Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

50 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (4.9)0.68%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access12/8/202517/6/2026
XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial of service
AnalizadaAlta (7.5)1.1%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access12/8/202517/6/2026
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.
AnalizadaAlta (7.5)1.1%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access12/8/202517/6/2026
A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.…
AnalizadaCrítica (9.8)2.1%—Ivanti Neurons FOR Itsm13/5/202517/6/2026
An authentication bypass in Ivanti Neurons for ITSM (on-prem only) before 2023.4, 2024.2 and 2024.3 with the May 2025 Security Patch allows a remote unauthenticated attacker to gain administrative access to the system.
AnalizadaAlta (7)17%—Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure8/1/202517/6/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
AnalizadaCrítica (9)100%⚠ Explotación activaIvanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure8/1/20251/10/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
AnalizadaAlta (7.1)0.21%—Ivanti Endpoint ManagerIvanti Neurons Agent PlatformIvanti Neurons FOR Patch ManagementIvanti Patch FOR Configuration Manager+210/12/202417/6/2026
Insufficient permissions in Ivanti Patch SDK before version 9.7.703 allows a local authenticated attacker to delete arbitrary files.
AnalizadaMedia (5.3)0.48%—Emqx Neuron7/11/202417/6/2026
A vulnerability classified as problematic was found in emqx neuron up to 2.10.0. Affected by this vulnerability is an unknown functionality of the file /api/v2/schema of the component JSON File Handler. The manipulation leads to information disclosure. The attack can be launched remotely. The patch is named…
AnalizadaMedia (5.3)0.66%—Emqx Neuron7/11/202417/6/2026
A vulnerability classified as critical has been found in emqx neuron up to 2.10.0. Affected is the function handle_add_plugin in the library cmd.library of the file plugins/restful/plugin_handle.c. The manipulation leads to buffer overflow. It is possible to launch the attack remotely. It is recommended to apply a…
AnalizadaAlta (8.1)0.57%—Ivanti Neurons FOR Itsm13/8/202417/6/2026
Improper certificate validation in Ivanti ITSM on-prem and Neurons for ITSM Versions 2023.4 and earlier allows a remote attacker in a MITM position to craft a token that would allow access to ITSM as any user.
AnalizadaCrítica (9.8)1.7%—Ivanti Neurons FOR Itsm13/8/202417/6/2026
An information disclosure vulnerability in Ivanti ITSM on-prem and Neurons for ITSM versions 2023.4 and earlier allows an unauthenticated attacker to obtain the OIDC client secret via debug information.
ModificadaMedia (6.5)0.50%—Wpneuron Sparkle Demo Importer22/6/202417/6/2026
The Sparkle Demo Importer plugin for WordPress is vulnerable to unauthorized database reset and demo data import due to a missing capability check on the multiple functions in all versions up to and including 1.4.7. This makes it possible for authenticated attackers, with Subscriber-level access and above, to delete…
AnalizadaMedia (4.9)1.1%—Ivanti Neurons FOR Itsm31/5/202417/6/2026
An unrestricted file upload vulnerability in web component of Ivanti Neurons for ITSM allows a remote, authenticated, high privileged user to write arbitrary files into sensitive directories of ITSM server.
AnalizadaAlta (8.8)1.1%—Ivanti Neurons FOR Itsm31/5/202417/6/2026
A SQL injection vulnerability in web component of Ivanti Neurons for ITSM allows a remote authenticated user to read/modify/delete information in the underlying database. This may also lead to DoS.
ModificadaCrítica (9.9)2.0%—Ivanti Neurons FOR Itsm31/3/202417/6/2026
An file upload vulnerability in Ivanti ITSM before 2023.4, allows an authenticated remote user to perform file writes to the server. Successful exploitation may lead to execution of commands in the context of non-root user.
AnalizadaAlta (8.2)100%⚠ Explotación activaIvanti Connect SecureIvanti Policy SecureIvanti Neurons FOR Zero-trust Access31/1/20244/8/2026
A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication.
ModificadaAlta (7.5)2.7%—Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure5/12/202217/6/2026
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
ModificadaAlta (7.5)2.7%—Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure5/12/202217/6/2026
An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1.
ModificadaAlta (7.6)0.47%—Capsuletech Smartlinx Neuron 2 Firmware11/4/201917/6/2026
A restricted environment escape vulnerability exists in the “kiosk mode” function of Capsule Technologies SmartLinx Neuron 2 medical information collection devices running versions 9.0.3 or lower. A specific series of keyboard inputs can escape the restricted environment, resulting in full administrator access to the…
ModificadaMedia (4.3)0.84%—Neuron News27/12/200716/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in neuron news 1.0 allow remote attackers to inject arbitrary web script or HTML via (1) the topic parameter in a viewtopic action, or the (2) newsyear or (3) newsmonth parameter in a newsarchive action to the default URI in patch/.
ModificadaAlta (7.5)1.1%—Neuron News27/12/200716/6/2026
SQL injection vulnerability in neuron news 1.0 allows remote attackers to execute arbitrary SQL commands via the q parameter to the default URI in patch/.
ModificadaAlta (7.5)3.0%—Neuron News24/9/200716/6/2026
Directory traversal vulnerability in index.php in Neuron News 1.0 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the q parameter.
ModificadaMedia (6.8)1.2%—Hotscripts Neuron Blog15/8/200716/6/2026
Unrestricted file upload vulnerability in admin/pages/blog-add.php in Neuron Blog 1.1 allows remote attackers to upload and execute arbitrary PHP files in uploads/.
ModificadaAlta (7.5)1.1%—DEV Neuron Blog12/2/200716/6/2026
Multiple SQL injection vulnerabilities in pages/addcomment2.php in Neuron Blog 1.1 allow remote attackers to inject arbitrary SQL commands via the (1) commentname, (2) commentmail, (3) commentwebsite, and (4) comment parameters. NOTE: the provenance of this information is unknown; the details are obtained solely from…
ModificadaBaja (2.6)1.3%—DEV Neuron Blog20/4/200616/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in dev Neuron Blog 1.1 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) name and (2) website parameters.