Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)38%💥 PoCIvanti Avalanche25/1/202417/6/2026
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
ModificadaAlta (7.5)4.1%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
ModificadaAlta (7.5)4.1%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
ModificadaCrítica (9.1)3.5%—Ivanti Avalanche19/12/202317/6/2026
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
ModificadaCrítica (9.8)4.0%—Ivanti Avalanche19/12/202317/6/2026
An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).
ModificadaCrítica (9.8)90%—Ivanti Avalanche19/12/202317/6/2026
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
ModificadaCrítica (9.8)82%—Ivanti Avalanche19/12/202317/6/2026
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
ModificadaAlta (7.5)83%—Ivanti Avalanche19/12/202317/6/2026
An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)9.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)36%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)36%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)36%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.1)91%—Ivanti Avalanche19/12/202317/6/2026
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
ModificadaAlta (7.8)0.60%—Ivanti Avalanche3/11/202317/6/2026
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability
ModificadaAlta (7.8)0.69%—Ivanti Avalanche3/11/202317/6/2026
Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability
Orbitaley — Vulnerabilidades