Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.18%—Skygroup Skysea Client View29/7/202417/6/2026
Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege.
AplazadaBaja (3.3)0.18%—Withsecure Elements AgentAIWithsecure Elements Client SecurityAI26/7/202417/6/2026
An issue was discovered in WithSecure Elements Agent through 23.x for macOS and WithSecure Elements Client Security through 23.x for macOS. Local users can block an admin from completing an installation, aka a Denial-of-Service (DoS).
AplazadaMedia (5.8)0.18%—Withsecure Elements AgentAIWithsecure Elements Client SecurityAIWithsecure MDRAI26/7/202417/6/2026
An issue was discovered in WithSecure Elements Agent through 23.x for macOS, WithSecure Elements Client Security through 23.x for macOS, and WithSecure MDR through 23.x for macOS. Local Privilege Escalation can occur during installations or updates by admins.
AplazadaAlta (7.2)0.51%—Full ClienteAI11/7/202417/6/2026
The FULL – Cliente plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the license plan parameter in all versions up to, and including, 3.1.12 due to insufficient input sanitization and output escaping as well as missing authorization and capability checks on the related functions. This makes it…
ModificadaAlta (7.5)1.0%—Siemens Sinema Remote Connect Client9/7/202417/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an administrative remote attacker running a…
ModificadaAlta (8.5)0.90%—Siemens Sinema Remote Connect Client9/7/202417/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading proxy configurations. This could allow an authenticated local attacker to execute…
AnalizadaAlta (8.5)0.90%—Siemens Sinema Remote Connect Client9/7/202417/6/2026
A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.2 HF1). The system service of affected applications is vulnerable to command injection due to missing server side input sanitation when loading VPN configurations. This could allow an authenticated local attacker to execute…
ModificadaMedia (6.5)0.30%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/7/202417/6/2026
SAP CRM WebClient does not perform necessary authorization check for an authenticated user, resulting in escalation of privileges. This could allow an attacker to access some sensitive information.
ModificadaAlta (7.7)0.31%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/7/202417/6/2026
SAP CRM (WebClient UI Framework) allows an authenticated attacker to enumerate accessible HTTP endpoints in the internal network by specially crafting HTTP requests. On successful exploitation this can result in information disclosure. It has no impact on integrity and availability of the application.
ModificadaMedia (6.1)0.26%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/7/202417/6/2026
Custom CSS support option in SAP CRM WebClient UI does not sufficiently encode user-controlled inputs resulting in Cross-Site Scripting vulnerability. On successful exploitation an attacker can cause limited impact on confidentiality and integrity of the application.
ModificadaMedia (6.1)0.27%—SAP Customer Relationship Management S4fndSAP Customer Relationship Management Webclient UI9/7/202417/6/2026
—
ModificadaMedia (6.7)0.15%—Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+3842/7/202417/6/2026
Dell BIOS contains an improper input validation vulnerability. A local authenticated malicious user with admin privileges may potentially exploit this vulnerability to modify a UEFI variable, leading to denial of service and escalation of privileges
AnalizadaAlta (7.8)0.12%—HP Elitebook 745 G4 FirmwareHP Elitebook 745 G5 FirmwareHP Elitebook 745 G6 FirmwareHP Elitebook 755 G4 Firmware+34928/6/202417/6/2026
A potential Time-of-Check to Time-of Use (TOCTOU) vulnerability has been identified in the HP BIOS for certain HP PC products, which might allow arbitrary code execution, denial of service, and information disclosure. HP is releasing BIOS updates to mitigate the potential vulnerability.
AplazadaAlta (8.8)0.51%—Aimeos Ai-client-htmlAI25/6/202417/6/2026
ai-client-html is an Aimeos e-commerce HTML client component. Debug information revealed sensitive information from environment variables in error log. This issue has been patched in versions 2024.04.7, 2023.10.15, 2022.10.13 and 2021.10.22.
AplazadaMedia (4)0.16%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered.
AplazadaCrítica (9.8)0.51%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed.
AplazadaCrítica (9.8)0.43%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the PC.
AplazadaMedia (6.3)0.22%—Ricoh Streamline NX PC ClientAI19/6/202417/6/2026
Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed.
ModificadaAlta (7)0.19%—Aveva PI Asset Framework Client12/6/202417/6/2026
There is a vulnerability in AVEVA PI Asset Framework Client that could allow malicious code to execute on the PI System Explorer environment under the privileges of an interactive user that was socially engineered to import XML supplied by an attacker.
AplazadaMedia (5.3)0.55%—Aimeos Html ClientAI11/6/202417/6/2026
The Aimeos HTML client provides Aimeos HTML components for e-commerce projects. Starting in version 2020.04.1 and prior to versions 2020.10.27, 2021.10.21, 2022.10.12, 2023.10.14, and 2024.04.5, digital downloads sold in online shops can be downloaded without valid payment, e.g. if the payment didn't succeed. Versions…
ModificadaMedia (6.1)0.27%—SAP Customer Relationship Management Webclient UI11/6/202417/6/2026
Due to insufficient input validation, SAP CRM WebClient UI allows an unauthenticated attacker to craft a URL link which embeds a malicious script. When a victim clicks on this link, the script will be executed in the victim's browser giving the attacker the ability to access and/or modify information with no effect on…
AnalizadaAlta (7.3)0.31%—Ivanti Secure Access Client31/5/202417/6/2026
A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.
AnalizadaAlta (7.8)0.34%—Ivanti Secure Access Client31/5/202417/6/2026
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
AplazadaAlta (7.1)0.25%—Amazon AWS Client VPNAI28/5/202417/6/2026
Amazon AWS Client VPN before 3.9.1 on macOS has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions, a different vulnerability than CVE-2024-30164.
AplazadaMedia (6.7)0.27%—Amazon AWS Client VPNAI28/5/202417/6/2026
Amazon AWS Client VPN has a buffer overflow that could potentially allow a local actor to execute arbitrary commands with elevated permissions. This is resolved in 3.11.1 on Windows, 3.9.1 on macOS, and 3.12.1 on Linux. NOTE: although the macOS resolution is the same as for CVE-2024-30165, this vulnerability on macOS…