Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2636 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.33% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to execute limited actions on behalf of the victim user. User… | |
| Analizada | Alta (7.6) | 0.56% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure… | |
| Analizada | Alta (8.8) | 0.61% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to execute sensitive actions on behalf of the victim user.… | |
| Analizada | Media (4.9) | 0.80% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial… | |
| Analizada | Alta (8.9) | 0.65% | — | Ivanti Neurons FOR Secure AccessIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway | 9/9/2025 | 17/6/2026 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker to hijack existing HTML5 connections. | |
| Analizada | Media (5.4) | 0.56% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure… | |
| Analizada | Media (6.1) | 0.71% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | Reflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to inject arbitrary text into a crafted… | |
| Analizada | Alta (8.8) | 0.93% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure… | |
| Analizada | Alta (8.8) | 0.93% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure… | |
| Analizada | Media (6.8) | 0.91% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to enumerate internal services. | |
| Analizada | Crítica (9.8) | 0.72% | — | Avigilon Access Control Manager | 8/9/2025 | 17/6/2026 | A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file. | |
| Analizada | Crítica (9.8) | 2.9% | 💥 Exploit | Avigilon Access Control Manager | 8/9/2025 | 17/6/2026 | A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL. | |
| Aplazada | Media (4.3) | 0.13% | — | Pluginsandsnippets Simple Page Access RestrictionAI | 27/8/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Plugins and Snippets Simple Page Access Restriction simple-page-access-restriction allows Cross Site Request Forgery.This issue affects Simple Page Access Restriction: from n/a through <= 1.0.32. | |
| Aplazada | Media (5.4) | 0.24% | — | Equalize Digital Accessibility CheckerAI | 22/8/2025 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in Equalize Digital Accessibility Checker by Equalize Digital accessibility-checker allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Accessibility Checker by Equalize Digital: from n/a through <= 1.30.0. | |
| Aplazada | Media (6.5) | 0.43% | — | Miniorange Prevent Files Folders AccessAI | 20/8/2025 | 17/6/2026 | Path Traversal: '.../...//' vulnerability in miniOrange Prevent files / folders access prevent-file-access allows Path Traversal.This issue affects Prevent files / folders access: from n/a through <= 2.6.0. | |
| Analizada | Alta (8.8) | 0.25% | — | F5 Access | 13/8/2025 | 17/6/2026 | F5 Access for Android before version 3.1.2 which uses HTTPS does not verify the remote endpoint identity. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.9) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+22 | 13/8/2025 | 17/6/2026 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/8/2025 | 17/6/2026 | When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Analizada | Alta (7) | 0.11% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client | 13/8/2025 | 17/6/2026 | A missing file integrity check vulnerability exists on MacOS F5 VPN browser client installer that may allow a local, authenticated attacker with access to the local file system to replace it with a malicious package installer. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.34% | — | F5 Big-ip Access Policy Manager | 13/8/2025 | 17/6/2026 | When Network Access is configured on a BIG-IP APM virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.5) | 0.36% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files… | |
| Analizada | Media (4.9) | 0.68% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial of service | |
| Analizada | Alta (7.5) | 1.1% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service. | |
| Analizada | Alta (7.5) | 1.1% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.… | |
| Analizada | Media (5.4) | 0.46% | — | Checkpoint Mobile AccessCheckpoint Remote Access VPN | 6/8/2025 | 17/6/2026 | The Mobile Access Portal's File Share application is vulnerable to a directory traversal attack, allowing an authenticated, malicious end-user (authorized to at least one File Share application) to list the file names of 'nobody'-accessible directories on the Mobile Access gateway. |