Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.9) | 5.8% | 💥 PoC | PuttyFilezilla-project Filezilla ClientWinscpTortoisegit+2 | 15/4/2024 | 17/6/2026 | In PuTTY 0.68 through 0.80 before 0.81, biased ECDSA nonce generation allows an attacker to recover a user's NIST P-521 secret key via a quick attack in approximately 60 signatures. This is especially important in a scenario where an adversary is able to read messages signed by PuTTY or Pageant. The required set of… | |
| Modificada | Alta (8.8) | 0.24% | — | Switchwp WP Client Reports | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in SwitchWP WP Client Reports.This issue affects WP Client Reports: from n/a through 1.0.22. | |
| Analizada | Alta (7.8) | 0.32% | — | Fortinet Forticlient | 10/4/2024 | 17/6/2026 | An external control of file name or path vulnerability [CWE-73] in FortiClientMac version 7.2.3 and below, version 7.0.10 and below installer may allow a local attacker to execute arbitrary code or commands via writing a malicious configuration file in /tmp before starting the installation process. | |
| Analizada | Media (4.4) | 0.18% | — | Dell Alienware M15 R6 FirmwareDell Alienware M15 R7 FirmwareDell Alienware M16 R1 FirmwareDell Alienware M18 R1 Firmware+264 | 10/4/2024 | 17/6/2026 | Dell BIOS contains an Out-of-Bounds Write vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Alta (8.8) | 1.5% | — | Fortinet Forticlient | 9/4/2024 | 17/6/2026 | An improper control of generation of code ('code injection') in Fortinet FortiClientLinux version 7.2.0, 7.0.6 through 7.0.10 and 7.0.3 through 7.0.4 allows attacker to execute unauthorized code or commands via tricking a FortiClientLinux user into visiting a malicious website | |
| Aplazada | Media (4.7) | 0.93% | 💥 PoC | Advanced Rest ClientAI | 4/4/2024 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in Advanced REST Client v.17.0.9 allows a remote attacker to execute arbitrary code and obtain sensitive information via a crafted script to the edit details parameter of the New Project function. | |
| Aplazada | Alta (7.3) | 0.41% | — | Instinct UI WEB ClientAI | 2/4/2024 | 17/6/2026 | A DOM-based open redirection in the returnUrl parameter of INSTINCT UI Web Client 6.5.0 allows attackers to redirect users to malicious sites via a crafted URL. | |
| Analizada | Alta (7.8) | 0.27% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | The ZScaler service is susceptible to a local privilege escalation vulnerability found in the ZScalerService process. Fixed Version: Mac ZApp 4.2.0.241 and later. | |
| Analizada | Alta (7.8) | 0.31% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | ZSATray passes the previousInstallerName as a config parameter to TrayManager, and TrayManager constructs the path and appends previousInstallerName to get the full path of the exe. Fixed Version: Win ZApp 4.3.0.121 and later. | |
| Analizada | Alta (7.8) | 0.24% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | In some rare cases, there is a password type validation missing in Revert Password check and for some features it could be disabled. Fixed Version: Win ZApp 4.3.0.121 and later. | |
| Analizada | Alta (7.1) | 0.31% | — | Zscaler Client Connector | 26/3/2024 | 17/6/2026 | An arbitrary file deletion in ZSATrayManager where it protects the temporary encrypted ZApp issue reporting file from the unprivileged end user access and modification. Fixed version: Win ZApp 4.3.0 and later. | |
| Aplazada | Alta (7.1) | 0.21% | — | Teamviewer Remote ClientAI | 26/3/2024 | 17/6/2026 | Insecure UNIX Symbolic Link (Symlink) Following in TeamViewer Remote Client prior Version 15.52 for macOS allows an attacker with unprivileged access, to potentially elevate privileges or conduct a denial-of-service-attack by overwriting the symlink. | |
