Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
93 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.74% | — | Ivanti Connect SecureIvanti Policy Secure | 11/2/2025 | 17/6/2026 | Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required. | |
| Analizada | Media (4.9) | 1.1% | — | Ivanti Connect SecureIvanti Policy Secure | 11/2/2025 | 17/6/2026 | External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files. | |
| Analizada | Alta (7.2) | 2.8% | — | Ivanti Connect SecureIvanti Policy Secure | 11/2/2025 | 17/6/2026 | Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7) | 17% | — | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 8/1/2025 | 17/6/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 8/1/2025 | 1/10/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Alta (7.5) | 1.5% | — | Ivanti Connect SecureIvanti Policy Secure | 12/12/2024 | 17/6/2026 | An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 1.8% | — | Ivanti Connect SecureIvanti Policy Secure | 12/12/2024 | 17/6/2026 | A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.2) | 1.8% | — | Ivanti Connect SecureIvanti Policy Secure | 10/12/2024 | 17/6/2026 | Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx) | |
| Analizada | Crítica (9.1) | 1.7% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.1) | 1.7% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Crítica (9.1) | 1.9% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.8) | 0.30% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges. | |
| Analizada | Crítica (9.1) | 1.7% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.7% | — | Ivanti Connect SecureIvanti Policy Secure | 13/11/2024 | 17/6/2026 | Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.6% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (7.2) | 1.6% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Media (6.1) | 0.85% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required. | |
| Modificada | Alta (8.8) | 1.4% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution | |
| Analizada | Alta (7.5) | 1.4% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Media (4.9) | 1.1% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service. | |
| Analizada | Alta (7.8) | 0.22% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges. | |
| Analizada | Media (4.9) | 1.1% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service. | |
| Modificada | Alta (7.2) | 1.6% | — | Ivanti Connect SecureIvanti Policy Secure | 12/11/2024 | 17/6/2026 | Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution. | |
| Analizada | Alta (8.8) | 71% | 💥 Exploit | Ivanti Connect SecureIvanti Policy Secure | 18/10/2024 | 17/6/2026 | Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution. | |
| Aplazada | Alta (7.5) | 1.6% | — | Ivanti Connect SecureAIIvanti Policy SecureAI | 25/4/2024 | 17/6/2026 | An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions. |