Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.6%—Fatpipeinc Ipvpn FirmwareFatpipeinc Mpvpn FirmwareFatpipeinc Warp Firmware15/12/202117/6/2026
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows an authenticated, remote attacker with read-only privileges to create an account with administrative privileges. Older versions of FatPipe software may…
ModificadaMedia (5.3)2.7%💥 ExploitFatpipeinc Ipvpn FirmwareFatpipeinc Mpvpn FirmwareFatpipeinc Warp Firmware15/12/202117/6/2026
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote attacker to access at least the URL "/fpui/jsp/index.jsp" leading to unknown impact, presumably some violation of confidentiality. Older versions…
ModificadaAlta (7.5)1.8%—Fatpipeinc Ipvpn FirmwareFatpipeinc Mpvpn FirmwareFatpipeinc Warp Firmware15/12/202117/6/2026
A missing authorization vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, unauthenticated attacker to download a configuration archive. The attacker needs to know or correctly guess the hostname of the target system…
ModificadaCrítica (9.8)5.6%💥 ExploitFatpipeinc Ipvpn FirmwareFatpipeinc Mpvpn FirmwareFatpipeinc Warp Firmware15/12/202117/6/2026
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 includes an account named "cmuser" that has administrative privileges and no password. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is FPSA002.
ModificadaAlta (8.8)1.6%—Fatpipeinc Ipvpn FirmwareFatpipeinc Warp FirmwareFatpipeinc Mpvpn Firmware15/12/202117/6/2026
FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p91 and 10.2.2r42 allows a remote, authenticated attacker with read-only privileges to grant themselves administrative privileges. Older versions of FatPipe software may also be vulnerable. The FatPipe advisory identifier for this vulnerability is…
AnalizadaAlta (8.8)40%⚠ Explotación activaFatpipeinc Ipvpn FirmwareFatpipeinc Warp FirmwareFatpipeinc Mpvpn Firmware8/12/202117/6/2026
A vulnerability in the web management interface of FatPipe WARP, IPVPN, and MPVPN software prior to versions 10.1.2r60p92 and 10.2.2r44p1 allows a remote, unauthenticated attacker to upload a file to any location on the filesystem. The FatPipe advisory identifier for this vulnerability is FPSA006.
ModificadaMedia (6.1)1.0%—Icewarp Webclient7/7/202117/6/2026
Cross Site Scripting (XSS) in Webmail Calender in IceWarp WebClient 10.3.5 allows remote attackers to inject arbitrary web script or HTML via the "p4" field.
ModificadaAlta (7.8)0.27%—Cloudflare Warp3/2/202117/6/2026
Cloudflare WARP for Windows allows privilege escalation due to an unquoted service path. A malicious user or process running with non-administrative privileges can become an administrator by abusing the unquoted service path issue. Since version 1.2.2695.1, the vulnerability was fixed by adding quotes around the…
ModificadaMedia (6.1)5.3%💥 ExploitIcewarp Mail Server2/11/202017/6/2026
IceWarp 11.4.5.0 allows XSS via the language parameter.
ModificadaAlta (8.8)1.8%💥 PoCIcewarp Mail Server15/7/202017/6/2026
IceWarp Email Server 12.3.0.1 allows remote attackers to upload JavaScript files that are dangerous for clients to access.
ModificadaMedia (6.5)1.5%💥 PoCIcewarp Mail Server15/7/202017/6/2026
IceWarp Email Server 12.3.0.1 allows remote attackers to upload files and consume disk space.
ModificadaMedia (6.5)0.97%💥 PoCIcewarp Mail Server15/7/202017/6/2026
IceWarp Email Server 12.3.0.1 has Incorrect Access Control for user accounts.
ModificadaMedia (6.1)15%💥 ExploitIcewarp Server1/2/202017/6/2026
In IceWarp Webmail Server through 11.4.4.1, there is XSS in the /webmail/ color parameter.
ModificadaMedia (6.1)1.0%—Icewarp Mail Server6/1/202017/6/2026
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 1 of 2) in notes for contacts.
ModificadaMedia (5.4)0.72%—Icewarp Mail Server6/1/202017/6/2026
IceWarp WebMail Server 12.2.0 and 12.1.x before 12.2.1.1 (and probably earlier versions) allows XSS (issue 2 of 2) in notes for objects.
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/ with the parameter password is non-persistent in 10.2.0.
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][uid] is non-persistent in 10.1.3 and 10.2.0.
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][action] is non-persistent in 10.1.3 and 10.2.0.
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: webmail/basic/ with the parameter _dlg[captcha][controller] is non-persistent in 10.1.3 and 10.2.0.
ModificadaMedia (6.1)0.84%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has XSS via an HTTP POST request: admin/login.html with the parameter username is persistent in 10.2.0.
ModificadaAlta (7.5)2.8%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (script to basic/minimizer/index.php) is not properly sanitised and can therefore be exploited to browse the…
ModificadaAlta (7.5)2.6%—Icewarp Webclient11/10/201916/6/2026
IceWarp Webclient before 10.2.1 has a directory traversal vulnerability. This can result in loss of confidential data of IceWarp Mailserver and the operating system. Input passed via a certain parameter (_c to basic/index.html) is not properly sanitised and can therefore be exploited to browse the partition where…
ModificadaAlta (7.5)41%💥 ExploitIcewarp Mail Server3/6/201917/6/2026
IceWarp Mail Server through 10.4.4 is prone to a local file inclusion vulnerability via webmail/calendar/minimizer/index.php?style=..%5c directory traversal.
ModificadaMedia (6.1)1.1%—Icewarp Mail Server1/9/201817/6/2026
In IceWarp Server 12.0.3.1 and before, there is XSS in the /webmail/ username field.
ModificadaMedia (6.1)0.96%—Icewarp Mail Server30/6/201817/6/2026
Cross-site scripting (XSS) vulnerability for webdav/ticket/ URIs in IceWarp Mail Server 12.0.3 allows remote attackers to inject arbitrary web script or HTML.
Orbitaley — Vulnerabilidades