Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2636 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip SSL Orchestrator | 15/10/2025 | 17/6/2026 | When the BIG-IP system is configured as both a Security Assertion Markup Language (SAML) service provider (SP) and Identity Provider (IdP), with single logout (SLO) enabled on an access policy, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of… | |
| Analizada | Alta (8.7) | 0.43% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+19 | 15/10/2025 | 17/6/2026 | When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.5) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 30/9/2026 | A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell. For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note:… | |
| Analizada | Alta (7.1) | 0.66% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+3 | 14/10/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Analizada | Alta (7.1) | 0.48% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft ExcelMicrosoft Office+3 | 14/10/2025 | 17/6/2026 | Out-of-bounds read in Microsoft Office Excel allows an unauthorized attacker to disclose information locally. | |
| Aplazada | Crítica (9) | 0.75% | — | Claroty Secure AccessAI | 14/10/2025 | 8/9/2026 | An incorrect OIDC authentication flow in Claroty Secure Access 3.3.0 through 4.0.2 can result in unauthorized user creation or impersonation of existing OIDC users. | |
| Analizada | Crítica (9.8) | 0.29% | — | IBM Security Verify AccessIBM Verify Identity Access | 13/10/2025 | 17/6/2026 | IBM Security Verify Access 10.0.0 through 10.0.9, 11.0.0, IBM Verify Identity Access Container 10.0.0 through 10.0.9, and 11.0.0, under certain configurations, contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external… | |
| Aplazada | Media (4.3) | 0.16% | — | WEB Accessibility BY AccessibeAI | 11/10/2025 | 30/9/2026 | The Web Accessibility By accessiBe plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 2.10. This is due to missing nonce validation on multiple AJAX actions including accessibe_signup, accessibe_login, accessibe_license_trial, accessibe_modify_config, and… | |
| Analizada | Crítica (9.3) | 0.19% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to escalate their privileges to root due to execution with more privileges than required. | |
| Analizada | Alta (8.5) | 0.17% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow a locally authenticated user to execute malicious scripts from outside of its control sphere. | |
| Analizada | Alta (7.3) | 0.33% | — | IBM Security Verify AccessIBM Security Verify Access DockerIBM Verify Identity AccessIBM Verify Identity Access Docker | 6/10/2025 | 17/6/2026 | IBM Security Verify Access and IBM Security Verify Access Docker 10.0.0.0 through 10.0.9.0 and 11.0.0.0 through 11.0.1.0 could allow an unauthenticated user to execute arbitrary commands with lower user privileges on the system due to improper validation of user supplied input. | |
| Analizada | Media (4.6) | 0.21% | — | Absolute Secure Access | 2/10/2025 | 17/6/2026 | CVE-2025-54089 is a cross-site scripting vulnerability in versions of secure access prior to 14.10. Attackers with administrative access to the console can interfere with another administrator’s access to the console. The attack complexity is low; there are no attack requirements. Privileges required to execute the… | |
| Analizada | Media (5.5) | 0.18% | — | Absolute Secure Access | 2/10/2025 | 17/6/2026 | CVE-2025-54088 is an open-redirect vulnerability in Secure Access prior to version 14.10. Attackers with access to the console can redirect victims to an arbitrary URL. The attack complexity is low, attack requirements are present, no privileges are required, and users must actively participate in the attack. Impact… | |
| Analizada | Baja (1.8) | 0.18% | — | Absolute Secure Access | 2/10/2025 | 17/6/2026 | CVE-2025-54087 is a server-side request forgery vulnerability in Secure Access prior to version 14.10. Attackers with administrative privileges can publish a crafted test HTTP request originating from the Secure Access server. The attack complexity is high, there are no attack requirements, and user interaction is… | |
| Analizada | Media (5.3) | 0.18% | — | Absolute Secure Access | 2/10/2025 | 17/6/2026 | CVE-2025-54086 is an excess permissions vulnerability in the Warehouse component of Absolute Secure Access prior to version 14.10. Attackers with access to the local file system can read the Java keystore file. The attack complexity is low, there are no attack requirements, the privileges required are low and no user… | |
| Aplazada | Alta (7.1) | 0.12% | — | Taraprasad Swain Htaccess IP BlockerAI | 26/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Taraprasad Swain HTACCESS IP Blocker htaccess-ip-blocker allows Stored XSS.This issue affects HTACCESS IP Blocker: from n/a through <= 1.0. | |
| Aplazada | Media (4.3) | 0.17% | — | Cisco Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the IPv6 Router Advertisement (RA) packet processing of Cisco Access Point Software could allow an unauthenticated, adjacent attacker to modify the IPv6 gateway on an affected device. This vulnerability is due to a logic error in the processing of IPv6 RA packets that are received from wireless… | |
| Aplazada | Media (4.3) | 0.12% | — | Cisco Wireless Access Point SoftwareAI | 24/9/2025 | 25/9/2026 | A vulnerability in the Device Analytics action frame processing of Cisco Wireless Access Point (AP) Software could allow an unauthenticated, adjacent attacker to inject wireless 802.11 action frames with arbitrary information. This vulnerability is due to insufficient verification checks of incoming 802.11 action… | |
| Aplazada | Media (4.3) | 0.24% | — | Azizul Hasan Text TO Speech TTS AccessibilityAI | 22/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Azizul Hasan Text To Speech TTS Accessibility text-to-audio allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Text To Speech TTS Accessibility: from n/a through <= 1.9.30. | |
| Analizada | Baja (2.1) | 0.39% | — | Itsourcecode Online Public Access Catalog | 17/9/2025 | 25/9/2026 | A security vulnerability has been detected in itsourcecode Online Public Access Catalog OPAC 1.0. This impacts an unknown function of the file mysearch.php of the component POST Parameter Handler. Such manipulation of the argument search_field/search_text leads to sql injection. The attack may be performed from… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Sophos AP6 Series Wireless Access PointAI | 9/9/2025 | 17/6/2026 | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7). | |
| Analizada | Crítica (9.3) | 0.66% | — | Opexustech Foiaxpress Public Access Link | 9/9/2025 | 30/9/2026 | OPEXUS FOIAXpress Public Access Link (PAL) before version 11.13.1.0 allows SQL injection via SearchPopularDocs.aspx. A remote, unauthenticated attacker could read, write, or delete any content in the underlying database. | |
| Aplazada | Media (5.4) | 0.17% | — | Equalize Digital Accessibility CheckerAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0. | |
| Aplazada | Media (4.3) | 0.21% | — | Equalize Digital Accessibility CheckerAI | 9/9/2025 | 17/6/2026 | Missing Authorization vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.31.0. | |
| Analizada | Media (5.4) | 0.45% | — | Ivanti Neurons FOR Secure AccessIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway | 9/9/2025 | 17/6/2026 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure… |