Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

1894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.11%—Teamviewer ClientAI28/5/202417/6/2026
Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to further elevate privileges via executable sideloading.
AnalizadaAlta (7.8)0.40%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security22/5/202417/6/2026
WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an administrator is required to exploit this…
AnalizadaMedia (6.7)0.21%—Dell Edge Gateway 5000 FirmwareDell Precision 5820 Tower FirmwareDell Edge Gateway 3000 FirmwareDell Embedded BOX PC 3000 Firmware+4617/5/202417/6/2026
Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution.
AnalizadaMedia (6.8)0.35%—Cisco Secure Client15/5/202417/6/2026
A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the…
AnalizadaAlta (7.4)0.21%—F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client8/5/202417/6/2026
An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaBaja (2.8)0.18%—Knowbe4 Phish Alert Button FOR OutlookAIKnowbe4 Second Chance ClientAIKnowbe4 PIQ ClientAI7/5/202417/6/2026
A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allows a regular user to modify the application's configuration file to redirect update checks to an arbitrary server, which…
AplazadaMedia (6)0.37%—Knowbe4 Phish Alert ButtonAIKnowbe4 Second Chance ClientAIKnowbe4 PIQ ClientAI7/5/202417/6/2026
A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely execute arbitrary code on the host machine. The vulnerability arises from the application's failure to securely verify the authenticity and integrity of the…
AnalizadaAlta (7.6)4.1%💥 PoCFortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+56/5/202417/6/2026
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that…
AnalizadaAlta (7.8)0.97%—Ivanti Pulse Secure Desktop ClientIvanti Pulse Secure Installer ServiceIvanti Secure Access Client3/5/202417/6/2026
Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
AnalizadaAlta (7.5)0.19%—Zscaler Client Connector2/5/202417/6/2026
An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of service of the Client Connector binary and thus removing client functionality.This issue affects Client Connector on MacOS: before 3.4.
AnalizadaMedia (5.5)0.11%—Zscaler Client Connector2/5/202417/6/2026
An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade process may allow a Local Execution of Code.This issue affects Client Connector on MacOS: before 3.4.
AnalizadaCrítica (9.8)0.47%—Zscaler Client Connector2/5/202417/6/2026
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7.
AnalizadaAlta (7.8)0.19%—Zscaler Client Connector2/5/202417/6/2026
An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7.
AnalizadaAlta (7.8)0.11%—Zscaler Client Connector2/5/202417/6/2026
An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair App functionality may allow Local Execution of Code.This issue affects Client Connector on Windows: before 4.1.0.62.
AnalizadaCrítica (9.8)0.43%—Zscaler Client Connector2/5/202417/6/2026
An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution.
AnalizadaCrítica (9.8)0.30%—Zscaler Client Connector1/5/202417/6/2026
A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2.
AnalizadaAlta (7.8)0.20%—Zscaler Client Connector1/5/202417/6/2026
The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209
AnalizadaAlta (8.1)0.37%—Zscaler Client Connector30/4/202417/6/2026
Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1
AplazadaMedia (5.3)0.52%—Realbigplugins Client DashAI29/4/202417/6/2026
Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1.
AnalizadaCrítica (9.8)0.63%—Phpgurukul Client Management System17/4/202417/6/2026
SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter.
AnalizadaMedia (5.4)0.44%—Phpgurukul Client Management System17/4/202417/6/2026
Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter.
AnalizadaMedia (6.8)0.58%—Phpgurukul Client Management System17/4/202417/6/2026
Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar.
AnalizadaMedia (6.8)0.58%—Phpgurukul Client Management System17/4/202417/6/2026
Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters.
AnalizadaMedia (6.5)0.43%—Phpgurukul Client Management System17/4/202417/6/2026
Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" and "sname" parameter.
AnalizadaCrítica (9.8)0.69%—Phpgurukul Client Management System17/4/202417/6/2026
SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters.