Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.20% | — | Cisco Anyconnect Secure Mobility ClientCisco Secure Client | 22/11/2023 | 17/6/2026 | Multiple vulnerabilities in Cisco Secure Client Software, formerly AnyConnect Secure Mobility Client, could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected system. These vulnerabilities are due to an out-of-bounds memory read from Cisco Secure Client Software. An… | |
| Modificada | Media (5.4) | 0.23% | — | Zscaler Client Connector | 21/11/2023 | 17/6/2026 | An Improper Validation of Integrity Check Value in Zscaler Client Connector on Windows allows an authenticated user to disable ZIA/ZPA by interrupting the service restart from Zscaler Diagnostics. This issue affects Client Connector: before 4.2.0.149. | |
| Modificada | Alta (7.8) | 0.22% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security | 20/11/2023 | 17/6/2026 | Certain WithSecure products allow Local Privilege Escalation. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, and WithSecure Elements Endpoint Protection 17 and later. | |
| Modificada | Alta (7.5) | 0.70% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 16/11/2023 | 17/6/2026 | Certain WithSecure products have a buffer over-read whereby processing certain fuzz file types may cause a denial of service (DoS). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client… | |
| Modificada | Alta (7.5) | 0.70% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 16/11/2023 | 17/6/2026 | Certain WithSecure products allow a Denial of Service (DoS) in the antivirus engine when scanning a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for… | |
| Modificada | Alta (7.8) | 0.45% | — | Ivanti Secure Access Client | 15/11/2023 | 17/6/2026 | When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file. | |
| Modificada | Media (5.5) | 0.37% | — | Ivanti Secure Access Client | 15/11/2023 | 17/6/2026 | A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system. | |
| Modificada | Alta (7.8) | 0.37% | — | Ivanti Secure Access Client | 15/11/2023 | 17/6/2026 | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine. | |
| Modificada | Alta (7.8) | 0.37% | — | Ivanti Secure Access Client | 15/11/2023 | 17/6/2026 | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the… | |
| Modificada | Alta (7.8) | 0.71% | 💥 PoC | Ivanti Secure Access Client | 15/11/2023 | 17/6/2026 | A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure. | |
| Modificada | Alta (7.1) | 0.21% | — | Fortinet Forticlient | 14/11/2023 | 17/6/2026 | A incorrect authorization in Fortinet FortiClient (Windows) 7.0.0 - 7.0.7, 6.4.0 - 6.4.9, 6.2.0 - 6.2.9 and 6.0.0 - 6.0.10 allows an attacker to cause denial of service via sending a crafted request to a specific named pipe. | |
| Modificada | Alta (7.8) | 0.31% | — | Fortinet Forticlient | 14/11/2023 | 17/6/2026 | A untrusted search path vulnerability in Fortinet FortiClientWindows 7.0.9 allows an attacker to perform a DLL Hijack attack via a malicious OpenSSL engine library in the search path. | |
| Modificada | Media (5.5) | 0.21% | — | Fortinet Forticlient | 14/11/2023 | 17/6/2026 | A use of hard-coded credentials vulnerability in Fortinet FortiClient Windows 7.0.0 - 7.0.9 and 7.2.0 - 7.2.1 allows an attacker to bypass system protections via the use of static credentials. | |
| Modificada | Media (6.7) | 0.18% | — | Appsanywhere Client | 9/11/2023 | 17/6/2026 | The AppsAnywhere macOS client-privileged helper can be tricked into executing arbitrary commands with elevated permissions by a local user process. | |
| Modificada | Crítica (9.8) | 0.34% | — | Appsanywhere Client | 9/11/2023 | 17/6/2026 | Symmetric encryption used to protect messages between the AppsAnywhere server and client can be broken by reverse engineering the client and used to impersonate the AppsAnywhere server. | |
| Modificada | Media (5.5) | 0.19% | — | Synology SSL VPN Client | 7/11/2023 | 17/6/2026 | Buffer copy without checking size of input ('Classic Buffer Overflow') vulnerability in cgi component in Synology SSL VPN Client before 1.4.7-0687 allows local users to conduct denial-of-service attacks via unspecified vectors. | |
| Modificada | Media (6.5) | 0.20% | — | Zscaler Client Connector | 6/11/2023 | 17/6/2026 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Privilege Abuse. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.27% | — | Redhat Insights-clientRedhat Enterprise LinuxRedhat Enterprise Linux AUSRedhat Enterprise Linux Desktop+15 | 1/11/2023 | 17/6/2026 | A vulnerability was found in insights-client. This security issue occurs because of insecure file operations or unsafe handling of temporary files and directories that lead to local privilege escalation. Before the insights-client has been registered on the system by root, an unprivileged local user or attacker could… | |
| Modificada | Alta (7.8) | 0.16% | — | Securepoint Openvpn-client | 30/10/2023 | 17/6/2026 | The installer (aka openvpn-client-installer) in Securepoint SSL VPN Client before 2.0.40 allows local privilege escalation during installation or repair. | |
| Modificada | Alta (7.5) | 1.1% | — | Vmware Rabbitmq Java Client | 25/10/2023 | 17/6/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. `maxBodyLebgth` was not used when receiving Message objects. Attackers could send a very large Message causing a memory overflow and triggering an OOM Error. Users of RabbitMQ may suffer from DoS… | |
| Modificada | Alta (7) | 0.67% | 💥 PoC | Ivanti Secure Access Client | 25/10/2023 | 17/6/2026 | A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. | |
| Modificada | Crítica (9.8) | 0.35% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An Improper Input Validation vulnerability in Zscaler Client Connector on Linux allows Privilege Escalation. This issue affects Client Connector: before 1.4.0.105 | |
| Modificada | Media (5.3) | 0.24% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows replacing binaries.This issue affects Linux Client Connector: before 1.4.0.105 | |
| Modificada | Media (6.5) | 0.26% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | An authentication bypass by spoofing of a device with a synthetic IP address is possible in Zscaler Client Connector on Windows, allowing a functionality bypass. This issue affects Client Connector: before 3.9. | |
| Modificada | Alta (7.3) | 0.22% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector for Windows before 4.1 writes/deletes a configuration file inside specific folders on the disk. A malicious user can replace the folder and execute code as a privileged user. |