Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 38% | 💥 PoC | Ivanti Avalanche | 25/1/2024 | 17/6/2026 | Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component. | |
| Modificada | Alta (7.5) | 4.1% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS). | |
| Modificada | Alta (7.5) | 4.1% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS). | |
| Modificada | Crítica (9.1) | 3.5% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | |
| Modificada | Crítica (9.8) | 4.0% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF). | |
| Modificada | Crítica (9.8) | 90% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution. | |
| Modificada | Crítica (9.8) | 82% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution. | |
| Modificada | Alta (7.5) | 83% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server. | |
| Modificada | Crítica (9.8) | 11% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 9.8% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 11% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 6.8% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 11% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 11% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 6.8% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 6.8% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 6.8% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 6.8% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 11% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 36% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 36% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.8) | 36% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution. | |
| Modificada | Crítica (9.1) | 91% | — | Ivanti Avalanche | 19/12/2023 | 17/6/2026 | An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack. | |
| Modificada | Alta (7.8) | 0.60% | — | Ivanti Avalanche | 3/11/2023 | 17/6/2026 | Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability | |
| Modificada | Alta (7.8) | 0.69% | — | Ivanti Avalanche | 3/11/2023 | 17/6/2026 | Ivanti Avalanche EnterpriseServer Service Unrestricted File Upload Local Privilege Escalation Vulnerability |