Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

1894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.3)0.36%—Nt-ware Uniflow OnlineNt-ware Uniflow Online Print & ScanNt-ware Uniflow Smartclient2/9/202417/6/2026
The registration process of uniFLOW Online (NT-ware product) apps, prior to and including version 2024.1.0, can be compromised when email login is enabled on the tenant. Those tenants utilising email login in combination with Microsoft Safe Links or similar are impacted. This vulnerability may allow the attacker to…
ModificadaMedia (6.5)0.32%—Serilog-contrib Serilog-enrichers-clientinfo29/8/202417/6/2026
Serilog before v2.1.0 was discovered to contain a Client IP Spoofing vulnerability, which allows attackers to falsify their IP addresses by specifying an arbitrary IP as a value of X-Forwarded-For or Client-Ip headers while performing HTTP requests.
AnalizadaAlta (7.3)0.17%—Dell Intel Thunderbolt Controller Firmware Update UtilityDell TPM 2.0 Firmware Update UtilityDell Alienware M15 R6 FirmwareDell Alienware M15 R7 Firmware+34228/8/202417/6/2026
Dell Dock Firmware and Dell Client Platform contain an Improper Link Resolution vulnerability during installation resulting in arbitrary folder deletion, which could lead to Privilege Escalation or Denial of Service.
AnalizadaAlta (7.5)0.84%—Barix SIP Client Firmware20/8/202417/6/2026
Barix – CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
AplazadaMedia (5.4)0.13%—Intel Unite Client Extended Display PluginAI14/8/202417/6/2026
Incorrect default permissions in some Intel Unite(R) Client Extended Display Plugin software installers before version 1.1.352.157 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6.7)0.15%—Dell Latitude 5290 2-in-1 FirmwareDell Precision 3420 Tower FirmwareDell Precision 3620 FirmwareDell Wyse 7040 Thin Client Firmware+3714/8/202417/6/2026
Dell BIOS contains an Improper Input Validation vulnerability in an externally developed component. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution.
AnalizadaAlta (7)0.43%—Microsoft Azure IOT HUB Device Client SDK13/8/202417/6/2026
Azure IoT SDK Remote Code Execution Vulnerability
AnalizadaAlta (7)0.48%—Microsoft Azure IOT HUB Device Client SDK13/8/202417/6/2026
Azure IoT SDK Remote Code Execution Vulnerability
AnalizadaAlta (8.8)1.3%—Microsoft Remote Desktop ClientMicrosoft Windows 10 1507Microsoft Windows 10 1607Microsoft Windows 10 1809+1213/8/202417/6/2026
Clipboard Virtual Channel Extension Remote Code Execution Vulnerability
AnalizadaCrítica (9.8)0.75%—Zscaler Client Connector6/8/202417/6/2026
An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2.
AnalizadaMedia (4.9)0.43%—Zscaler Client Connector6/8/202417/6/2026
In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1
AnalizadaAlta (7.8)0.13%—Zscaler Client Connector6/8/202417/6/2026
The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2.
AnalizadaAlta (7.8)0.11%—Zscaler Client Connector6/8/202417/6/2026
While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190.
AnalizadaAlta (7.5)0.23%—Zscaler Client Connector6/8/202417/6/2026
Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled.
AnalizadaMedia (6.5)0.19%—Zscaler Client Connector6/8/202417/6/2026
An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190.
ModificadaAlta (8.3)0.19%—Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Network Intrusion Detection SystemSiemens Omnivise T3000 Product Data Management+32/8/202417/6/2026
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Network Intrusion Detection System (NIDS) R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3…
ModificadaAlta (8.5)0.24%—Siemens Omnivise T3000 Application ServerSiemens Omnivise T3000 Domain ControllerSiemens Omnivise T3000 Product Data ManagementSiemens Omnivise T3000 Terminal Server+22/8/202417/6/2026
A vulnerability has been identified in Omnivise T3000 Application Server R9.2 (All versions), Omnivise T3000 Domain Controller R9.2 (All versions), Omnivise T3000 Product Data Management (PDM) R9.2 (All versions), Omnivise T3000 R8.2 SP3 (All versions), Omnivise T3000 R8.2 SP4 (All versions), Omnivise T3000 Terminal…
AnalizadaCrítica (9)0.44%—Johnsoncontrols Exacqvision ClientJohnsoncontrols Exacqvision Server1/8/202417/6/2026
Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange
AnalizadaAlta (8.8)0.14%—Catonetworks Cato Client31/7/202417/6/2026
Cato Networks Windows SDP Client Local root certificates can be installed by low-privileged users.This issue affects SDP Client: before 5.10.28.
AnalizadaMedia (6.5)0.23%—Catonetworks Cato Client31/7/202417/6/2026
A vulnerability in Cato Networks SDP Client on Windows allows the insertion of sensitive information into the log file, which can lead to an account takeover. However, the attack requires bypassing protections on modifying the tunnel token on a the attacker's system.This issue affects SDP Client: before 5.10.34.
AnalizadaAlta (8.8)0.27%—Catonetworks Cato Client31/7/202417/6/2026
Cato Networks Windows SDP Client Local Privilege Escalation via openssl configuration file. This issue affects SDP Client before 5.10.34.
AnalizadaAlta (7.8)0.24%—Catonetworks Cato Client31/7/202417/6/2026
Cato Networks Windows SDP Client Local Privilege Escalation via self-upgradeThis issue affects SDP Client: before 5.10.34.
AnalizadaAlta (8.8)0.80%—Catonetworks Cato Client31/7/202417/6/2026
Remote Code Execution in Cato Windows SDP client via crafted URLs. This issue affects Windows SDP Client before 5.10.34.
AnalizadaAlta (7.5)0.62%—Skygroup Skysea Client View29/7/202417/6/2026
Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable file may be executed by a user who can log in to the PC where the product's Windows client is installed.
ModificadaAlta (7.8)0.12%—Skygroup Skysea Client View29/7/202417/6/2026
Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed.