Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
5089 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.8) | 0.28% | — | Trendmicro Worry-free Business Security Services | 17/6/2025 | 17/6/2026 | An uncontrolled search path vulnerability in the Trend Micro Worry-Free Business Security Services (WFBSS) agent could have allowed an attacker with physical access to a machine to execute arbitrary code on affected installations. An attacker must have had physical access to the target system in order to exploit this… | |
| Analizada | Alta (7.8) | 0.12% | — | Trendmicro Worry-free Business SecurityTrendmicro Worry-free Business Security ServicesTrendmicro Apex ONE | 17/6/2025 | 17/6/2026 | An insecure access control vulnerability in Trend Micro Apex One and Trend Micro Worry-Free Business Security could allow a local attacker to overwrite key memory-mapped files which could then have severe consequences for the security and stability of affected installations. Please note: an attacker must first obtain… | |
| Analizada | Alta (7.8) | 0.17% | — | IBM Security Verify Directory | 15/6/2025 | 17/6/2026 | IBM Security Verify Directory Container 10.0.0.0 through 10.0.3.1 could allow a local user to execute commands as root due to execution with unnecessary privileges. | |
| Analizada | Media (5.3) | 0.34% | — | IBM Security Verify AccessIBM Security Verify Access Docker | 11/6/2025 | 17/6/2026 | IBM Security Verify Access Appliance and Docker 10.0 through 10.0.8 could allow a remote attacker to enumerate usernames due to an observable response discrepancy of disabled accounts. | |
| Aplazada | Media (5.6) | 0.23% | 💥 PoC | K7 Security Anti-malwareAIK7 Rkscan.sysAI | 11/6/2025 | 17/6/2026 | A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating… | |
| Analizada | Media (5.5) | 0.70% | — | Microsoft Windows Security APP | 10/6/2025 | 17/6/2026 | External control of file name or path in Windows Security App allows an authorized attacker to perform spoofing locally. | |
| Analizada | Media (6.8) | 0.29% | — | Keepersecurity Keeperchat | 9/6/2025 | 17/6/2026 | An issue in KeeperChat IOS Application v.5.8.8 allows a physically proximate attacker to escalate privileges via the Biometric Authentication Module | |
| Aplazada | Media (4.3) | 0.15% | — | Vuong Nguyen WP Security MasterAI | 6/6/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Vuong Nguyen WP Security Master wp-security-master allows Cross Site Request Forgery.This issue affects WP Security Master: from n/a through <= 1.0.2. | |
| Analizada | Crítica (9.8) | 0.33% | — | IBM Security Verify Governance | 6/6/2025 | 17/6/2026 | IBM Security Verify Governance 10.0.2 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | |
| Analizada | Alta (8.8) | 0.32% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an unauthenticated user in the environment to obtain highly sensitive information in configuration files. | |
| Analizada | Alta (7.2) | 0.64% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow a privileged execute code in case management script creation due to the improper generation of code. | |
| Analizada | Media (6.5) | 0.43% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 could allow an authenticated user to cause a denial of service due to improperly validating API data input. | |
| Analizada | Media (6.5) | 0.26% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 does not invalidate session after a logout which could allow a user to impersonate another user on the system. | |
| Analizada | Media (4) | 0.18% | — | IBM Cloud PAK FOR SecurityIBM Qradar Suite | 3/6/2025 | 17/6/2026 | IBM QRadar Suite Software 1.10.12.0 through 1.11.2.0 and IBM Cloud Pak for Security 1.10.0.0 through 1.10.11.0 allows web pages to be stored locally which can be read by another user on the system. | |
| Analizada | Alta (7.5) | 0.83% | — | Owasp Modsecurity | 2/6/2025 | 17/6/2026 | ModSecurity is an open source, cross platform web application firewall (WAF) engine for Apache, IIS and Nginx. Versions prior to 2.9.10 contain a denial of service vulnerability similar to GHSA-859r-vvv8-rm8r/CVE-2025-47947. The `sanitiseArg` (and `sanitizeArg` - this is the same action but an alias) is vulnerable to… | |
| Analizada | Media (6.5) | 0.40% | — | IBM Security Guardium | 28/5/2025 | 17/6/2026 | IBM Security Guardium 12.0 could allow a privileged user to download any file on the system due to improper escaping of input. | |
| Analizada | Media (4.3) | 0.28% | — | IBM Security Guardium | 28/5/2025 | 17/6/2026 | IBM Security Guardium 12.0 could allow an authenticated user to obtain sensitive information due to an incorrect authentication check. | |
| Analizada | Media (5.3) | 0.35% | — | IBM Security Guardium | 28/5/2025 | 17/6/2026 | IBM Security Guardium 12.0 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Modificada | Media (5.4) | 0.28% | — | Redhat Advanced Cluster SecurityStackrox | 27/5/2025 | 17/6/2026 | A flaw was found in Stackrox, where it is vulnerable to Cross-site scripting (XSS) if the script code is included in a small subset of table cells. The only known potential exploit is if the script is included in the name of a Kubernetes “Role” object* that is applied to a secured cluster. This object can be used by a… | |
| Analizada | Crítica (9.8) | 0.65% | — | Tridium NiagaraTridium Niagara Enterprise Security | 22/5/2025 | 17/6/2026 | Improper Neutralization of Argument Delimiters in a Command ('Argument Injection') vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows Command Delimiters. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security:… | |
| Analizada | Crítica (9.8) | 0.53% | — | Tridium NiagaraTridium Niagara Enterprise Security | 22/5/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in Tridium Niagara Framework on QNX, Tridium Niagara Enterprise Security on QNX allows File Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2, before 4.15.1,… | |
| Analizada | Alta (7.5) | 11% | — | Tridium NiagaraTridium Niagara Enterprise Security | 22/5/2025 | 17/6/2026 | Use of GET Request Method With Sensitive Query Strings vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Parameter Injection. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise… | |
| Analizada | Alta (7.5) | 0.29% | — | Tridium NiagaraTridium Niagara Enterprise Security | 22/5/2025 | 17/6/2026 | Improper Output Neutralization for Logs vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before… | |
| Analizada | Crítica (9.8) | 0.53% | — | Tridium NiagaraTridium Niagara Enterprise Security | 22/5/2025 | 17/6/2026 | Improper Handling of Windows ::DATA Alternate Data Stream vulnerability in Tridium Niagara Framework on Windows, Tridium Niagara Enterprise Security on Windows allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before 4.14.2,… | |
| Analizada | Crítica (9.8) | 0.36% | — | Tridium NiagaraTridium Niagara Enterprise Security | 22/5/2025 | 17/6/2026 | Improper Use of Validation Framework vulnerability in Tridium Niagara Framework on Windows, Linux, QNX, Tridium Niagara Enterprise Security on Windows, Linux, QNX allows Input Data Manipulation. This issue affects Niagara Framework: before 4.14.2, before 4.15.1, before 4.10.11; Niagara Enterprise Security: before… |