Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
5089 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2.8) | 0.17% | — | Heimdalsecurity ThorAI | 20/7/2025 | 17/6/2026 | Thor before 1.4.0 can construct an unsafe shell command from library input. NOTE: this is disputed by the Supplier because "the method that was fixed can only be used with arguments that are controlled by Thor, and there is no way an attacker can take control of those arguments." | |
| Analizada | Baja (2) | 0.25% | — | Phpgurukul Online Security Guards Hiring System | 18/7/2025 | 17/6/2026 | A vulnerability was found in PHPGurukul Online Security Guards Hiring System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/search.php. The manipulation of the argument searchdata leads to cross site scripting. The attack can be initiated remotely. The exploit has… | |
| Aplazada | Alta (8.8) | 0.76% | — | Mingyu Security GatewayAI | 17/7/2025 | 17/6/2026 | Mingyu Security Gateway before v3.0-5.3p was discovered to contain a remote command execution (RCE) vulnerability via the log_type parameter at /log/fw_security.mds. | |
| Analizada | Media (5.4) | 0.19% | — | IBM Qradar Security Information AND Event Manager | 15/7/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 - 7.5.0 UP12 IF02 is vulnerable to stored cross-site scripting. This vulnerability allows authenticated users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Aplazada | Alta (8.5) | 0.37% | 💥 Exploit | Pandasecurity Global ProtectionAIPandasecurity Antivirus PROAIPandasecurity Small Business ProtectionAIPandasecurity Internet SecurityAI | 15/7/2025 | 17/6/2026 | PSEvents.exe in multiple Panda Security products runs hourly with SYSTEM privileges and loads DLL files from a user-writable directory without proper validation. An attacker with low-privileged access who can write DLL files to the monitored directory can achieve arbitrary code execution with SYSTEM privileges.… | |
| Analizada | Media (6.4) | 0.44% | — | Juniper Security Director | 11/7/2025 | 17/6/2026 | A Missing Authorization vulnerability in Juniper Networks Security Director allows an unauthenticated network-based attacker to read or tamper with multiple sensitive resources via the web interface. Numerous endpoints on the Juniper Security Director appliance do not validate authorization and will deliver… | |
| Aplazada | Media (6.8) | 0.14% | — | Eset Security ProductsAI | 11/7/2025 | 17/6/2026 | Installation file of ESET security products on Windows allow an attacker to misuse to delete an arbitrary file without having the permissions to do so. | |
| Analizada | Crítica (9.8) | 0.75% | — | Trendmicro Worry-free Business Security Services | 10/7/2025 | 17/6/2026 | A missing authentication vulnerability in Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an unauthenticated attacker to remotely take control of the agent on affected installations. Also note: this vulnerability only affected the SaaS client version of WFBSS only, meaning the… | |
| Analizada | Alta (7.1) | 0.36% | — | Trendmicro Maximum Security 2022 | 10/7/2025 | 17/6/2026 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. | |
| Modificada | Media (4.3) | 0.21% | — | Jenkins Aqua Security Scanner | 9/7/2025 | 17/6/2026 | Jenkins Aqua Security Scanner Plugin 3.2.8 and earlier stores Scanner Tokens for Aqua API unencrypted in job config.xml files on the Jenkins controller, where they can be viewed by users with Item/Extended Read permission or access to the Jenkins controller file system. | |
| Analizada | Baja (2.9) | 0.74% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Comodo Internet Security Premium 12.3.4.8162. Affected is an unknown function of the component File Name Handler. The manipulation of the argument name/folder leads to path traversal. It is possible to launch the attack remotely. The complexity of an… | |
| Analizada | Alta (8.2) | 4.1% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Comodo Internet Security Premium 12.3.4.8162. This issue affects some unknown processing of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation of the argument binary/params leads to os command injection. The attack… | |
| Analizada | Alta (8.2) | 0.48% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability classified as critical was found in Comodo Internet Security Premium 12.3.4.8162. This vulnerability affects unknown code of the file cis_update_x64.xml of the component Manifest File Handler. The manipulation leads to improper validation of integrity check value. The attack can be initiated remotely.… | |
| Analizada | Media (6.3) | 0.29% | — | Comodo Internet Security | 6/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Comodo Internet Security Premium 12.3.4.8162. This affects an unknown part of the component Update Handler. The manipulation leads to improper certificate validation. It is possible to initiate the attack remotely. The complexity of an attack is rather high. The… | |
| Aplazada | Media (6.5) | 0.23% | — | Dsrodzin Email Address Security BY WebemailprotectorAI | 4/7/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dsrodzin Email Address Security by WebEmailProtector webemailprotector allows Stored XSS.This issue affects Email Address Security by WebEmailProtector: from n/a through <= 3.3.6. | |
| Aplazada | Media (6.5) | 0.38% | — | ModsecurityAI | 2/7/2025 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. In versions 2.9.8 to before 2.9.11, an empty XML tag can cause a segmentation fault. If SecParseXmlIntoArgs is set to On or OnlyArgs, and the request type is application/xml, and at least one XML tag is empty… | |
| Aplazada | Crítica (10) | 22% | — | Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI | 2/7/2025 | 17/6/2026 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger… | |
| Analizada | Media (6.2) | 0.17% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 stores potentially sensitive information in log files that could be read by a local user. | |
| Analizada | Alta (7.1) | 0.48% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Crítica (9.1) | 0.55% | — | IBM Qradar Security Information AND Event Manager | 19/6/2025 | 17/6/2026 | IBM QRadar SIEM 7.5 through 7.5.0 Update Package 12 could allow a privileged user to modify configuration files that would allow the upload of a malicious autoupdate file to execute arbitrary commands. | |
| Analizada | Alta (7.1) | 0.18% | — | Trendmicro Maximum Security 2022 | 17/6/2025 | 17/6/2026 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. | |
| Analizada | Alta (7.1) | 0.17% | — | Trendmicro Maximum Security 2022 | 17/6/2025 | 17/6/2026 | Trend Micro Security 17.8 (Consumer) is vulnerable to a link following local privilege escalation vulnerability that could allow a local attacker to unintentionally delete privileged Trend Micro files including its own. | |
| Analizada | Media (5.5) | 0.17% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to create a denial of service (DoS) situation on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in the anti-malware solution portion of Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.19% | — | Trendmicro Deep Security Agent | 17/6/2025 | 17/6/2026 | A link following vulnerability in Trend Micro Deep Security 20.0 agents could allow a local attacker to escalate privileges on affected installations. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. |