Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.5) | 0.71% | — | Withsecure Client SecurityAIWithsecure Server SecurityAIWithsecure Email AND Server SecurityAIWithsecure Elements Endpoint ProtectionAI+5 | 26/2/2024 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because the engine scanner can go into an infinite loop when processing an archive file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later,… | |
| Analizada | Media (6.7) | 0.36% | — | Hexagon Qognify VMS Client Viewer | 26/2/2024 | 17/6/2026 | A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met. | |
| Modificada | Alta (7.2) | 0.82% | — | Fortinet Forticlient Enterprise Management Server | 15/2/2024 | 17/6/2026 | An improper privilege management vulnerability [CWE-269] in Fortinet FortiClientEMS version 7.2.0 through 7.2.2 and before 7.0.10 allows an Site administrator with Super Admin privileges to perform global administrative operations affecting other sites via crafted HTTP or HTTPS requests. | |
| Modificada | Media (6.5) | 1.7% | — | Zoom Meeting SDKZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Business logic error in some Zoom clients may allow an authenticated user to conduct information disclosure via network access. | |
| Modificada | Media (4.4) | 0.53% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper authentication in some Zoom clients may allow a privileged user to conduct a disclosure of information via local access. | |
| Modificada | Alta (7.8) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Untrusted search path in some Zoom 32 bit Windows clients may allow an authenticated user to conduct an escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.80% | — | Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Media (6.5) | 0.80% | — | Zoom Meeting Software Development KITZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an authenticated user to conduct a disclosure of information via network access. | |
| Modificada | Crítica (9.8) | 1.7% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom | 14/2/2024 | 17/6/2026 | Improper input validation in Zoom Desktop Client for Windows, Zoom VDI Client for Windows, and Zoom Meeting SDK for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access. | |
| Modificada | Media (6.5) | 0.57% | — | Zoom Meeting Software Development KITZoom RoomsZoom VDI Windows Meeting ClientsZoom Video Software Development KIT+1 | 14/2/2024 | 17/6/2026 | Improper input validation in some Zoom clients may allow an authenticated user to conduct a denial of service via network access. | |
| Modificada | Media (4.1) | 0.33% | — | SAP CRM - Webclient UI | 13/2/2024 | 17/6/2026 | SAP CRM WebClient UI - version S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, WEBCUIF 701, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An attacker with low privileges… | |
| Modificada | Media (5.4) | 0.32% | — | SAP CRM - Webclient UI | 13/2/2024 | 17/6/2026 | Print preview option in SAP CRM WebClient UI - versions S4FND 102, S4FND 103, S4FND 104, S4FND 105, S4FND 106, S4FND 107, S4FND 108, WEBCUIF 700, WEBCUIF 701, WEBCUIF 730, WEBCUIF 731, WEBCUIF 746, WEBCUIF 747, WEBCUIF 748, WEBCUIF 800, WEBCUIF 801, does not sufficiently encode user-controlled inputs, resulting in… | |
| Modificada | Media (6.1) | 0.35% | — | SAP Netweaver Business Client FOR Html | 13/2/2024 | 17/6/2026 | SAP NWBC for HTML - versions SAP_UI 754, SAP_UI 755, SAP_UI 756, SAP_UI 757, SAP_BASIS 700, SAP_BASIS 701, SAP_BASIS 702, SAP_BASIS 731, does not sufficiently encode user-controlled inputs, resulting in Cross-Site Scripting (XSS) vulnerability. An unauthenticated attacker can inject malicious javascript to cause… | |
| Modificada | Media (5.5) | 0.57% | 💥 Exploit | IBM I Access Client Solutions | 9/2/2024 | 17/6/2026 | IBM i Access Client Solutions (ACS) 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.4 is vulnerable to NT LAN Manager (NTLM) hash disclosure by an attacker modifying UNC capable paths within ACS configuration files to point to a hostile server. If NTLM is enabled, the Windows operating system will try to authenticate… | |
| Modificada | Media (6.7) | 0.17% | — | Withsecure Client SecurityWithsecure Server SecurityWithsecure Email AND Server SecurityWithsecure Elements Endpoint Protection | 8/2/2024 | 17/6/2026 | Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15 and later, WithSecure Server Security 15 and later, WithSecure Email and Server Security 15 and later, and WithSecure Elements Endpoint Protection 17 and later. | |
| Modificada | Media (4.4) | 0.16% | — | Dell Optiplex 3000 Micro FirmwareDell Optiplex 3000 Small Form Factor FirmwareDell Optiplex 3000 Tower FirmwareDell Optiplex 5000 Micro Firmware+287 | 6/2/2024 | 17/6/2026 | Dell BIOS contains a Signed to Unsigned Conversion Error vulnerability. A local authenticated malicious user with admin privileges could potentially exploit this vulnerability, leading to denial of service. | |
| Modificada | Media (6.1) | 0.39% | — | Apollographql Apollo Client | 30/1/2024 | 17/6/2026 | apollo-client-nextjs is the Apollo Client support for the Next.js App Router. The @apollo/experimental-apollo-client-nextjs NPM package is vulnerable to a cross-site scripting vulnerability. To exploit this vulnerability, an attacker would need to either inject malicious input (e.g. by redirecting a user to a… | |
| Modificada | Media (5.5) | 0.21% | — | Sonicwall Capture ClientSonicwall Netextender | 18/1/2024 | 17/6/2026 | SonicWall Capture Client version 3.7.10, NetExtender client version 10.2.337 and earlier versions are installed with sfpmonitor.sys driver. The driver has been found to be vulnerable to Denial-of-Service (DoS) caused by Stack-based Buffer Overflow vulnerability. | |
| Modificada | Alta (8.7) | 1.2% | — | Microsoft.data.sqlclientMicrosoft SQL ServerMicrosoft System.data.sqlclientMicrosoft Visual Studio 2022+2 | 9/1/2024 | 17/6/2026 | Microsoft.Data.SqlClient and System.Data.SqlClient SQL Data Provider Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.8) | 0.21% | — | Lenovo Universal Device Client | 3/1/2024 | 17/6/2026 | Uncontrolled search path vulnerabilities were reported in the Lenovo Universal Device Client (UDC) that could allow an attacker with local access to execute code with elevated privileges. | |
| Modificada | Crítica (9.8) | 1.2% | — | Mehah Otclient | 2/1/2024 | 17/6/2026 | OTCLient is an alternative tibia client for otserv. Prior to commit db560de0b56476c87a2f967466407939196dd254, the /mehah/otclient "`Analysis - SonarCloud`" workflow is vulnerable to an expression injection in Actions, allowing an attacker to run commands remotely on the runner, leak secrets, and alter the repository… | |
| Analizada | Media (4.8) | 0.54% | — | Fabian Client Details System | 29/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Client Details System 1.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the file /admin/regester.php. The manipulation of the argument fname/lname/email/contact leads to cross site scripting. The attack may be launched remotely.… | |
| Modificada | Crítica (9.8) | 0.64% | — | Fabian Client Details System | 29/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Client Details System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/clientview.php. The manipulation of the argument ID leads to sql injection. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.64% | — | Fabian Client Details System | 29/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Client Details System 1.0. It has been classified as problematic. Affected is an unknown function of the file /admin/update-clients.php. The manipulation of the argument uid leads to sql injection. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Crítica (9.8) | 0.64% | — | Fabian Client Details System | 28/12/2023 | 17/6/2026 | A vulnerability was found in code-projects Client Details System 1.0 and classified as problematic. This issue affects some unknown processing of the file /admin/manage-users.php. The manipulation of the argument id leads to sql injection. The exploit has been disclosed to the public and may be used. The associated… |