Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
78 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.73% | — | Securepoint Openvpn-client | 28/6/2021 | 17/6/2026 | Securepoint SSL VPN Client v2 before 2.0.32 on Windows has unsafe configuration handling that enables local privilege escalation to NT AUTHORITY\SYSTEM. A non-privileged local user can modify the OpenVPN configuration stored under "%APPDATA%\Securepoint SSL VPN" and add a external script file that is executed as… | |
| Modificada | Alta (7.8) | 0.31% | — | Aviatrix VPN Client | 29/4/2021 | 17/6/2026 | Aviatrix VPN Client before 2.14.14 on Windows has an unquoted search path that enables local privilege escalation to the SYSTEM user, if the machine is misconfigured to allow unprivileged users to write to directories that are supposed to be restricted to administrators. | |
| Modificada | Alta (8.6) | 1.2% | — | Sonicwall Global VPN Client | 28/10/2020 | 17/6/2026 | SonicWall Global VPN client version 4.10.4.0314 and earlier have an insecure library loading (DLL hijacking) vulnerability. Successful exploitation could lead to remote code execution in the target system. | |
| Modificada | Alta (7.8) | 0.58% | — | Sonicwall Global VPN Client | 28/10/2020 | 17/6/2026 | SonicWall Global VPN client version 4.10.4.0314 and earlier allows unprivileged windows user to elevate privileges to SYSTEM through loaded process hijacking vulnerability. | |
| Modificada | Alta (7.5) | 2.5% | — | Privateinternetaccess Private Internet Access VPN Client | 14/9/2020 | 17/6/2026 | A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic. Since 1.5, PIA has supported a “split tunnel” OpenVPN bypass option. The PIA killswitch &… | |
| Modificada | Crítica (9.8) | 2.3% | — | Aviatrix ControllerAviatrix GatewayAviatrix VPN Client | 22/5/2020 | 17/6/2026 | An Elevation of Privilege issue was discovered in Aviatrix VPN Client before 2.10.7, because of an incomplete fix for CVE-2020-7224. This affects Linux, macOS, and Windows installations for certain OpenSSL parameters. | |
| Modificada | Media (5.3) | 1.4% | — | Aviatrix ControllerAviatrix VPN Client | 22/5/2020 | 17/6/2026 | An issue was discovered in Aviatrix Controller before 5.4.1204. There is a Observable Response Discrepancy from the API, which makes it easier to perform user enumeration via brute force. | |
| Modificada | Alta (7.8) | 0.57% | — | Aviatrix VPN Client | 5/12/2019 | 17/6/2026 | Weak file permissions applied to the Aviatrix VPN Client through 2.2.10 installation directory on Windows and Linux allow a local attacker to execute arbitrary code by gaining elevated privileges through file modifications. | |
| Modificada | Alta (7.8) | 0.72% | — | Aviatrix VPN Client | 5/12/2019 | 17/6/2026 | An authentication flaw in the AVPNC_RP service in Aviatrix VPN Client through 2.2.10 allows an attacker to gain elevated privileges through arbitrary code execution on Windows, Linux, and macOS. | |
| Modificada | Media (6.7) | 0.66% | — | Forcepoint VPN Client | 20/9/2019 | 17/6/2026 | Forcepoint VPN Client for Windows versions lower than 6.6.1 have an unquoted search path vulnerability. This enables local privilege escalation to SYSTEM user. By default, only local administrators can write executables to the vulnerable directories. Forcepoint thanks Peleg Hadar of SafeBreach Labs for finding this… | |
| Modificada | Alta (7.8) | 0.81% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is setuid root. This binary accepts several parameters to update… | |
| Modificada | Alta (7.8) | 0.81% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. This binary executes /opt/pia/openvpn-64/openvpn, passing the parameters provided… | |
| Modificada | Alta (7.8) | 0.63% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS binary openvpn_launcher.64 is setuid root. This binary creates /tmp/pia_upscript.sh when executed. Because the file… | |
| Modificada | Alta (7.8) | 0.86% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating… | |
| Modificada | Alta (7.8) | 0.91% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby, which in turn attempts to load several… | |
| Modificada | Alta (7.8) | 2.1% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability during the software update process. The updater loads several… | |
| Modificada | Alta (7.1) | 0.58% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log option, which accepts a path as an argument. This parameter is… | |
| Modificada | Alta (7.1) | 0.64% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, local attacker to overwrite arbitrary files. When the client initiates a connection, the XML /tmp/pia-watcher.plist file is created. If the file exists, it will be… | |
| Modificada | Alta (7.4) | 1.4% | — | Synology SSL VPN Client | 1/4/2019 | 17/6/2026 | Lack of administrator control over security vulnerability in client.cgi in Synology SSL VPN Client before 1.2.5-0226 allows remote attackers to conduct man-in-the-middle attacks via the (1) command, (2) hostname, or (3) port parameter. | |
| Modificada | Alta (7.8) | 0.52% | — | Barracuda VPN Client | 21/3/2019 | 17/6/2026 | The barracudavpn component of the Barracuda VPN Client prior to version 5.0.2.7 for Linux, macOS, and OpenBSD runs as a privileged process and can allow an unprivileged local attacker to load a malicious library, resulting in arbitrary code executing as root. | |
| Modificada | Alta (8.1) | 0.75% | — | Synology SSL VPN Client | 6/7/2018 | 17/6/2026 | Improper restriction of communication channel to intended endpoints vulnerability in HTTP daemon in Synology SSL VPN Client before 1.2.4-0224 allows remote attackers to conduct man-in-the-middle attacks via a crafted payload. | |
| Modificada | Alta (7.5) | 0.44% | — | Fortinet ForticlientFortinet Forticlient Sslvpn Client | 26/4/2018 | 17/6/2026 | Users' VPN authentication credentials are unsafely encrypted in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2335 and below versions, due to the use of a static encryption key and weak encryption algorithms. | |
| Modificada | Alta (8.8) | 2.1% | — | Fortinet ForticlientFortinet Forticlient Sslvpn Client | 15/12/2017 | 17/6/2026 | An Information Disclosure vulnerability in Fortinet FortiClient for Windows 5.6.0 and below versions, FortiClient for Mac OSX 5.6.0 and below versions and FortiClient SSLVPN Client for Linux 4.4.2334 and below versions allows regular users to see each other's VPN authentication credentials due to improperly secured… | |
| Modificada | Alta (7.2) | 0.54% | — | Cisco VPN Client | 6/10/2015 | 17/6/2026 | Cisco VPN Client 5.x through 5.0.07.0440 uses weak permissions for vpnclient.ini, which allows local users to gain privileges by entering an arbitrary program name in the Command field of the ApplicationLauncher section. | |
| Modificada | Baja (2.6) | 2.0% | — | Strongswan VPN ClientCanonical Ubuntu LinuxDebian LinuxStrongswan | 10/6/2015 | 17/6/2026 | strongSwan 4.3.0 through 5.x before 5.3.2 and strongSwan VPN Client before 1.4.6, when using EAP or pre-shared keys for authenticating an IKEv2 connection, does not enforce server authentication restrictions until the entire authentication process is complete, which allows remote servers to obtain credentials by using… |