Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

1894 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.18%—Zscaler Client Connector23/10/202317/6/2026
Improper Verification of Cryptographic Signature vulnerability in Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
ModificadaAlta (7.8)0.15%—Zscaler Client Connector23/10/202317/6/2026
Origin Validation Error vulnerability in Zscaler Client Connector on Linux allows Inclusion of Code in Existing Process. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
ModificadaAlta (7.8)0.30%—Zscaler Client Connector23/10/202317/6/2026
Buffer overflow vulnerability in the signelf library used by Zscaler Client Connector on Linux allows Code Injection. This issue affects Zscaler Client Connector for Linux: before 1.3.1.6.
ModificadaAlta (7.8)0.23%—Zscaler Client Connector23/10/202317/6/2026
Zscaler Client Connector for macOS prior to 3.7 had an unquoted search path vulnerability via the PATH variable. A local adversary may be able to execute code with root privileges.
ModificadaMedia (4.7)0.11%—Zscaler Client Connector23/10/202317/6/2026
The Zscaler Client Connector for macOS prior to 3.6 did not sufficiently validate RPC clients. A local adversary without sufficient privileges may be able to shutdown the Zscaler tunnel by exploiting a race condition.
ModificadaAlta (7.8)0.22%—Zscaler Client Connector23/10/202317/6/2026
Multiple vulnerabilities in the Zscaler Client Connector Installer and Uninstaller for Windows prior to 3.6 allowed execution of binaries from a low privileged path. A local adversary may be able to execute code with SYSTEM privileges.
ModificadaAlta (7.8)0.13%—Zscaler Client Connector23/10/202317/6/2026
The Zscaler Client Connector Installer and Unsintallers for Windows prior to 3.6 had an unquoted search path vulnerability. A local adversary may be able to execute code with SYSTEM privileges.
ModificadaMedia (5.5)0.14%—Zscaler Client Connector23/10/202317/6/2026
Zscaler Client Connector Installer on Windows before version 3.4.0.124 improperly handled directory junctions during uninstallation. A local adversary may be able to delete folders in an elevated context.
ModificadaAlta (7.8)0.18%—HP Desktop PRO A 300 G3 FirmwareHP Desktop PRO A G3 FirmwareHP Desktop PRO A G3 Microtower FirmwareHP Zhan 66 PRO A G1 R Microtower Firmware+8518/10/202317/6/2026
A potential security vulnerability has been identified in the system BIOS for certain HP PC products which might allow escalation of privilege. HP is releasing firmware updates to mitigate the potential vulnerability.
ModificadaMedia (6.8)0.29%—HP T430 Thin Client FirmwareHP T638 Thin Client Firmware13/10/202317/6/2026
HP is aware of a potential security vulnerability in HP t430 and t638 Thin Client PCs. These models may be susceptible to a physical attack, allowing an untrusted source to tamper with the system firmware using a publicly disclosed private key. HP is providing recommended guidance for customers to reduce exposure to…
ModificadaBaja (3.3)0.24%—Fortinet Forticlient10/10/202317/6/2026
An exposure of sensitive information to an unauthorized actor vulnerability [CWE-200] in FortiClient for Windows 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions, Linux 7.2.0, 7.0 all versions, 6.4 all versions, 6.2 all versions and Mac 7.2.0 through 7.2.1, 7.0 all versions, 6.4 all versions, 6.2 all…
ModificadaAlta (7.8)0.24%—IBM Storage ProtectIBM Storage Protect Client6/10/202317/6/2026
IBM Spectrum Protect Client and IBM Storage Protect for Virtual Environments 8.1.0.0 through 8.1.19.0 could allow a local user to execute arbitrary code on the system using a specially crafted file, caused by a DLL hijacking flaw. IBM X-Force ID: 259246.
ModificadaAlta (8.8)0.88%—1E Client5/10/202317/6/2026
In the affected version of the 1E Client, an ordinary user could subvert downloaded instruction resource files, e.g., to substitute a harmful script. by replacing a resource script file created by an instruction at run time with a malicious script. The 1E Client's temporary directory is now locked down in the released…
ModificadaAlta (8.4)0.23%—1E Client5/10/202317/6/2026
1E Client installer can perform arbitrary file deletion on protected files. A non-privileged user could provide a symbolic link or Windows junction to point to a protected directory in the installer that the 1E Client would then clear on service startup. A hotfix is available from the 1E support portal that forces the…
ModificadaAlta (8.1)0.63%—Catonetworks Cato Client3/10/202317/6/2026
An issue in CatoNetworks CatoClient before v.5.4.0 allows attackers to escalate privileges and winning the race condition (TOCTOU) via the PrivilegedHelperTool component.
ModificadaAlta (8.2)0.28%—F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client27/9/202317/6/2026
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
ModificadaAlta (7.1)0.17%—F5 Big-ip Access Policy ManagerF5 Big-ip Access Policy Manager Client27/9/202317/6/2026
BIG-IP APM clients may send IP traffic outside of the VPN tunnel. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
ModificadaMedia (6.1)0.50%—Icewarp Webclient25/9/202317/6/2026
Cross Site Scripting (XSS) vulnerability in the Sign-In page of IceWarp WebClient 10.3.5 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the username parameter.
ModificadaAlta (7.5)0.64%—F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+322/9/202317/6/2026
Certain WithSecure products allow Denial of Service via the aepack archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements…
ModificadaAlta (7.8)0.16%—F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+322/9/202317/6/2026
Certain WithSecure products allow Local privilege escalation via the lhz archive unpack handler. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure…
ModificadaAlta (7.5)0.64%—F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+322/9/202317/6/2026
Certain WithSecure products allow Denial of Service in the aeelf component. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint…
ModificadaAlta (7.5)0.64%—F-secure Linux ProtectionF-secure Linux Security 64F-secure AtlantF-secure Client Security+322/9/202317/6/2026
Certain WithSecure products allow Denial of Service (infinite loop). This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint Protection…
ModificadaAlta (7.5)0.64%—F-secure Client SecurityF-secure Elements Endpoint ProtectionF-secure Email AND Server SecurityF-secure Server Security+322/9/202317/6/2026
Certain WithSecure products allow Denial of Service via a fuzzed PE32 file. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure Elements Endpoint…
ModificadaAlta (7.4)0.24%—Mimsoftware AssistantMimsoftware Client19/9/202317/6/2026
Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML document, embed this document into specific 3rd…
ModificadaAlta (7.5)0.62%—Withsecure Client SecurityWithsecure Elements Endpoint ProtectionWithsecure Email AND Server SecurityWithsecure Server Security+318/9/202317/6/2026
Certain WithSecure products allow an infinite loop in a scanning engine via unspecified file types. This affects WithSecure Client Security 15, WithSecure Server Security 15, WithSecure Email and Server Security 15, WithSecure Elements Endpoint Protection 17 and later, WithSecure Client Security for Mac 15, WithSecure…