Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1894 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.18% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.15% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.30% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6. | |
| Modificada | Alta (7.8) | 0.23% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges. | |
| Modificada | Media (4.7) | 0.11% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition. | |
| Modificada | Alta (7.8) | 0.22% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges. | |
| Modificada | Alta (7.8) | 0.13% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges. | |
| Modificada | Media (5.5) | 0.14% | — | Zscaler Client Connector | 23/10/2023 | 17/6/2026 | Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context. | |
| Modificada | Alta (7.8) | 0.18% | — | HP Desktop PRO A 300 G3 FirmwareHP Desktop PRO A G3 FirmwareHP Desktop PRO A G3 Microtower FirmwareHP Zhan 66 PRO A G1 R Microtower Firmware+85 | 18/10/2023 | 17/6/2026 | A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability. | |
| Modificada | Media (6.8) | 0.29% | — | HP T430 Thin Client FirmwareHP T638 Thin Client Firmware | 13/10/2023 | 17/6/2026 | HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to… | |
| Modificada | Baja (3.3) | 0.24% | — | Fortinet Forticlient | 10/10/2023 | 17/6/2026 | An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all… | |
| Modificada | Alta (7.8) | 0.24% | — | IBM Storage ProtectIBM Storage Protect Client | 6/10/2023 | 17/6/2026 | IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246. | |
| Modificada | Alta (8.8) | 0.88% | — | 1E Client | 5/10/2023 | 17/6/2026 | In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. The 1E Client's temporary directory is now locked down in the released… | |
| Modificada | Alta (8.4) | 0.23% | — | 1E Client | 5/10/2023 | 17/6/2026 | 1E Client installer can perform arbitrary file deletion on protected files. A non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup. A hotfix is available from the 1E support portal that forces the… | |
| Modificada | Alta (8.1) | 0.63% | — | Catonetworks Cato Client | 3/10/2023 | 17/6/2026 | An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component. | |
| Modificada | Alta (8.2) | 0.28% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client | 27/9/2023 | 17/6/2026 | BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Alta (7.1) | 0.17% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client | 27/9/2023 | 17/6/2026 | BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Media (6.1) | 0.50% | — | Icewarp Webclient | 25/9/2023 | 17/6/2026 | Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter. | |
| Modificada | Alta (7.5) | 0.64% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 22/9/2023 | 17/6/2026 | Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements… | |
| Modificada | Alta (7.8) | 0.16% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 22/9/2023 | 17/6/2026 | Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure… | |
| Modificada | Alta (7.5) | 0.64% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 22/9/2023 | 17/6/2026 | Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint… | |
| Modificada | Alta (7.5) | 0.64% | — | F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+3 | 22/9/2023 | 17/6/2026 | Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection… | |
| Modificada | Alta (7.5) | 0.64% | — | F-secure Client SecurityF-secure Elements Endpoint ProtectionF-secure Email AND Server SecurityF-secure Server Security+3 | 22/9/2023 | 17/6/2026 | Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint… | |
| Modificada | Alta (7.4) | 0.24% | — | Mimsoftware AssistantMimsoftware Client | 19/9/2023 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML document, embed this document into specific 3rd… | |
| Modificada | Alta (7.5) | 0.62% | — | Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+3 | 18/9/2023 | 17/6/2026 | Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure… |