Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

2624 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)3.2%💥 ExploitProxmox Virtual EnvironmentAIProxmox Libpve-access-controlAI1/9/20268/9/2026
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login…
AplazadaCrítica (9.3)0.40%—Wpdataaccess WP Data AccessAI31/8/20261/9/2026
Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions.
AplazadaCrítica (9.9)0.47%—UI Unifi AccessAI26/8/202628/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
AplazadaCrítica (9.9)1.4%—UI Unifi AccessAI26/8/202628/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
AplazadaCrítica (9.9)1.4%—UI Unifi AccessAI26/8/202628/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
AplazadaMedia (5.3)0.40%—Wpdataaccess WP Data AccessAI26/8/202628/8/2026
The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app…
AplazadaCrítica (9.9)1.4%—UI Unifi AccessAI26/8/202628/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
Pendiente de análisisAlta (7.5)0.24%—Drupal Token Content AccessAI25/8/202628/8/2026
Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2.
Pendiente de análisisMedia (5.3)0.14%—Okta Privileged AccessAIOpenbsd OpensshAI25/8/202628/8/2026
The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process.
AplazadaMedia (5.9)0.32%—Wpdataaccess WP Data AccessAI20/8/202620/8/2026
Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions.
AnalizadaMedia (4.3)0.33%—Oracle Access Manager18/8/202620/8/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Access Manager.…
ModificadaCrítica (9.8)0.51%—Oracle Access Manager18/8/202622/8/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SAML to compromise Oracle Access Manager.…
AnalizadaAlta (8.8)0.43%—Oracle Access Manager18/8/202620/8/2026
Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.…
AplazadaAlta (8.6)0.68%—Google ChromeAIGoogle Verified Access APIAIGoauthentik AuthentikAI18/8/20268/9/2026
authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED…
AnalizadaAlta (7.8)0.17%—IBM I Access Client Solutions13/8/202617/8/2026
IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory.
AnalizadaAlta (8.7)0.40%—Absolute Secure Access13/8/20264/9/2026
CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service.
AnalizadaMedia (6.9)0.40%—Absolute Secure Access13/8/20264/9/2026
CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure…
AnalizadaMedia (6)0.37%—Absolute Secure Access13/8/20264/9/2026
CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service.
Pendiente de análisisAlta (8.5)0.15%—Lenovo Accessories AND Display Manager FOR EnterpriseAI13/8/202624/8/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges.
AplazadaMedia (5.9)0.24%—Wpdataaccess WP Data AccessAI13/8/202614/8/2026
Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions.
AplazadaMedia (5.3)0.47%—Prevent Direct Access Protect Wordpress FilesAI13/8/202614/8/2026
The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without…
AnalizadaBaja (1.7)0.32%—Paloaltonetworks Cloud NgfwPaloaltonetworks Prisma AccessPaloaltonetworks Pan-os13/8/202628/8/2026
An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability.
AnalizadaMedia (6)0.11%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected.
AnalizadaMedia (5.6)0.11%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected.
AnalizadaBaja (2.1)0.13%—Paloaltonetworks Prisma Access Agent13/8/20269/9/2026
An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome…
Orbitaley — Vulnerabilidades