Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.11% | — | Teamviewer ClientAI | 28/5/2024 | 17/6/2026 | Improper fingerprint validation in the TeamViewer Client (Full & Host) prior Version 15.54 for Windows and macOS allows an attacker with administrative user rights to further elevate privileges via executable sideloading. | |
| Analizada | Alta (7.8) | 0.40% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security | 22/5/2024 | 17/6/2026 | WithSecure Elements Endpoint Protection Link Following Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of WithSecure Elements Endpoint Protection. User interaction on the part of an administrator is required to exploit this… | |
| Analizada | Media (6.7) | 0.21% | — | Dell Edge Gateway 5000 FirmwareDell Precision 5820 Tower FirmwareDell Edge Gateway 3000 FirmwareDell Embedded BOX PC 3000 Firmware+46 | 17/5/2024 | 17/6/2026 | Dell BIOS contains an Improper Input Validation vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to arbitrary code execution. | |
| Analizada | Media (6.8) | 0.35% | — | Cisco Secure Client | 15/5/2024 | 17/6/2026 | A vulnerability in the Network Access Manager (NAM) module of Cisco Secure Client could allow an unauthenticated attacker with physical access to an affected device to elevate privileges to SYSTEM. This vulnerability is due to a lack of authentication on a specific function. A successful exploit could allow the… | |
| Analizada | Alta (7.4) | 0.21% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client | 8/5/2024 | 17/6/2026 | An origin validation vulnerability exists in BIG-IP APM browser network access VPN client for Windows, macOS and Linux which may allow an attacker to bypass F5 endpoint inspection. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Baja (2.8) | 0.18% | — | Knowbe4 Phish Alert Button FOR OutlookAIKnowbe4 Second Chance ClientAIKnowbe4 PIQ ClientAI | 7/5/2024 | 17/6/2026 | A local privilege escalation (LPE) vulnerability has been identified in Phish Alert Button for Outlook (PAB), specifically within its configuration management functionalities. This vulnerability allows a regular user to modify the application's configuration file to redirect update checks to an arbitrary server, which… | |
| Aplazada | Media (6) | 0.37% | — | Knowbe4 Phish Alert ButtonAIKnowbe4 Second Chance ClientAIKnowbe4 PIQ ClientAI | 7/5/2024 | 17/6/2026 | A medium severity vulnerability has been identified in the update mechanism of the Phish Alert Button for Outlook, which could allow an attacker to remotely execute arbitrary code on the host machine. The vulnerability arises from the application's failure to securely verify the authenticity and integrity of the… | |
| Analizada | Alta (7.6) | 4.1% | 💥 PoC | Fortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+5 | 6/5/2024 | 17/6/2026 | DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that… | |
| Analizada | Alta (7.8) | 0.97% | — | Ivanti Pulse Secure Desktop ClientIvanti Pulse Secure Installer ServiceIvanti Secure Access Client | 3/5/2024 | 17/6/2026 | Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Analizada | Alta (7.5) | 0.19% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS allows a denial of service of the Client Connector binary and thus removing client functionality.This issue affects Client Connector on MacOS: before 3.4. | |
| Analizada | Media (5.5) | 0.11% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on MacOS during the upgrade process may allow a Local Execution of Code.This issue affects Client Connector on MacOS: before 3.4. | |
| Analizada | Crítica (9.8) | 0.47% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Mac allows a system file to be overwritten.This issue affects Zscaler Client Connector on Mac : before 3.7. | |
| Analizada | Alta (7.8) | 0.19% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Link Resolution Before File Access ('Link Following') vulnerability in Zscaler Client Connector on Windows allows a system file to be overwritten.This issue affects Client Connector on Windows: before 3.7. | |
| Analizada | Alta (7.8) | 0.11% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An Improper Validation of Integrity Check Value vulnerability in Zscaler Client Connector on Windows during the Repair App functionality may allow Local Execution of Code.This issue affects Client Connector on Windows: before 4.1.0.62. | |
| Analizada | Crítica (9.8) | 0.43% | — | Zscaler Client Connector | 2/5/2024 | 17/6/2026 | An out-of-bounds write to heap in the pacparser library on Zscaler Client Connector on Mac may lead to arbitrary code execution. | |
| Analizada | Crítica (9.8) | 0.30% | — | Zscaler Client Connector | 1/5/2024 | 17/6/2026 | A fallback mechanism in code sign checking on macOS may allow arbitrary code execution. This issue affects Zscaler Client Connector on MacOS prior to 4.2. | |
| Analizada | Alta (7.8) | 0.20% | — | Zscaler Client Connector | 1/5/2024 | 17/6/2026 | The anti-tampering functionality of the Zscaler Client Connector can be disabled under certain conditions when an uninstall password is enforced. This affects Zscaler Client Connector on Windows prior to 4.2.0.209 | |
| Analizada | Alta (8.1) | 0.37% | — | Zscaler Client Connector | 30/4/2024 | 17/6/2026 | Anti-tampering protection of the Zscaler Client Connector can be bypassed under certain conditions when running the Repair App functionality. This affects Zscaler Client Connector on Windows prior to 4.2.1 | |
| Aplazada | Media (5.3) | 0.52% | — | Realbigplugins Client DashAI | 29/4/2024 | 17/6/2026 | Missing Authorization vulnerability in Real Big Plugins Client Dash.This issue affects Client Dash: from n/a through 2.2.1. | |
| Analizada | Crítica (9.8) | 0.63% | — | Phpgurukul Client Management System | 17/4/2024 | 17/6/2026 | SQL Injection vulnerability in the "Invoices" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "searchdata" parameter. | |
| Analizada | Media (5.4) | 0.44% | — | Phpgurukul Client Management System | 17/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in /edit-client-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code via the "cname", "comname", "state" and "city" parameter. | |
| Analizada | Media (6.8) | 0.58% | — | Phpgurukul Client Management System | 17/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in /search-invoices.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the Search bar. | |
| Analizada | Media (6.8) | 0.58% | — | Phpgurukul Client Management System | 17/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in /bwdates-reports-ds.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and obtain sensitive information via the fromdate and todate parameters. | |
| Analizada | Media (6.5) | 0.43% | — | Phpgurukul Client Management System | 17/4/2024 | 17/6/2026 | Cross Site Scripting vulnerability in /edit-services-details.php of phpgurukul Client Management System using PHP & MySQL 1.1 allows attackers to execute arbitrary code and via "price" and "sname" parameter. | |
| Analizada | Crítica (9.8) | 0.69% | — | Phpgurukul Client Management System | 17/4/2024 | 17/6/2026 | SQL Injection vulnerability in "B/W Dates Reports" page in phpgurukul Client Management System using PHP & MySQL 1.1 allows attacker to execute arbitrary SQL commands via "todate" and "fromdate" parameters. |