing Registry Daemon | 6/3/2026 | 17/6/2026 | Internet Routing Registry daemon version 4 is an IRR database server, processing IRR objects in the RPSL format. From version 4.4.0 to before version 4.4.5 and from version 4.5.0 to before version 4.5.1, an attacker can manipulate the HTTP Host header on a password reset or account creation request. The confirmation… | |
| Modificada | Alta (7) | 0.14% | — | Avira Internet Security | 5/3/2026 | 17/6/2026 | Avira Internet Security contains a time-of-check time-of-use (TOCTOU) vulnerability in the Optimizer component. A privileged service running as SYSTEM identifies directories for cleanup during a scan phase and subsequently deletes them during a separate cleanup phase without revalidating the target path. A local… | |
| Modificada | Alta (7.8) | 0.77% | — | Avira Internet Security | 5/3/2026 | 17/6/2026 | Avira Internet Security contains a deserialization of untrusted data vulnerability in the System Speedup component. The Avira.SystemSpeedup.RealTimeOptimizer.exe process, which runs with SYSTEM privileges, deserializes data from a file located in C:\\ProgramData using .NET BinaryFormatter without implementing input… | |
| Modificada | Alta (7.1) | 0.19% | — | Avira Internet Security | 5/3/2026 | 17/6/2026 | Avira Internet Security contains an improper link resolution vulnerability in the Software Updater component. During the update process, a privileged service running as SYSTEM deletes a file under C:\\ProgramData without validating whether the path resolves through a symbolic link or reparse point. A local attacker… | |
| Analizada | Baja (2.7) | 0.17% | — | Zscaler Internet Access Admin Portal | 23/2/2026 | 17/6/2026 | Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare conditions. | |
| Analizada | Baja (2.7) | 0.20% | — | Zscaler Internet Access Admin Portal | 23/2/2026 | 17/6/2026 | Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios. | |
| Aplazada | Crítica (9.8) | 0.57% | — | Inrove Software AND Internet Services Bieticaret CMSAI | 19/2/2026 | 17/6/2026 | Execution After Redirect (EAR), Missing Authentication for Critical Function vulnerability in Inrove Software and Internet Services BiEticaret CMS allows Authentication Bypass, HTTP Response Splitting. This issue affects BiEticaret CMS: from 2.1.13 through 19022026. NOTE: The vendor was contacted early about this… | |
| Aplazada | Alta (8.6) | 0.29% | — | Tumeva Internet Technologies Tumeva Prime News SoftwareAI | 17/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Tumeva Internet Technologies Software Information Advertising and Consulting Services Trade Ltd. Co. Tumeva Prime News Software allows SQL Injection. This issue affects Tumeva Prime News Software: from v.1.0.1 before… | |
| Analizada | Media (6.7) | 0.46% | — | Internet-soft FTP Navigator | 12/2/2026 | 17/6/2026 | FTP Navigator 8.03 contains a denial of service vulnerability that allows attackers to crash the application by overwriting Structured Exception Handler (SEH) with malicious input. Attackers can generate a payload of 4108 'A' characters followed by 4 'B' characters and 40 'C' characters to trigger a program crash when… | |
| Analizada | Alta (8.4) | 0.71% | — | Internet-soft FTP Navigator | 12/2/2026 | 17/6/2026 | FTP Navigator 8.03 contains a stack overflow vulnerability that allows attackers to execute arbitrary code by overwriting Structured Exception Handler (SEH) registers. Attackers can craft a malicious payload that triggers a buffer overflow when pasted into the Custom Command textbox, enabling remote code execution and… | |
| Aplazada | Crítica (9.4) | 0.39% | — | E-kalite Software Hardware Engineering Design AND Internet Services Industry AND Trade LTD CO TurboardAI | 11/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in E-Kalite Software Hardware Engineering Design and Internet Services Industry and Trade Ltd. Co. Turboard allows Reflected XSS. This issue affects Turboard: from 2025.07 before 2026.02. NOTE: This CVE record… | |
| Aplazada | Alta (8.3) | 0.27% | — | Saastech Cleaning AND Internet Services INC TemizlikyoldaAI | 11/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Cross-Site Scripting (XSS). This issue affects TemizlikYolda: through 11022026. NOTE: The vendor was contacted early about this disclosure but… | |
| Aplazada | Media (5.4) | 0.21% | — | Saastech Cleaning AND Internet Services INC TemizlikyoldaAI | 11/2/2026 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Saastech Cleaning and Internet Services Inc. TemizlikYolda allows Manipulating User-Controlled Variables. This issue affects TemizlikYolda: through 11022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Analizada | Media (4.8) | 0.17% | — | Bordeaux-metropole AT Internet Piano Analytics | 4/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet Piano Analytics allows Cross-Site Scripting (XSS).This issue affects AT Internet Piano Analytics: from 0.0.0 before 1.0.1, from 2.0.0 before 2.3.1. | |
| Analizada | Media (6.1) | 0.18% | — | Bordeaux-metropole AT Internet Smarttag | 4/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal AT Internet SmartTag allows Cross-Site Scripting (XSS).This issue affects AT Internet SmartTag: from 0.0.0 before 1.0.1. | |
| Aplazada | Alta (8.5) | 0.21% | — | Privateinternetaccess Private Internet AccessAI | 13/1/2026 | 17/6/2026 | Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during… | |
| Modificada | Media (5.4) | 0.29% | — | Heytap Internet Browser | 5/1/2026 | 5/7/2026 | An issue in realme Internet browser v.45.13.4.1 allows a remote attacker to execute arbitrary code via a crafted webpage in the built-in HeyTap/ColorOS browser. NOTE: The supplier is currently disputing this finding and the record is under review. |