Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.3) | 0.36% | — | Nt-ware Uniflow OnlineNt-ware Uniflow Online Print & ScanNt-ware Uniflow Smartclient | 2/9/2024 | 17/6/2026 | The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to… | |
| Modificada | Media (6.5) | 0.32% | — | Serilog-contrib Serilog-enrichers-clientinfo | 29/8/2024 | 17/6/2026 | Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests. | |
| Analizada | Alta (7.3) | 0.17% | — | Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+342 | 28/8/2024 | 17/6/2026 | Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service. | |
| Analizada | Alta (7.5) | 0.84% | — | Barix SIP Client Firmware | 20/8/2024 | 17/6/2026 | Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Unite Client Extended Display PluginAI | 14/8/2024 | 17/6/2026 | Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.7) | 0.15% | — | Dell Latitude 5290 2-in-1 FirmwareDell Precision 3420 Tower FirmwareDell Precision 3620 FirmwareDell Wyse 7040 Thin Client Firmware+37 | 14/8/2024 | 17/6/2026 | Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (7) | 0.43% | — | Microsoft Azure IOT HUB Device Client SDK | 13/8/2024 | 17/6/2026 | Azure IoT SDK Remote Code Execution Vulnerability | |
| Analizada | Alta (7) | 0.48% | — | Microsoft Azure IOT HUB Device Client SDK | 13/8/2024 | 17/6/2026 | Azure IoT SDK Remote Code Execution Vulnerability | |
| Analizada | Alta (8.8) | 1.3% | — | Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+12 | 13/8/2024 | 17/6/2026 | Clipboard Virtual Channel Extension Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 0.75% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2. | |
| Analizada | Media (4.9) | 0.43% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1 | |
| Analizada | Alta (7.8) | 0.13% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2. | |
| Analizada | Alta (7.8) | 0.11% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190. | |
| Analizada | Alta (7.5) | 0.23% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled. | |
| Analizada | Media (6.5) | 0.19% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190. | |
| Modificada | Alta (8.3) | 0.19% | — | Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Network Intrusion Detection SystemSiemens Omnivise T3000 Product Data Management+3 | 2/8/2024 | 17/6/2026 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3… | |
| Modificada | Alta (8.5) | 0.24% | — | Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Product Data ManagementSiemens Omnivise T3000 Terminal Server+2 | 2/8/2024 | 17/6/2026 | A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions), Omnivise T3000 Terminal… | |
| Analizada | Crítica (9) | 0.44% | — | Johnsoncontrols Exacqvision ClientJohnsoncontrols Exacqvision Server | 1/8/2024 | 17/6/2026 | Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange | |
| Analizada | Alta (8.8) | 0.14% | — | Catonetworks Cato Client | 31/7/2024 | 17/6/2026 | Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28. | |
| Analizada | Media (6.5) | 0.23% | — | Catonetworks Cato Client | 31/7/2024 | 17/6/2026 | A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue affects SDP Client: before 5.10.34. | |
| Analizada | Alta (8.8) | 0.27% | — | Catonetworks Cato Client | 31/7/2024 | 17/6/2026 | Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34. | |
| Analizada | Alta (7.8) | 0.24% | — | Catonetworks Cato Client | 31/7/2024 | 17/6/2026 | Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34. | |
| Analizada | Alta (8.8) | 0.80% | — | Catonetworks Cato Client | 31/7/2024 | 17/6/2026 | Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34. | |
| Analizada | Alta (7.5) | 0.62% | — | Skygroup Skysea Client View | 29/7/2024 | 17/6/2026 | Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable file may be executed by a user who can log in to the PC where the product's Windows client is installed. | |
| Modificada | Alta (7.8) | 0.12% | — | Skygroup Skysea Client View | 29/7/2024 | 17/6/2026 | Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed. |