Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

194 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.32%—Ivanti Secure Access Client13/11/202417/6/2026
Insufficient validation in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
AnalizadaMedia (4.7)0.30%—Ivanti Secure Access Client13/11/202417/6/2026
A race condition in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to modify sensitive configuration files.
AnalizadaMedia (5.5)0.26%—Ivanti Secure Access Client12/11/202417/6/2026
A buffer over-read in Ivanti Secure Access Client before 22.7R4 allows a local unauthenticated attacker to cause a denial of service.
AnalizadaBaja (3.3)0.21%—Ivanti Secure Access Client12/11/202417/6/2026
Incorrect permissions in Ivanti Secure Access Client before version 22.7R4 allows a local authenticated attacker to create arbitrary folders.
AnalizadaAlta (7.1)0.22%—Ivanti Secure Access Client12/11/202417/6/2026
Improper authorization in Ivanti Secure Access Client before version 22.7R3 allows a local authenticated attacker to modify sensitive configuration files.
AnalizadaAlta (7.8)0.26%—Ivanti Secure Access Client12/11/202417/6/2026
Incorrect permissions in Ivanti Secure Access Client before 22.7R4 allows a local authenticated attacker to escalate their privileges.
ModificadaBaja (3.4)0.27%—Absolute Secure Access25/7/202417/6/2026
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.07. Attackers with system administrator permissions can interfere with another system administrator’s use of the publishing UI when the administrators are editing the same management…
AplazadaAlta (8.4)0.16%—Absolute Secure AccessAI25/7/202417/6/2026
There is an elevation of privilege vulnerability in server and client components of Absolute Secure Access prior to version 13.07. Attackers with local access and valid desktop user credentials can elevate their privilege to system level by passing invalid address data to the vulnerable component. This could be used…
ModificadaBaja (3.4)0.27%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06 that allows attackers with system administrator permissions to interfere with other system administrators’ use of the management UI when the second administrator accesses the vulnerable page. The scope…
ModificadaBaja (3.4)0.27%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with other system administrator’s use of the management UI when the second administrator later edits the same management object. This…
ModificadaMedia (4.7)0.28%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the policy management UI of Absolute Secure Access prior to version 13.06. Attackers can interfere with a system administrator’s use of the policy management UI when the attacker convinces the victim administrator to follow a crafted link to the vulnerable component…
ModificadaBaja (3.4)0.27%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with other system administrator’s use of the management UI when the victim administrator edits the same management object. This…
ModificadaBaja (3.4)0.27%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the management UI when the second administrator later edits the same management object. This…
ModificadaBaja (3.4)0.27%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the pool configuration component of the management UI of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can pass a limited length script to be run by another administrator. The scope is unchanged, there is no loss of…
ModificadaMedia (4.9)0.40%—Absolute Secure Access20/6/202417/6/2026
There is an insufficient input validation vulnerability in the Warehouse component of Absolute Secure Access prior to 13.06. Attackers with system administrator permissions can impair the availability of certain elements of the Secure Access administrative UI by writing invalid data to the warehouse over the network.…
ModificadaMedia (5.4)0.22%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the Secure Access administrative UI of Absolute Secure Access prior to version 13.06. Attackers can pass a limited-length script to the administrative UI which is then stored where an administrator can access it. The scope is unchanged, there is no loss of…
ModificadaBaja (3.4)0.27%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the Policy management UI of Absolute Secure Access prior to version 13.06. Attackers with system administrator permissions can interfere with another system administrator’s use of the policy management UI when the administrators are editing the same policy object. The…
ModificadaMedia (5.4)0.22%—Absolute Secure Access20/6/202417/6/2026
There is a cross-site scripting vulnerability in the Secure Access administrative console of Absolute Secure Access prior to version 13.06. Attackers with valid tunnel credentials can pass a limited-length script to the administrative console which is then temporarily stored where an administrator using a non-default…
AnalizadaAlta (7.3)0.31%—Ivanti Secure Access Client31/5/202417/6/2026
A local privilege escalation vulnerability in Ivanti Secure Access Client for Linux before 22.7R1, allows a low privileged user to execute code as root.
AnalizadaAlta (7.8)0.34%—Ivanti Secure Access Client31/5/202417/6/2026
A local privilege escalation vulnerability in Ivanti Secure Access Client for Windows allows a low privileged user to execute code as SYSTEM.
AnalizadaAlta (7.6)4.1%💥 PoCFortinet ForticlientCisco Anyconnect VPN ClientCisco Secure ClientPaloaltonetworks Globalprotect+56/5/202417/6/2026
DHCP can add routes to a client’s routing table via the classless static route option (121). VPN-based security solutions that rely on routes to redirect traffic can be forced to leak traffic over the physical interface. An attacker on the same local network can read, disrupt, or possibly modify network traffic that…
AnalizadaAlta (7.8)0.97%—Ivanti Pulse Secure Desktop ClientIvanti Pulse Secure Installer ServiceIvanti Secure Access Client3/5/202417/6/2026
Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to…
ModificadaAlta (7.8)0.45%—Ivanti Secure Access Client15/11/202317/6/2026
When a particular process flow is initiated, an attacker may be able to gain unauthorized elevated privileges on the affected system when having control over a specific file.
ModificadaMedia (5.5)0.37%—Ivanti Secure Access Client15/11/202317/6/2026
A logged in user can modify specific files that may lead to unauthorized changes in system-wide configuration settings. This vulnerability could be exploited to compromise the integrity and security of the network on the affected system.
ModificadaAlta (7.8)0.37%—Ivanti Secure Access Client15/11/202317/6/2026
A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine.
Orbitaley — Vulnerabilidades