Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2624 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (1.1) | 0.11% | — | Paloaltonetworks Prisma Access Agent | 13/8/2026 | 9/9/2026 | An improper link resolution before file access vulnerability exists in the Palo Alto Networks Prisma® Access Agent on Linux platforms that enables a local low privileged user to delete system files in a limited scope and disable Prisma Access Agent. The Prisma Access Agent on macOS, Windows, iOS, Android, and Chrome… | |
| Analizada | Crítica (9.8) | 0.40% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Analizada | Alta (7.8) | 0.21% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 could allow a local attacker to execute arbitrary code due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.1) | 0.11% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to injection of rogue certificate authority due to publicly writeable truststore. | |
| Analizada | Crítica (9.6) | 0.17% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 (ACS) is vulnerable to downloading unverified product code when configured to update from an IBM i. A bad actor could use this vulnerablity to run compromised code on the ACS user's workstation. | |
| Analizada | Alta (8.8) | 0.50% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to zip slip path traversal exploit when importing a configuration. | |
| Analizada | Alta (7.8) | 0.20% | — | IBM I Access Client Solutions | 12/8/2026 | 18/8/2026 | IBM i Access Client Solutions 1.1.2.0 through 1.1.9.13 is vulnerable to arbitrary code execution on Windows when installed for all users due to publicly writeable configuration file. | |
| Analizada | Alta (7.5) | 0.46% | — | IBM Security Verify AccessIBM Security Verify Access ContainerIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 18/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 is vulnerable to a denial of service attack. | |
| Analizada | Alta (8.1) | 0.35% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an authenticated user to gain privileges of another user via a specially crafted request. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow an administrator to execute additional commands they are not entitled to due to improper validation of user supplied input. | |
| Analizada | Alta (8.1) | 0.45% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 could allow a remote attacker to access sensitive information due to an inconsistent interpretation of an HTTP request by a reverse proxy. | |
| Analizada | Alta (7.2) | 0.54% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a input validation vulnerability in the management interface that allows already privileged attackers to execute additional operations by crafting a… | |
| Analizada | Alta (8.7) | 0.49% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 contains a format string injection vulnerability in the management interface that allows attackers to cause denial of service and information disclosure by… | |
| Analizada | Baja (3.1) | 0.29% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 and IBM Security Verify Access Container 10.0 through 10.0.9.2 Reverse Proxy in certain configurations is vulnerable to a denial of service attack. | |
| Analizada | Alta (7.4) | 0.32% | — | IBM Security Verify AccessIBM Verify Identity AccessIBM Verify Identity Access Container | 12/8/2026 | 17/8/2026 | IBM Security Verify Access 10.0 through 10.0.9.2 and IBM Verify Identity Access 11.0 through 11.0.3 and IBM Verify Identity Access Container 11.0 through 11.0.3 Reverse Proxy in certain configurations may provide weaker than expected cryptographic validation of user supplied data. | |
| Aplazada | Media (5.3) | 0.32% | — | User Access ManagerAI | 12/8/2026 | 26/8/2026 | The User Access Manager WordPress plugin before 2.3.15 does not apply its access restrictions to REST API requests, allowing unauthenticated attackers to read the content of posts, pages and custom post types that have been restricted to specific user groups. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 11/8/2026 | 14/8/2026 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 11/8/2026 | 14/8/2026 | Stack-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft AccessMicrosoft Office 2019Microsoft Office 2021+1 | 11/8/2026 | 14/8/2026 | Heap-based buffer overflow in Microsoft Office Access allows an unauthorized attacker to execute code locally. | |
| Aplazada | Alta (7.5) | 0.43% | — | Wpdataaccess WP Data AccessAI | 9/8/2026 | 26/8/2026 | The WP Data Access WordPress plugin before 5.5.79 does not validate the column names it accepts on one of its unauthenticated AJAX actions, and the nonce guarding that action does not cover them, allowing unauthenticated attackers to read arbitrary columns of the database table the affected front-end form is bound to,… | |
| Aplazada | Alta (7.1) | 0.25% | — | Wpdataaccess WP Data AccessAI | 6/8/2026 | 12/8/2026 | Unauthenticated Cross Site Scripting (XSS) in WP Data Access <= 5.5.79 versions. | |
| Analizada | Media (4.6) | 0.23% | — | Eclipse Accessibility Tools FrameworkSoumu Michecker | 5/8/2026 | 10/8/2026 | In Eclipse Accessibility Tools Framework (ACTF) versions up to 1.6.0 (including source code versions up to v20260630 and ACTF based application miChecker versions up to 3.1.0), it has been identified that an XML External Entity (XXE) vulnerability exists. If this vulnerability is exploited, a malicious third party… |