Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2983▼ 79 respecto a la semana anterior
Críticas / altas1412▲ 62 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.49% | 💥 PoC | Zoom ClientAI | 11/8/2026 | 28/8/2026 | Missing bounds check in the annotator function of Zoom Clients allows buffer over-write, which may allow a meeting participant to achieve remote code execution of another participant via network access. | |
| Aplazada | Crítica (9.1) | 0.42% | — | Prosolution WP ClientAI | 10/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.6 does not sanitise and escape a parameter before using it in a SQL statement reachable by unauthenticated visitors, leading to a blind SQL injection. | |
| Aplazada | Alta (8.6) | 0.52% | — | Prosolution WP ClientAI | 10/8/2026 | 26/8/2026 | The ProSolution WP Client WordPress plugin before 2.0.9 does not sanitise a cookie value before using it in SQL queries, and processes that cookie on every request without any authentication or capability check, allowing unauthenticated users to read arbitrary data from the database and to delete the records the… | |
| Aplazada | Crítica (9.8) | 0.76% | 💥 PoC | Infinitewp ClientAI | 9/8/2026 | 26/8/2026 | The InfiniteWP Client WordPress plugin before 1.13.6 does not properly verify the site-connection state and the authenticity of requests to its remote-management endpoint on WordPress Multisite installations, allowing unauthenticated attackers to bind their own key, hijack an administrator session, and take over the… | |
| Pendiente de análisis | Media (5.5) | 0.16% | — | Sonicwall Global VPN ClientAI | 7/8/2026 | 28/8/2026 | SonicWall Global VPN Client version 4.10.8.1108 and earlier is vulnerable to an out-of-bounds kernel memory read in the SWIPsec.sys driver, which could allow a local attacker to cause a system crash. | |
| Modificada | Media (5.3) | 0.46% | — | Apache Httpclient | 31/7/2026 | 13/8/2026 | HttpClient based on the classic i/o model fails to correctly release the underlying connection back to the connection manager if it encounters an invalid or unsupported `Content-Encoding` header value in the response message. Please note this defect does not affect HttpClient based on the async i/o model. This issue… | |
| Aplazada | Alta (8) | 0.40% | — | Teamviewer Full ClientAITeamviewer HostAI | 29/7/2026 | 30/7/2026 | TeamViewer Full Client and Host for macOS before version 15.80 contain a business logic error that can allow an authenticated attacker to bypass a configured 2FA for Connections approval flow via Unattended Access and establish a remote connection to an affected macOS host. | |
| Analizada | Alta (8.2) | 0.43% | — | Appium Java-client | 28/7/2026 | 7/8/2026 | Appium Java Client is the Java language binding for writing Appium tests that conform to the W3C WebDriver protocol. From 8.2.1 until 10.1.1, when directConnect(true) is enabled, AppiumCommandExecutor.setDirectConnect() reads the directConnectHost, directConnectPort, and directConnectPath fields from the server's… | |
| Aplazada | Alta (7.3) | 0.16% | — | Arksigner Software AND Hardware Industry AND Trade INC Arksigner Desktop ClientAI | 28/7/2026 | 28/7/2026 | Uncontrolled Search Path Element vulnerability in ArkSigner Software and Hardware Industry and Trade Inc. ArkSigner Desktop Client allows Search Order Hijacking. This issue affects ArkSigner Desktop Client: from v2.2.16.10 through 17062026. | |
| Pendiente de análisis | Alta (7.4) | 0.26% | — | Apereo CAS ClientAIJasig CAS ClientAI | 24/7/2026 | 3/9/2026 | Apereo CAS Client accepts any CA-trusted certificate for any hostname, provided the URL the client is calling matches the configured allowlist or regex. An attacker with a MITM position (DNS poisoning, rogue Wi-Fi, malicious proxy, etc.) can provide any CA-signed certificate for a hostname that matches the configured… | |
