Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

1881 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.3)0.49%💥 PoCZoom ClientAI11/8/202628/8/2026
Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access.
AplazadaCrítica (9.1)0.42%—Prosolution WP ClientAI10/8/202626/8/2026
The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection.
AplazadaAlta (8.6)0.52%—Prosolution WP ClientAI10/8/202626/8/2026
The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the…
AplazadaCrítica (9.8)0.76%💥 PoCInfinitewp ClientAI9/8/202626/8/2026
The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the…
Pendiente de análisisMedia (5.5)0.16%—Sonicwall Global VPN ClientAI7/8/202628/8/2026
SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash.
ModificadaMedia (5.3)0.46%—Apache Httpclient31/7/202613/8/2026
HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue…
AplazadaAlta (8)0.40%—Teamviewer Full ClientAITeamviewer HostAI29/7/202630/7/2026
TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host.
AnalizadaAlta (8.2)0.43%—Appium Java-client28/7/20267/8/2026
Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, AppiumCommandExecutor.setDirectConnect() reads the directConnectHost, directConnectPort, and directConnectPath fields from the server's…
AplazadaAlta (7.3)0.16%—Arksigner Software AND Hardware Industry AND Trade INC Arksigner Desktop ClientAI28/7/202628/7/2026
Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026.
Pendiente de análisisAlta (7.4)0.26%—Apereo CAS ClientAIJasig CAS ClientAI24/7/20263/9/2026
Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured…
Pendiente de análisisAlta (8.8)1.3%—LibsnowflakeclientAISnowflake PHP PDO DriverAISnowflake Odbc DriverAI24/7/202630/7/2026
Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a…
Pendiente de análisisBaja (2.4)0.35%—Kubernetes Java Client LibraryAI23/7/202623/7/2026
A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false.
AplazadaAlta (7.1)0.25%—Sprout ClientsAI23/7/202623/7/2026
Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions.
AplazadaAlta (8.8)0.14%—Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI22/7/202622/7/2026
The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory…
AplazadaMedia (5.3)0.45%—Cartodb Carto-api-clientAI18/7/202620/7/2026
A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads to improperly controlled modification of object prototype attributes. The attack can be executed remotely. The project was informed of the…
AnalizadaAlta (7.5)0.66%—Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center17/7/202622/7/2026
Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network.
Pendiente de análisisAlta (8.2)0.26%—Ongres Scram ClientAIOngres Scram CommonAI17/7/202623/7/2026
SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3.3, a flaw in com.ongres.scram:scram-client and com.ongres.scram:scram-common allows an attacker capable of a TLS man-in-the-middle attack…
Pendiente de análisisMedia (5.5)0.15%—Canonical Ubuntu-pro-clientAI16/7/202616/7/2026
An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL…
Pendiente de análisisMedia (5)0.21%—Canonical Ubuntu PRO ClientAI16/7/202616/7/2026
An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying…
Pendiente de análisisCrítica (9)0.53%—Canonical Ubuntu-pro-clientAI16/7/202616/7/2026
An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the…
AnalizadaCrítica (9.8)0.22%—Fortinet Forticlientems14/7/202615/7/2026
A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here>
Pendiente de análisisMedia (6.8)0.18%—Citrix Secure Access ClientAI14/7/202615/7/2026
Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.
Pendiente de análisisAlta (8.5)0.17%—Citrix Secure Access ClientAICitrix Endpoint Analysis ClientAI14/7/202615/7/2026
Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.
Pendiente de análisisMedia (4.1)0.26%—SAP CRM Webclient UIAI14/7/202614/7/2026
SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and…
AplazadaMedia (6.5)0.34%—Webventures Client Invoicing BY Sprout InvoicesAI13/7/202613/7/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13.