Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.18%—Cisco Anyconnect Secure Mobility Client6/10/202117/6/2026
A vulnerability in the shared library loading mechanism of Cisco AnyConnect Secure Mobility Client for Linux and Mac OS could allow an authenticated, local attacker to perform a shared library hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This…
ModificadaMedia (6.8)0.58%—Netmotionsoftware Mobility16/9/202117/6/2026
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings.…
ModificadaMedia (5.3)0.58%—Netmotionsoftware Mobility16/9/202117/6/2026
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.
ModificadaMedia (5.5)0.21%—Cisco Anyconnect Secure Mobility Client16/6/202117/6/2026
A vulnerability in Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. This vulnerability is due to uncontrolled memory allocation. An attacker could exploit this vulnerability by copying a crafted file to…
ModificadaMedia (6.7)0.18%—Cisco Anyconnect Secure Mobility Client16/6/202117/6/2026
A vulnerability in the DLL loading mechanism of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is due to a race…
ModificadaMedia (5.5)0.21%—Cisco Anyconnect Secure Mobility Client6/5/202117/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. The vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this…
ModificadaAlta (7.8)0.53%—Cisco Anyconnect Secure Mobility Client6/5/202117/6/2026
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an…
ModificadaAlta (7.8)0.23%—Cisco Anyconnect Secure Mobility Client6/5/202117/6/2026
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an…
ModificadaAlta (7.8)0.25%—Cisco Anyconnect Secure Mobility Client6/5/202117/6/2026
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an…
ModificadaAlta (7.8)0.25%—Cisco Anyconnect Secure Mobility Client6/5/202117/6/2026
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an…
ModificadaAlta (7.8)0.25%—Cisco Anyconnect Secure Mobility Client6/5/202117/6/2026
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an…
ModificadaAlta (7.8)0.25%—Cisco Anyconnect Secure Mobility Client6/5/202117/6/2026
Multiple vulnerabilities in the install, uninstall, and upgrade processes of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to hijack DLL or executable files that are used by the application. A successful exploit could allow the attacker to execute arbitrary code on an…
ModificadaMedia (5.5)0.23%—Cisco Anyconnect Secure Mobility Client24/2/202117/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the device. The…
ModificadaAlta (7.8)1.3%—Cisco Anyconnect Secure Mobility Client17/2/202117/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is…
ModificadaAlta (8.1)42%—Netmotionsoftware Netmotion Mobility8/2/202117/6/2026
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
ModificadaAlta (8.1)78%—Netmotionsoftware Netmotion Mobility8/2/202117/6/2026
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.
ModificadaAlta (8.1)13%—Netmotionsoftware Netmotion Mobility8/2/202117/6/2026
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in RpcServlet.
ModificadaAlta (8.1)41%—Netmotionsoftware Netmotion Mobility8/2/202117/6/2026
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in SupportRpcServlet.
ModificadaMedia (5.5)0.34%—Cisco Anyconnect Secure Mobility ClientMcafee Agent Epolicy Orchestrator Extension13/1/202117/6/2026
A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker…
ModificadaAlta (7.8)0.40%—Cisco Anyconnect Secure Mobility Client13/1/202117/6/2026
A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.…
ModificadaAlta (7.3)0.45%—Cisco Anyconnect Secure Mobility Client6/11/202017/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC listener. An attacker could…
ModificadaMedia (5.5)0.33%—Cisco Anyconnect Secure Mobility Client6/11/202017/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerability is due to an exposed IPC function. An attacker could…
ModificadaAlta (7.1)0.36%—Cisco Anyconnect Secure Mobility Client23/9/202017/6/2026
A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The vulnerability is due to the use of implicit service…
ModificadaMedia (5.5)0.34%—Cisco Anyconnect Secure Mobility Client17/8/202017/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.…
ModificadaMedia (5.5)0.46%—Cisco Anyconnect Secure Mobility Client17/8/202017/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the…