Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 3.2% | 💥 Exploit | Proxmox Virtual EnvironmentAIProxmox Libpve-access-controlAI | 1/9/2026 | 8/9/2026 | Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login… | |
| Aplazada | Crítica (9.3) | 0.40% | — | Wpdataaccess WP Data AccessAI | 31/8/2026 | 1/9/2026 | Unauthenticated SQL Injection in WP Data Access <= 5.5.81 versions. | |
| Aplazada | Crítica (9.9) | 0.47% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Aplazada | Media (5.3) | 0.40% | — | Wpdataaccess WP Data AccessAI | 26/8/2026 | 28/8/2026 | The WP Data Access plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.5.68 via the 'check_app_access' function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to access data from protected app… | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi AccessAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device. | |
| Pendiente de análisis | Alta (7.5) | 0.24% | — | Drupal Token Content AccessAI | 25/8/2026 | 28/8/2026 | Observable Timing Discrepancy vulnerability in Drupal Token Content Access allows Brute Force. This issue affects Token Content Access versions: from 0.0.0 to 3.1.2. | |
| Pendiente de análisis | Media (5.3) | 0.14% | — | Okta Privileged AccessAIOpenbsd OpensshAI | 25/8/2026 | 28/8/2026 | The Okta Privileged Access client does not reject a leading hyphen in the username portion of an SSH target. As a result, the value may be interpreted as a command-line option by the underlying SSH process. | |
| Aplazada | Media (5.9) | 0.32% | — | Wpdataaccess WP Data AccessAI | 20/8/2026 | 20/8/2026 | Unauthenticated Broken Access Control in WP Data Access <= 5.5.80 versions. | |
| Analizada | Media (4.3) | 0.33% | — | Oracle Access Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authorization Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via TCP to compromise Oracle Access Manager.… | |
| Modificada | Crítica (9.8) | 0.51% | — | Oracle Access Manager | 18/8/2026 | 22/8/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Agent infrastructure). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via SAML to compromise Oracle Access Manager.… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Access Manager | 18/8/2026 | 20/8/2026 | Vulnerability in the Oracle Access Manager product of Oracle Fusion Middleware (component: Authentication Engine). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Access Manager.… | |
| Aplazada | Alta (8.6) | 0.68% | — | Google ChromeAIGoogle Verified Access APIAIGoauthentik AuthentikAI | 18/8/2026 | 8/9/2026 | authentik is an open-source identity provider. Prior to 2026.2.6 and 2026.5.5, the enterprise Google Chrome device-trust stages advance the flow without confirming that the out-of-band device attestation actually ran. Affected enterprise deployments place either a Google Chrome Endpoint stage with mode set to REQUIRED… | |
| Analizada | Alta (7.8) | 0.17% | — | IBM I Access Client Solutions | 13/8/2026 | 17/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable directory. | |
| Analizada | Alta (8.7) | 0.40% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55402 is an out of bounds read vulnerability in Secure Access servers prior to version 14.57. Attackers with an ‘in the middle’ position can send specially crafted data to a server causing a persistent denial of service. | |
| Analizada | Media (6.9) | 0.40% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55401 is a null dereference vulnerability on the load-balancing sub-system of Secure Access servers prior to 14.57. Attackers can send an unauthenticated packet to a Secure Access server with load balancing enabled, which results in the internal load balancer crashing. After a successful attack, the Secure… | |
| Analizada | Media (6) | 0.37% | — | Absolute Secure Access | 13/8/2026 | 4/9/2026 | CVE-2026-55400 is an integer underflow in Secure Access servers prior to version 14.57. Attackers with an authenticated session can send specially crafted traffic to a server in a non-default configuration and cause a persistent denial of service. | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Lenovo Accessories AND Display Manager FOR EnterpriseAI | 13/8/2026 | 24/8/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Accessories and Display Manager for Enterprise for Windows that could allow a local authenticated user to execute arbitrary code with elevated privileges. | |
| Aplazada | Media (5.9) | 0.24% | — | Wpdataaccess WP Data AccessAI | 13/8/2026 | 14/8/2026 | Author Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | |
| Aplazada | Media (5.3) | 0.47% | — | Prevent Direct Access Protect Wordpress FilesAI | 13/8/2026 | 14/8/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without… | |
| Analizada | Baja (1.7) | 0.32% | — | Paloaltonetworks Cloud NgfwPaloaltonetworks Prisma AccessPaloaltonetworks Pan-os | 13/8/2026 | 28/8/2026 | An information disclosure vulnerability in the URL Filtering feature of Palo Alto Networks PAN-OS® software enables an unauthenticated user with network access to obtain sensitive information. Panorama is not impacted by this vulnerability. | |
| Analizada | Media (6) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | A privilege escalation (PE) vulnerability in the Palo Alto Networks Prisma® Access Agent app on Windows and macOS devices enables a local user to execute code with elevated privileges. The Prisma Access Agent on Linux, iOS, Android, and ChromeOS is not affected. | |
| Analizada | Media (5.6) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | A vulnerability in Palo Alto Networks Prisma® Access Agent on Windows enables a local attacker with administrator privileges to bypass the anti-tamper protection, enabling unauthorized access to protected processes and files. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome OS is not affected. | |
| Analizada | Baja (2.1) | 0.13% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | An authentication bypass vulnerability in the network driver of Palo Alto Networks Prisma® Access Agent on Windows enables a local administrator to bypass security inspection, subsequently allowing them to inject and intercept arbitrary network traffic. The Prisma Access Agent on Linux, macOS, iOS, Android, and Chrome… |