| Aplazada | Media (5.5) | 0.16% | — | Mcafee Client ProxyAI | 14/3/2024 | 17/6/2026 | A malicious insider can uninstall Skyhigh Client Proxy without a valid uninstall password. | |
| Aplazada | Media (5.5) | 0.42% | 💥 PoC | Mcafee Client ProxyAI | 14/3/2024 | 17/6/2026 | A malicious insider can bypass the existing policy of Skyhigh Client Proxy without a valid release code. | |
| Analizada | Crítica (9.8) | 98% | ⚠ Explotación activa💥 Exploit | Fortinet Forticlient Enterprise Management Server | 12/3/2024 | 17/6/2026 | A improper neutralization of special elements used in an sql command ('sql injection') in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, FortiClientEMS 7.0.1 through 7.0.10 allows attacker to execute unauthorized code or commands via specially crafted packets. | |
| Modificada | Alta (8.8) | 1.1% | — | Fortinet Forticlient Endpoint Management Server | 12/3/2024 | 17/6/2026 | A improper neutralization of formula elements in a csv file in Fortinet FortiClientEMS version 7.2.0 through 7.2.2, 7.0.0 through 7.0.10, 6.4.0 through 6.4.9, 6.2.0 through 6.2.9, 6.0.0 through 6.0.8 allows attacker to execute unauthorized code or commands via specially crafted packets. | |
| Modificada | Media (6.5) | 0.43% | — | Siemens Sinema Remote Connect Client | 12/3/2024 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Client (All versions < V3.1 SP1). The product places sensitive information into files or directories that are accessible to actors who are allowed to have access to the files, but not to the sensitive information. This information is also available via the… | |
| Analizada | Media (6.3) | 0.41% | — | Skygroup Skysea Client View | 12/3/2024 | 17/6/2026 | Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed. | |
| Analizada | Alta (7.8) | 0.24% | — | Skygroup Skysea Client View | 12/3/2024 | 17/6/2026 | Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's Windows client is installed. In case… | |
| Analizada | Alta (7.3) | 0.89% | 💥 PoC | Cisco Secure Client | 6/3/2024 | 17/6/2026 | A vulnerability in the ISE Posture (System Scan) module of Cisco Secure Client for Linux could allow an authenticated, local attacker to elevate privileges on an affected device. This vulnerability is due to the use of an uncontrolled search path element. An attacker could exploit this vulnerability by copying a… | |
| Analizada | Alta (8.2) | 30% | — | Cisco Secure Client | 6/3/2024 | 17/6/2026 | A vulnerability in the SAML authentication process of Cisco Secure Client could allow an unauthenticated, remote attacker to conduct a carriage return line feed (CRLF) injection attack against a user. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this… | |
| Analizada | Alta (7.8) | 0.19% | — | Netiq Client Login Extension | 29/2/2024 | 17/6/2026 | Authorization Bypass Through User-Controlled Key vulnerability in NetIQ (OpenText) Client Login Extension on Windows allows Privilege Escalation, Code Injection.This issue only affects NetIQ Client Login Extension: 4.6. | |
| Modificada | Media (5.9) | 0.64% | — | Revmakx Infinitewp Client | 29/2/2024 | 17/6/2026 | The InfiniteWP Client plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 1.12.3 via the multi-call backup option. This makes it possible for unauthenticated attackers to extract sensitive data from a temporary SQL file via repeated GET requests during the limited… | |
| Analizada | Alta (7.8) | 0.34% | 💥 PoC | Thalesgroup Safenet Authentication Client | 27/2/2024 | 17/6/2026 | A flaw in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to execute code at a SYSTEM level via local access. | |
| Analizada | Alta (7.8) | 0.17% | — | Thalesgroup Safenet Authentication Client | 27/2/2024 | 17/6/2026 | A flaw in the Windows Installer in Thales SafeNet Authentication Client prior to 10.8 R10 on Windows allows an attacker to escalate their privilege level via local access. |