Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

1894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.64%—Fabian Client Details System28/12/202317/6/2026
A vulnerability has been found in code-projects Client Details System 1.0 and classified as problematic. This vulnerability affects unknown code of the file /admin/regester.php of the component HTTP POST Request Handler. The manipulation of the argument fname/lname/email/contact leads to sql injection. The exploit has…
ModificadaAlta (8.8)0.70%—Fabian Client Details System28/12/202317/6/2026
A vulnerability, which was classified as critical, was found in code-projects Client Details System 1.0. This affects an unknown part of the file /admin of the component HTTP POST Request Handler. The manipulation of the argument username leads to sql injection. The exploit has been disclosed to the public and may be…
ModificadaAlta (8.8)17%—Fabian Client Details System28/12/202317/6/2026
A vulnerability, which was classified as critical, has been found in code-projects Client Details System 1.0. Affected by this issue is some unknown functionality of the component HTTP POST Request Handler. The manipulation of the argument uemail leads to sql injection. The exploit has been disclosed to the public and…
ModificadaAlta (8.8)0.77%—Ncp-e Secure Enterprise Client25/12/202317/6/2026
Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location.
ModificadaAlta (8.8)0.49%—Yiiframework Yii2-authclient22/12/202317/6/2026
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth2 PKCE implementation is vulnerable in 2 ways. First, the `authCodeVerifier` should be removed after usage (similar to `authState`). Second, there…
ModificadaCrítica (9.8)0.72%—Yiiframework Yii2-authclient22/12/202317/6/2026
yii2-authclient is an extension that adds OpenID, OAuth, OAuth2 and OpenId Connect consumers for the Yii framework 2.0. In yii2-authclient prior to version 2.2.15, the Oauth1/2 `state` and OpenID Connect `nonce` is vulnerable for a `timing attack` since it is compared via regular string comparison (instead of…
ModificadaCrítica (9.8)0.73%—NOS Client21/12/202317/6/2026
An issue was discovered in nos client version 0.6.6, allows remote attackers to escalate privileges via getRPCEndpoint.js.
ModificadaMedia (4.8)0.31%—Hcltech Bigfix Modern Client Management21/12/202317/6/2026
Due to this vulnerability, the Master operator could potentially incorporate an SVG tag into HTML, leading to an alert pop-up displaying a cookie. To mitigate stored XSS vulnerabilities, a preventive measure involves thoroughly sanitizing and validating all user inputs before they are processed and stored in the…
AnalizadaCrítica (9.8)0.75%—Thegreenbow VPN Client19/12/202317/6/2026
An issue discovered in TheGreenBow Windows Enterprise Certified VPN Client 6.52, Windows Standard VPN Client 6.87, and Windows Enterprise VPN Client 6.87 allows attackers to gain escalated privileges via crafted changes to memory mapped file.
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaMedia (5.9)0.56%—Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+1018/12/202317/6/2026
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
ModificadaMedia (5.4)0.41%—Realbigplugins Client Dash15/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Real Big Plugins Client Dash allows Stored XSS.This issue affects Client Dash: from n/a through 2.2.1.
ModificadaAlta (8.8)0.99%💥 PoCIBM I Access Client Solutions14/12/202317/6/2026
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to execute remote code. Due to improper authority checks the attacker could perform operations on the PC under the user's authority. IBM X-Force ID: 268273.
ModificadaMedia (6.5)0.63%💥 PoCIBM I Access Client Solutions14/12/202317/6/2026
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 is vulnerable to having its key for an encrypted password decoded. By somehow gaining access to the encrypted password, a local attacker could exploit this vulnerability to obtain the password to other systems. IBM X-Force ID: 268265.
ModificadaAlta (7.5)1.6%💥 PoCIBM I Access Client Solutions14/12/202317/6/2026
IBM i Access Client Solutions 1.1.2 through 1.1.4 and 1.1.4.3 through 1.1.9.3 could allow an attacker to obtain a decryption key due to improper authority checks. IBM X-Force ID: 268270.
ModificadaCrítica (9.8)1.1%—SAP Cloud-security-client-go12/12/202317/6/2026
SAP BTP Security Services Integration Library ([Golang] github.com/sap/cloud-security-client-go) - versions < 0.17.0, allow under certain conditions an escalation of privileges. On successful exploitation, an unauthenticated attacker can obtain arbitrary permissions within the application.
ModificadaMedia (4.3)0.59%—Ncp-e Secure Enterprise Client9/12/202317/6/2026
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link.
ModificadaMedia (6.5)0.70%—Ncp-e Secure Enterprise Client9/12/202317/6/2026
Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts.
ModificadaMedia (6.5)0.77%—Ncp-e Secure Enterprise Client9/12/202317/6/2026
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link.
ModificadaAlta (8.1)0.85%—Ncp-e Secure Enterprise Client9/12/202317/6/2026
Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link.
ModificadaMedia (5)0.54%—Oroinc Client Relationship Management28/11/202317/6/2026
OroCalendarBundle enables a Calendar feature and related functionality in Oro applications. Back-office users can access information from any call event, bypassing ACL security restrictions due to insufficient security checks. This issue has been patched in version 5.0.4 and 5.1.1.
ModificadaAlta (7.5)0.70%—F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+327/11/202317/6/2026
Certain WithSecure products allow a Denial of Service because there is an unpack handler crash that can lead to a scanning engine crash. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…
ModificadaMedia (5.3)0.61%—F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+327/11/202317/6/2026
Certain WithSecure products allow a Denial of Service because scanning a crafted file takes a long time, and causes the scanner to hang. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure…
ModificadaMedia (6.5)0.68%—Switchwp WP Client Reports23/11/202317/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in SwitchWP WP Client Reports plugin <= 1.0.16 versions.
ModificadaMedia (5.5)0.20%—Cisco Anyconnect Secure Mobility ClientCisco Secure Client22/11/202317/6/2026
Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An…