Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.64% | — | Fabian Client Details System | 28/12/2023 | 17/6/2026 | A vulnerability has been found in code-projects Client Details System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/regester.php of the component HTTP POST Request Handler. The manipulation of the argument fname/lname/email/contact leads to sql injection. The exploit has… | |
| Modificada | Alta (8.8) | 0.70% | — | Fabian Client Details System | 28/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in code-projects Client Details System 1.0. This affects an unknown part of the file /admin of the component HTTP POST Request Handler. The manipulation of the argument username leads to sql injection. The exploit has been disclosed to the public and may be… | |
| Modificada | Alta (8.8) | 17% | — | Fabian Client Details System | 28/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the component HTTP POST Request Handler. The manipulation of the argument uemail leads to sql injection. The exploit has been disclosed to the public and… | |
| Modificada | Alta (8.8) | 0.77% | — | Ncp-e Secure Enterprise Client | 25/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location. | |
| Modificada | Alta (8.8) | 0.49% | — | Yiiframework Yii2-authclient | 22/12/2023 | 17/6/2026 | yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways. First, the `authCodeVerifier` should be removed after usage (similar to `authState`). Second, there… | |
| Modificada | Crítica (9.8) | 0.72% | — | Yiiframework Yii2-authclient | 22/12/2023 | 17/6/2026 | yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 `state` and OpenID Connect `nonce` is vulnerable for a `timing attack` since it is compared via regular string comparison (instead of… | |
| Modificada | Crítica (9.8) | 0.73% | — | NOS Client | 21/12/2023 | 17/6/2026 | An issue was discovered in nos client version 0.6.6, allows remote attackers to escalate privileges via getRPCEndpoint.js. | |
| Modificada | Media (4.8) | 0.31% | — | Hcltech Bigfix Modern Client Management | 21/12/2023 | 17/6/2026 | Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the… | |
| Analizada | Crítica (9.8) | 0.75% | — | Thegreenbow VPN Client | 19/12/2023 | 17/6/2026 | An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file. | |
| Modificada | Media (5.9) | 94% | 💥 Exploit | Openbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+64 | 18/12/2023 | 17/6/2026 | The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some… | |
| Modificada | Media (5.9) | 0.56% | — | Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+10 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks. | |
| Modificada | Media (5.4) | 0.41% | — | Realbigplugins Client Dash | 15/12/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins Client Dash allows Stored XSS.This issue affects Client Dash: from n/a through 2.2.1. | |
| Modificada | Alta (8.8) | 0.99% | 💥 PoC | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273. | |
| Modificada | Media (6.5) | 0.63% | 💥 PoC | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265. | |
| Modificada | Alta (7.5) | 1.6% | 💥 PoC | IBM I Access Client Solutions | 14/12/2023 | 17/6/2026 | IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270. | |
| Modificada | Crítica (9.8) | 1.1% | — | SAP Cloud-security-client-go | 12/12/2023 | 17/6/2026 | SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application. | |
| Modificada | Media (4.3) | 0.59% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link. | |
| Modificada | Media (6.5) | 0.70% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts. | |
| Modificada | Media (6.5) | 0.77% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link. | |
| Modificada | Alta (8.1) | 0.85% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link. | |
| Modificada | Media (5) | 0.54% | — | Oroinc Client Relationship Management | 28/11/2023 | 17/6/2026 | OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1. | |
| Modificada | Alta (7.5) | 0.70% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 27/11/2023 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure… | |
| Modificada | Media (5.3) | 0.61% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 27/11/2023 | 17/6/2026 | Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the scanner to hang. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure… | |
| Modificada | Media (6.5) | 0.68% | — | Switchwp WP Client Reports | 23/11/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions. | |
| Modificada | Media (5.5) | 0.20% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 22/11/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An… |