Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 6.5% | — | Ivanti Avalanche | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to bypass authentication on affected installations of Ivanti Avalanche 6.3.2.3490. The specific flaw exists within the ProfileDaoImpl class. A crafted request can trigger execution of SQL queries composed from a user-supplied string. An attacker can leverage this… | |
| Modificada | Alta (8.8) | 15% | — | Ivanti Avalanche | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Ivanti Avalanche 6.3.2.3490. Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within the JwtTokenUtility class. The issue… | |
| Modificada | Alta (7.5) | 62% | — | Ivanti Avalanche | 10/3/2023 | 17/6/2026 | An improper authentication vulnerability exists in Avalanche version 6.3.x and below allows unauthenticated attacker to modify properties on specific port. | |
| Modificada | Alta (7.5) | 97% | 💥 Exploit | Ivanti Avalanche | 6/4/2022 | 17/6/2026 | Ivanti Avalanche (Premise) 6.3.2 allows remote unauthenticated users to read arbitrary files via Absolute Path Traversal. The imageFilePath parameter processed by the /AvalancheWeb/image endpoint is not verified to be within the scope of the image folder, e.g., the attacker can obtain sensitive information via the… | |
| Modificada | Alta (8.1) | 2.9% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform an arbitrary file write. | |
| Modificada | Alta (8.8) | 70% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | A command Injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. | |
| Modificada | Alta (8.8) | 67% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | A SQL Injection vulnerability exists in Ivanti Avalance before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. | |
| Modificada | Alta (8.8) | 62% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary code execution. | |
| Modificada | Alta (8.8) | 77% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | A command injection vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform arbitrary command execution. | |
| Modificada | Crítica (9.8) | 4.6% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | An exposed dangerous function vulnerability exists in Ivanti Avalanche before 6.3.3 using inforail Service allows Privilege Escalation via Enterprise Server Service. | |
| Modificada | Crítica (9.8) | 66% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | A deserialization of untrusted data vulnerability exists in Ivanti Avalanche before 6.3.3 using Inforail Service allows arbitrary code execution via Data Repository Service. | |
| Modificada | Alta (8.8) | 4.0% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | An improper authorization control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform privilege escalation. | |
| Modificada | Alta (8.8) | 82% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | An unrestricted file upload vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to write dangerous files. | |
| Modificada | Alta (8.8) | 2.7% | — | Ivanti Avalanche | 7/12/2021 | 17/6/2026 | An improper access control vulnerability exists in Ivanti Avalanche before 6.3.3 allows an attacker with access to the Inforail Service to perform a session takeover. | |
| Modificada | Media (6.7) | 1.6% | — | Spirent AvalancheSpirent Testcenter | 13/8/2020 | 17/6/2026 | An issue was discovered on Spirent TestCenter and Avalanche appliance admin interface firmware. An attacker, who already has access to an SSH restricted shell, can achieve root access via shell metacharacters. The attacker can then, for example, read sensitive files such as appliance admin configuration source code.… | |
| Modificada | Crítica (9.8) | 2.3% | — | Ivanti Avalanche | 28/4/2020 | 17/6/2026 | Ivanti Avalanche 6.3 allows a SQL injection that is vaguely associated with the Apache HTTP Server, aka Bug 683250. | |
| Modificada | Media (6.5) | 1.7% | — | Ivanti Avalanche | 29/6/2018 | 17/6/2026 | An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. The impacted products used a single shared key encryption model to encrypt data. A user with access to system databases can use the discovered key to access potentially confidential stored data, which may include Wi-Fi passwords. This… | |
| Modificada | Alta (7.8) | 0.66% | — | Ivanti Avalanche | 29/6/2018 | 17/6/2026 | An issue was discovered in Ivanti Avalanche for all versions between 5.3 and 6.2. A local user with database access privileges can read the encrypted passwords for users who authenticate via LDAP to Avalanche services. These passwords are stored in the Avalanche databases. This issue only affects customers who have… | |
| Modificada | Media (5) | 6.2% | 💥 Exploit | Codeavalanche Freeforum | 21/1/2009 | 16/6/2026 | CodeAvalanche FreeForum stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the password via a direct request for _private/CAForum.mdb. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Codeavalanche Articles | 12/1/2009 | 16/6/2026 | CodeAvalanche Articles stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAArticles.mdb. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Codeavalanche Freeforall | 12/1/2009 | 16/6/2026 | CodeAvalanche FreeForAll stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAFFAPage.mdb. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Codeavalanche Directory | 12/1/2009 | 16/6/2026 | CodeAvalanche Directory stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CADirectory.mdb. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (7.5) | 6.4% | 💥 Exploit | Codeavalanche Freewallpaper | 12/1/2009 | 16/6/2026 | CodeAvalanche FreeWallpaper stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CAFreeWallpaper.mdb. NOTE: some of these details are obtained from third… | |
| Modificada | Alta (7.5) | 2.4% | 💥 Exploit | Codeavalanche Ratemysite | 12/1/2009 | 16/6/2026 | CodeAvalanche RateMySite stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file containing the administrator password via a direct request for _private/CARateMySite.mdb. NOTE: some of these details are obtained from third party… | |
| Modificada | Alta (10) | 1.7% | 💥 Exploit | Xfairguy Codeavalanche News | 21/2/2007 | 16/6/2026 | SQL injection vulnerability in inc_listnews.asp in CodeAvalanche News 1.x allows remote attackers to execute arbitrary SQL commands via the CAT_ID parameter. |