Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

93 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.1)0.74%—Ivanti Connect SecureIvanti Policy Secure11/2/202517/6/2026
Reflected XSS in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
AnalizadaMedia (4.9)1.1%—Ivanti Connect SecureIvanti Policy Secure11/2/202517/6/2026
External control of a file name in Ivanti Connect Secure before version 22.7R2.6 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to read arbitrary files.
AnalizadaAlta (7.2)2.8%—Ivanti Connect SecureIvanti Policy Secure11/2/202517/6/2026
Code injection in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7)17%—Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure8/1/202517/6/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges.
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitIvanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure8/1/20251/10/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution.
AnalizadaAlta (7.5)1.5%—Ivanti Connect SecureIvanti Policy Secure12/12/202417/6/2026
An out-of-bounds read in IPsec of Ivanti Connect Secure before version 22.7R2.1 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)1.8%—Ivanti Connect SecureIvanti Policy Secure12/12/202417/6/2026
A heap-based buffer overflow in IPsec of Ivanti Connect Secure before version 22.7R2.3 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.2)1.8%—Ivanti Connect SecureIvanti Policy Secure10/12/202417/6/2026
Command injection in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution. (Not applicable to 9.1Rx)
AnalizadaCrítica (9.1)1.7%—Ivanti Connect SecureIvanti Policy Secure13/11/202417/6/2026
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaCrítica (9.1)1.7%—Ivanti Connect SecureIvanti Policy Secure13/11/202417/6/2026
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaCrítica (9.1)1.9%—Ivanti Connect SecureIvanti Policy Secure13/11/202417/6/2026
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.7 and Ivanti Policy Secure before version 22.7R1.1 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.8)0.30%—Ivanti Connect SecureIvanti Policy Secure13/11/202417/6/2026
Incorrect file permissions in Ivanti Connect Secure before version 22.6R2 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1 (Not Applicable to 9.1Rx) allow a local authenticated attacker to escalate their privileges.
AnalizadaCrítica (9.1)1.7%—Ivanti Connect SecureIvanti Policy Secure13/11/202417/6/2026
Argument injection in Ivanti Connect Secure before version 22.7R2.2 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)1.7%—Ivanti Connect SecureIvanti Policy Secure13/11/202417/6/2026
Argument injection in Ivanti Connect Secure before version 22.7R2.1 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.1 and 9.1R18.9 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)1.6%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (7.2)1.6%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaMedia (6.1)0.85%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
Reflected XSS in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to obtain admin privileges. User interaction is required.
ModificadaAlta (8.8)1.4%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
A use-after-free in Ivanti Connect Secure before version 22.7R2.3 and 9.1R18.9 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker to achieve remote code execution
AnalizadaAlta (7.5)1.4%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
A null pointer dereference in Ivanti Connect Secure before version 22.7R2.1 and Ivanti Policy Secure before version 22.7R1.1 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaMedia (4.9)1.1%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
AnalizadaAlta (7.8)0.22%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
Excessive binary privileges in Ivanti Connect Secure before version 22.7R2.3 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.2 (Not Applicable to 9.1Rx) allows a local authenticated attacker to escalate privileges.
AnalizadaMedia (4.9)1.1%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.3 and Ivanti Policy Secure before version 22.7R1.2 allows a remote authenticated attacker with admin privileges to cause a denial of service.
ModificadaAlta (7.2)1.6%—Ivanti Connect SecureIvanti Policy Secure12/11/202417/6/2026
Command injection in Ivanti Connect Secure before version 22.7R2.1 (Not Applicable to 9.1Rx) and Ivanti Policy Secure before version 22.7R1.1 (Not Applicable to 9.1Rx) allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaAlta (8.8)71%💥 ExploitIvanti Connect SecureIvanti Policy Secure18/10/202417/6/2026
Improper Input Validation in the admin portal of Ivanti Connect Secure before 22.7R2.1 and 9.1R18.9, or Ivanti Policy Secure before 22.7R1.1 allows a remote authenticated attacker to achieve remote code execution.
AplazadaAlta (7.5)1.6%—Ivanti Connect SecureAIIvanti Policy SecureAI25/4/202417/6/2026
An Improper Check for Unusual or Exceptional Conditions vulnerability in the web component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) allows a remote unauthenticated attacker to send specially crafted requests in-order-to cause service disruptions.
Orbitaley — Vulnerabilidades