Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.93% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure… | |
| Analizada | Alta (8.8) | 0.93% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure… | |
| Analizada | Media (6.8) | 0.91% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 9/9/2025 | 17/6/2026 | SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to enumerate internal services. | |
| Analizada | Media (5.5) | 0.36% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files… | |
| Analizada | Media (4.9) | 0.68% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial of service | |
| Analizada | Alta (7.5) | 1.1% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service. | |
| Analizada | Alta (7.5) | 1.1% | — | Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access | 12/8/2025 | 17/6/2026 | A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.… | |
| Analizada | Media (5.1) | 0.20% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-54085 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read or change other settings. The attack complexity is… | |
| Analizada | Media (5.3) | 0.31% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-49084 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access can overwrite policy rules without the requisite permissions. The attack complexity is low, attack requirements are present, privileges required are high and no user… | |
| Analizada | Alta (7) | 0.37% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-49083 is a vulnerability in the management console of Absolute Secure Access after version 12.00 and prior to version 13.56. Attackers with administrative access to the console can cause unsafe content to be deserialized and executed in the security context of the console. The attack complexity is low and… | |
| Analizada | Media (5.1) | 0.22% | — | Absolute Secure Access | 31/7/2025 | 17/6/2026 | CVE-2025-49082 is a vulnerability in the management console of Absolute Secure Access prior to version 13.56. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly read other settings. The attack complexity is low, there… | |
| Analizada | Alta (8.6) | 0.15% | — | Citrix Secure Access Client | 17/6/2025 | 17/6/2026 | Local Privilege escalation allows a low-privileged user to gain SYSTEM privileges in Citrix Secure Access Client for Windows | |
| Analizada | Media (6.9) | 0.48% | — | Absolute Secure Access | 12/6/2025 | 17/6/2026 | There is an insufficient input validation vulnerability in the warehouse component of Absolute Secure Access prior to server version 13.55. Attackers with system administrator permissions can impair the availability of the Secure Access administrative UI by writing invalid data to the warehouse over the network. The… | |
| Analizada | Alta (8.7) | 0.37% | — | Absolute Secure Access | 12/6/2025 | 17/6/2026 | There is a memory management vulnerability in Absolute Secure Access server versions 9.0 to 13.54. Attackers with network access to the server can cause a Denial of Service by sending a specially crafted sequence of packets to the server. The attack complexity is low, there are no attack requirements, privileges, or… | |
| Analizada | Media (4.6) | 0.24% | — | Absolute Secure Access | 28/5/2025 | 17/6/2026 | CVE-2025-27706 is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second administrator visits the page. Attack… | |
| Analizada | Alta (7) | 0.30% | — | Absolute Secure Access | 28/5/2025 | 17/6/2026 | CVE-2025-27703 is a privilege escalation vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to a specific subset of privileged features in the console can elevate their permissions to access additional features in the console. The attack… | |
| Analizada | Media (6.9) | 0.31% | — | Absolute Secure Access | 28/5/2025 | 17/6/2026 | CVE-2025-27702 is a vulnerability in the management console of Absolute Secure Access prior to version 13.54. Attackers with administrative access to the console and who have been assigned a certain set of permissions can bypass those permissions to improperly modify settings. The attack complexity is low, there are… | |
| Aplazada | Media (5.5) | 0.31% | — | Absolute Secure AccessAI | 19/3/2025 | 17/6/2026 | There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.53. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second administrator logs in. Attack… | |
| Aplazada | Media (5.5) | 0.31% | — | Absolute Secure AccessAI | 19/3/2025 | 17/6/2026 | There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.53. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second administrator logs in. Attack… | |
| Analizada | Alta (7.8) | 0.30% | — | Ivanti Secure Access Client | 11/3/2025 | 17/6/2026 | Insufficiently restrictive permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Media (5.9) | 0.16% | — | Citrix Secure Access Client | 20/2/2025 | 17/6/2026 | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac | |
| Analizada | Media (5.9) | 0.16% | — | Citrix Secure Access Client | 20/2/2025 | 17/6/2026 | An attacker can gain application privileges in order to perform limited modification and/or read arbitrary data in Citrix Secure Access Client for Mac | |
| Analizada | Alta (7.1) | 0.21% | — | Ivanti Secure Access Client | 11/2/2025 | 17/6/2026 | Insufficient permissions in Ivanti Secure Access Client before version 22.8R1 allows a local authenticated attacker to delete arbitrary files. | |
| Aplazada | Media (5.9) | 0.32% | — | Absolute Secure AccessAI | 20/12/2024 | 17/6/2026 | There is a cross-site scripting vulnerability in the management console of Absolute Secure Access prior to version 13.52. Attackers with system administrator permissions can interfere with another system administrator’s use of the management console when the second administrator logs in. Attack complexity is high,… | |
| Analizada | Media (4.4) | 0.28% | — | Ivanti Secure Access Client | 13/11/2024 | 17/6/2026 | Improper bounds checking in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker with admin privileges to cause a denial of service. |