Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
139 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.40% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-33449 is a buffer overflow in a message handling function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a cryptographically valid message to the client, overwriting a small portion of memory conceivably leading to a denial of service. | |
| Analizada | Media (4.8) | 0.14% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-33448 is a format string vulnerability in the logging subsystem of Secure Access client for MacOS prior to 14.50. Attackers with control of a modified server can force the client to dump the contents of a small portion of memory to the log files potentially revealing secrets. | |
| Analizada | Baja (2.3) | 0.44% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-33447 is a buffer overflow in a message parsing function of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to memory corruption or denial of service. | |
| Analizada | Baja (2.3) | 0.52% | — | Absolute Secure Access | 30/4/2026 | 17/6/2026 | CVE-2026-33446 is a buffer overflow in the authentication sub-system of the Secure Access client prior to 14.50. Attackers with control of a modified server can send a special packet that can overwrite a small portion of memory conceivably leading to memory corruption or a denial of service. | |
| Analizada | Media (6.9) | 0.24% | — | Celestialsoftware Absolutetelnet | 7/2/2026 | 17/6/2026 | AbsoluteTelnet 11.12 contains a denial of service vulnerability in the SSH2 username input field that allows local attackers to crash the application. Attackers can overwrite the username field with a 1000-byte buffer, causing the application to become unresponsive and terminate. | |
| Analizada | Media (6.7) | 0.25% | — | Celestialsoftware Absolutetelnet | 7/2/2026 | 17/6/2026 | AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license name field to trigger an application crash. | |
| Analizada | Media (6.7) | 0.25% | — | Celestialsoftware Absolutetelnet | 7/2/2026 | 17/6/2026 | AbsoluteTelnet 11.12 contains a denial of service vulnerability that allows local attackers to crash the application by supplying an oversized license name. Attackers can generate a 2500-character payload and paste it into the license entry field to trigger an application crash. | |
| Aplazada | Media (4.3) | 0.21% | — | Absoluteplugins Absolute Addons FOR ElementorAI | 22/1/2026 | 17/6/2026 | Missing Authorization vulnerability in AbsolutePlugins Absolute Addons For Elementor absolute-addons allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Absolute Addons For Elementor: from n/a through <= 1.0.14. | |
| Analizada | Media (4.6) | 0.14% | — | Absolute Secure Access | 17/1/2026 | 17/6/2026 | In Secure Access 12.70 and prior to 14.20, the logging subsystem may write an unredacted authentication token to logs under certain configurations. Any party with access to those logs could read the token and reuse it to access an integrated system. | |
| Analizada | Media (4.8) | 0.17% | — | Absolute Secure Access | 17/1/2026 | 17/6/2026 | CVE-2026-0518 is a cross-site scripting vulnerability in versions of Secure Access prior to 14.20. An attacker with administrative privileges can interfere with another administrator’s use of the console. | |
| Analizada | Media (6) | 0.31% | — | Absolute Secure Access | 17/1/2026 | 17/6/2026 | CVE-2026-0517 is a denial-of-service vulnerability in versions of Secure Access Server prior to 14.20. An attacker can send a specially crafted packet to a server and cause the server to crash | |
| Modificada | Media (6.7) | 0.20% | — | Celestialsoftware Absolutetelnet | 15/1/2026 | 17/6/2026 | AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating username and error report fields. Attackers can trigger the crash by inserting 1000 characters into the username or email address fields, causing the application to become unresponsive. | |
| Modificada | Media (6.7) | 0.20% | — | Celestialsoftware Absolutetelnet | 15/1/2026 | 17/6/2026 | AbsoluteTelnet 11.24 contains a denial of service vulnerability that allows local attackers to crash the application by manipulating DialUp connection and license name fields. Attackers can generate a 1000-character payload and paste it into specific input fields to trigger application crashes and force unexpected… | |
| Aplazada | Media (6.4) | 0.21% | — | Htmega HT Mega Absolute Addons FOR ElementorAI | 21/11/2025 | 17/6/2026 | The HT Mega – Absolute Addons For Elementor plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's Gutenberg blocks in all versions up to, and including, 3.0.0 due to insufficient input validation on user-supplied HTML tag names. This is due to the lack of a tag name whitelist allowing… | |
| Analizada | Media (6) | 0.22% | — | Absolute Secure Access | 4/11/2025 | 17/6/2026 | CVE-2025-59596 is a denial-of-service vulnerability in Secure Access Windows client versions 12.0 to 14.10 that is addressed in version 14.12. If a local networking policy is active, attackers on an adjacent network may be able to send a crafted packet and cause the client system to crash. | |
| Analizada | Alta (8.2) | 0.37% | — | Absolute Secure Access | 4/11/2025 | 17/6/2026 | CVE-2025-59595 is an internally discovered denial of service vulnerability in versions of Secure Access prior to 14.12. An attacker can send a specially crafted packet to a server in a non-default configuration and cause the server to crash. | |
| Analizada | Media (4.6) | 0.21% | — | Absolute Secure Access | 2/10/2025 | 17/6/2026 | CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the… | |
| Analizada | Media (5.5) | 0.18% | — | Absolute Secure Access | 2/10/2025 | 17/6/2026 | CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are required, and users must actively participate in the attack. Impact… | |
| Analizada | Baja (1.8) | 0.18% | — | Absolute Secure Access | 2/10/2025 | 17/6/2026 | CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is… | |
| Analizada | Media (5.3) | 0.18% | — | Absolute Secure Access | 2/10/2025 | 17/6/2026 | CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low, there are no attack requirements, the privileges required are low and no user… | |
| Aplazada | Media (6.5) | 0.27% | — | HT Plugins HT Mega - Absolute Addons FOR Wpbakery Page BuilderAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in HT Plugins HT Mega – Absolute Addons for WPBakery Page Builder ht-mega-for-wpbakery allows DOM-Based XSS.This issue affects HT Mega – Absolute Addons for WPBakery Page Builder: from n/a through <= 1.0.9. | |
| Aplazada | Alta (7.6) | 0.43% | — | Xolluteon DropshixAI | 15/8/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Xolluteon Dropshix allows DOM-Based XSS.This issue affects Dropshix: from n/a through 4.0.14. | |
| Analizada | Media (5.1) | 0.20% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read or change other settings. The attack complexity is… | |
| Analizada | Media (5.3) | 0.31% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, attack requirements are present, privileges required are high and no user… | |
| Analizada | Alta (7) | 0.37% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack complexity is low and… |