Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 2.0% | — | Teamviewer Full ClientAITeamviewer HostAI | 26/8/2026 | 1/9/2026 | A command injection vulnerability in TeamViewer Full Client and Host for Linux prior to version 15.81.5 allows a remote attacker to execute arbitrary commands in the context of the current user via a specially crafted URL sent through the out-of-session chat feature. Exploitation requires user interaction by clicking… | |
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Aplazada | Media (5.8) | 0.61% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… | |
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Pendiente de análisis | Media (6.6) | 0.14% | — | Dell Client BiosAI | 24/8/2026 | 28/8/2026 | Dell Client BIOS contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Arbitrary Write | |
| Aplazada | Crítica (10) | 0.41% | — | Miniorange Oauth ClientAIMiniorange Oauth Single Sign ON Oidc SSOAIMiniorange Login With Keycloak Oauth Single Sign ON SSOAIMiniorange Single Sign ON FOR Educational InstitutesAI | 24/8/2026 | 8/9/2026 | Joomla Extension - miniorange.com - Arbitrary account takeover in miniOrange OAuth Client < 3.2.0, OAuth Single Sign-On – OIDC SSO < 1.2.2, Login with Keycloak OAuth Single Sign-On (SSO) < 1.2.2, Single Sign-On for Educational Institutes < 1.2.2 - The manipulation of a cookie value allows actors to login as arbitrary… | |
| Pendiente de análisis | Crítica (9.1) | 0.66% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow remote code execution, giving an unauthenticated, unprivileged user the ability to execute arbitrary code in the ZCC context. | |
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | Multiple vulnerabilities on affected versions of Zscaler Client Connector allow local privilege escalation, giving an unprivileged user the ability to execute arbitrary code in a privileged context. | |
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | A locally exploitable buffer overflow bug can cause a local denial-of-service attack on affected versions of Zscaler Client Connector on Android and ChromeOS. | |
| Pendiente de análisis | Alta (8.8) | 0.48% | — | Zscaler Client ConnectorAI | 24/8/2026 | 28/8/2026 | A remotely exploitable buffer overflow bug can cause a local and kernel denial-of-service attack on affected versions of Zscaler Client Connector on Windows. | |
| Pendiente de análisis | Crítica (9.1) | 0.53% | — | Zscaler Client ConnectorAIZscaler Client Connector PortalAI | 24/8/2026 | 28/8/2026 | An authentication bypass issue exists in communications between affected versions of the Zscaler Client Connector and the Zscaler Client Connector Portal. | |
| Aplazada | Alta (8.8) | 0.40% | — | LibvncclientAI | 21/8/2026 | 30/9/2026 | LibVNCClient is a library for easy implementation of a VNC client. In versions 0.9.12 through 0.9.15, a malicious (or man-in-the-middle) VNC server can force a connecting `libvncclient` to write attacker-controlled data past the end of its framebuffer. This is an out-of-bounds heap write with attacker-controlled… | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Aplazada | Alta (7.8) | 0.17% | — | Parallels RAS ClientAI | 20/8/2026 | 1/9/2026 | Parallels RAS Client RDP Backend Service Exposed Dangerous Function Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Parallels RAS Client. An attacker must first obtain the ability to execute low-privileged code on the target system… | |
| Aplazada | Baja (3.7) | 0.31% | — | Freedom OF THE Press Foundation Securedrop ClientAIFreedom OF THE Press Foundation Securedrop ServerAIFreedom OF THE Press Foundation Securedrop-proxyAI | 20/8/2026 | 18/9/2026 | SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. Prior to version 1.3.1, a malicious SecureDrop Server could bypass securedrop-proxy's origin limitation by responding with cross-origin redirects. SecureDrop Server itself has… | |
| Aplazada | Alta (7.6) | 0.38% | — | Revmakx Infinitewp ClientAI | 20/8/2026 | 24/8/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in revmakx InfiniteWP Client allows Blind SQL Injection. This issue affects InfiniteWP Client: from n/a through 1.13.9. | |
| Aplazada | Alta (7.1) | 0.25% | — | Prosolution WP ClientAI | 19/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape a parameter before reflecting it into an HTML attribute on one of its administrative pages, leading to reflected Cross-Site Scripting that runs in the session of an administrator induced to submit a crafted request. | |
| Aplazada | Alta (7.1) | 0.25% | — | Prosolution WP ClientAI | 19/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.11 does not sanitise and escape several parameters before reflecting them into HTML attributes on its public pages, leading to reflected Cross-Site Scripting that can be triggered against any visitor, including a logged-in administrator. | |
| Pendiente de análisis | Alta (8.7) | 0.73% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.1, src/main/java/com/rabbitmq/client/impl/ValueReader.java permits ValueReader.readTable and ValueReader.readArray to call ValueReader.readFieldValue recursively for AMQP table type F… | |
| Pendiente de análisis | Media (5.1) | 0.31% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, com.rabbitmq.client.ConnectionFactory.useSslProtocol() and ConnectionFactory.useSslProtocol(String) configure com.rabbitmq.client.TrustEverythingTrustManager and leave hostname… | |
| Pendiente de análisis | Media (6.3) | 0.52% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.31.0, inbound AMQP command assembly in src/main/java/com/rabbitmq/client/impl/CommandAssembler.java processes a content-bearing method and header whose remainingBodyBytes value is smaller… | |
| Pendiente de análisis | Ninguna (0) | 0.49% | — | Rabbitmq Java Client LibraryAI | 18/8/2026 | 10/9/2026 | The RabbitMQ Java client library allows Java and JVM-based applications to connect to and interact with RabbitMQ nodes. Prior to 5.33.0, the AMQP connection tuning path records the negotiated AMQP frame_max value, but src/main/java/com/rabbitmq/client/impl/SocketFrameHandler.java and NettyFrameHandlerFactory continue… |