Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

5089 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.8)0.28%—Trendmicro Worry-free Business Security Services17/6/202517/6/2026
An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a machine to execute arbitrary code on affected installations. An attacker must have had physical access to the target system in order to exploit this…
AnalizadaAlta (7.8)0.12%—Trendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security ServicesTrendmicro Apex ONE17/6/202517/6/2026
An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain…
AnalizadaAlta (7.8)0.17%—IBM Security Verify Directory15/6/202517/6/2026
IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges.
AnalizadaMedia (5.3)0.34%—IBM Security Verify AccessIBM Security Verify Access Docker11/6/202517/6/2026
IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts.
AplazadaMedia (5.6)0.23%💥 PoCK7 Security Anti-malwareAIK7 Rkscan.sysAI11/6/202517/6/2026
A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating…
AnalizadaMedia (5.5)0.70%—Microsoft Windows Security APP10/6/202517/6/2026
External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally.
AnalizadaMedia (6.8)0.29%—Keepersecurity Keeperchat9/6/202517/6/2026
An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module
AplazadaMedia (4.3)0.15%—Vuong Nguyen WP Security MasterAI6/6/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master wp-security-master allows Cross Site Request Forgery.This issue affects WP Security Master: from n/a through <= 1.0.2.
AnalizadaCrítica (9.8)0.33%—IBM Security Verify Governance6/6/202517/6/2026
IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts.
AnalizadaAlta (8.8)0.32%—IBM Cloud PAK FOR SecurityIBM Qradar Suite3/6/202517/6/2026
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files.
AnalizadaAlta (7.2)0.64%—IBM Cloud PAK FOR SecurityIBM Qradar Suite3/6/202517/6/2026
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code.
AnalizadaMedia (6.5)0.43%—IBM Cloud PAK FOR SecurityIBM Qradar Suite3/6/202517/6/2026
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input.
AnalizadaMedia (6.5)0.26%—IBM Cloud PAK FOR SecurityIBM Qradar Suite3/6/202517/6/2026
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system.
AnalizadaMedia (4)0.18%—IBM Cloud PAK FOR SecurityIBM Qradar Suite3/6/202517/6/2026
IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system.
AnalizadaAlta (7.5)0.83%—Owasp Modsecurity2/6/202517/6/2026
ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to…
AnalizadaMedia (6.5)0.40%—IBM Security Guardium28/5/202517/6/2026
IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input.
AnalizadaMedia (4.3)0.28%—IBM Security Guardium28/5/202517/6/2026
IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check.
AnalizadaMedia (5.3)0.35%—IBM Security Guardium28/5/202517/6/2026
IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system.
ModificadaMedia (5.4)0.28%—Redhat Advanced Cluster SecurityStackrox27/5/202517/6/2026
A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a…
AnalizadaCrítica (9.8)0.65%—Tridium NiagaraTridium Niagara Enterprise Security22/5/202517/6/2026
Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security:…
AnalizadaCrítica (9.8)0.53%—Tridium NiagaraTridium Niagara Enterprise Security22/5/202517/6/2026
Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1,…
AnalizadaAlta (7.5)11%—Tridium NiagaraTridium Niagara Enterprise Security22/5/202517/6/2026
Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise…
AnalizadaAlta (7.5)0.29%—Tridium NiagaraTridium Niagara Enterprise Security22/5/202517/6/2026
Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before…
AnalizadaCrítica (9.8)0.53%—Tridium NiagaraTridium Niagara Enterprise Security22/5/202517/6/2026
Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2,…
AnalizadaCrítica (9.8)0.36%—Tridium NiagaraTridium Niagara Enterprise Security22/5/202517/6/2026
Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before…