Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)3.6%—Ivanti Avalanche19/4/202417/6/2026
A Heap Overflow vulnerability in WLInfoRailService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands
ModificadaMedia (6.5)38%💥 PoCIvanti Avalanche25/1/202417/6/2026
Directory Traversal vulnerability in Ivanti Avalanche 6.3.4.153 allows a remote authenticated attacker to obtain sensitive information via the javax.faces.resource component.
ModificadaAlta (7.5)4.1%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
ModificadaAlta (7.5)4.1%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS).
ModificadaCrítica (9.1)3.5%—Ivanti Avalanche19/12/202317/6/2026
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
ModificadaCrítica (9.8)4.0%—Ivanti Avalanche19/12/202317/6/2026
An unauthenticated could abuse a XXE vulnerability in the Smart Device Server to leak data or perform a Server-Side Request Forgery (SSRF).
ModificadaCrítica (9.8)90%—Ivanti Avalanche19/12/202317/6/2026
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remove code execution.
ModificadaCrítica (9.8)82%—Ivanti Avalanche19/12/202317/6/2026
An unrestricted upload of file with dangerous type vulnerability exists in Avalanche versions 6.4.1 and below that could allow an attacker to achieve a remote code execution.
ModificadaAlta (7.5)83%—Ivanti Avalanche19/12/202317/6/2026
An unauthenticated attacked could send a specifically crafted web request causing a Server-Side Request Forgery (SSRF) in Ivanti Avalanche Remote Control server.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)9.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)6.8%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)11%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)36%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)36%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.8)36%—Ivanti Avalanche19/12/202317/6/2026
An attacker sending specially crafted data packets to the Mobile Device Server can cause memory corruption which could result to a Denial of Service (DoS) or code execution.
ModificadaCrítica (9.1)91%—Ivanti Avalanche19/12/202317/6/2026
An attacker can send a specially crafted request which could lead to leakage of sensitive data or potentially a resource-based DoS attack.
ModificadaAlta (7.8)0.60%—Ivanti Avalanche3/11/202317/6/2026
Ivanti Avalanche Incorrect Default Permissions allows Local Privilege Escalation Vulnerability