| Pendiente de análisis | Alta (8.8) | 1.3% | — | LibsnowflakeclientAISnowflake PHP PDO DriverAISnowflake Odbc DriverAI | 24/7/2026 | 30/7/2026 | Multiple security vulnerabilities in Snowflake libsnowflakeclient versions prior to 2.9.2 could allow remote code execution and credential exfiltration. A stack-based buffer overflow in the file download path could allow remote code execution on a victim host. An attacker could exploit this by uploading a file with a… | |
| Pendiente de análisis | Baja (2.4) | 0.35% | — | Kubernetes Java Client LibraryAI | 23/7/2026 | 23/7/2026 | A security issue was discovered in the Kubernetes Java client library where a compromised pod may be able to create new files in arbitrary locations on the client machine executing copy operations via non-tar copyDirectoryFromPod when enableTarCompressing is false. | |
| Aplazada | Alta (7.1) | 0.25% | — | Sprout ClientsAI | 23/7/2026 | 23/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Sprout Clients <= 3.2.3 versions. | |
| Aplazada | Alta (8.8) | 0.14% | — | Servereye ClientAIServereye SensorhubAIServereye ClientagentcontainerserviceAI | 22/7/2026 | 22/7/2026 | The servereye client (also known as sensorhub, technically ClientAgentContainerService) versions 20.15 and earlier are vulnerable to Local Privilege Escalation. The high-privileged service SE3Recovery (EmergencyRecoveryService.exe), running as SYSTEM, periodically monitors the directory… | |
| Aplazada | Media (5.3) | 0.45% | — | Cartodb Carto-api-clientAI | 18/7/2026 | 20/7/2026 | A vulnerability has been found in CartoDB carto-api-client 0.5.29. This impacts the function addFilter of the file src/filters.ts. Such manipulation of the argument column leads to improperly controlled modification of object prototype attributes. The attack can be executed remotely. The project was informed of the… | |
| Analizada | Alta (7.5) | 0.66% | — | Microsoft Remote Desktop WEB ClientMicrosoft Windows Admin Center | 17/7/2026 | 22/7/2026 | Exposure of private personal information to an unauthorized actor in Windows RDP allows an unauthorized attacker to disclose information over a network. | |
| Pendiente de análisis | Alta (8.2) | 0.26% | — | Ongres Scram ClientAIOngres Scram CommonAI | 17/7/2026 | 23/7/2026 | SCRAM (Salted Challenge Response Authentication Mechanism) is part of the family of Simple Authentication and Security Layer (SASL, RFC 4422) authentication mechanisms. Prior to 3.3, a flaw in com.ongres.scram:scram-client and com.ongres.scram:scram-common allows an attacker capable of a TLS man-in-the-middle attack… | |
| Pendiente de análisis | Media (5.5) | 0.15% | — | Canonical Ubuntu-pro-clientAI | 16/7/2026 | 16/7/2026 | An information disclosure vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client validates Ubuntu Pro APT credentials by executing /usr/lib/apt/apt-helper using the download-file command. During this process, the secret bearer token is embedded directly in the cleartext URL… | |
| Pendiente de análisis | Media (5) | 0.21% | — | Canonical Ubuntu PRO ClientAI | 16/7/2026 | 16/7/2026 | An insecure symlink following vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools) within the pro collect-logs command framework. The utility creates or utilizes predictable temporary file paths or user-accessible log directories when gathering diagnostic information without verifying… | |
| Pendiente de análisis | Crítica (9) | 0.53% | — | Canonical Ubuntu-pro-clientAI | 16/7/2026 | 16/7/2026 | An input validation and injection vulnerability exists in Canonical ubuntu-pro-client (formerly ubuntu-advantage-tools). The client constructs APT source files (such as /etc/apt/sources.list.d/ubuntu-.list or their DEB822 equivalents) using data received directly from the contract server response via the… | |
| Analizada | Crítica (9.8) | 0.22% | — | Fortinet Forticlientems | 14/7/2026 | 15/7/2026 | A improper certificate validation vulnerability in Fortinet FortiClientEMS 7.4.3 through 7.4.5, FortiClientEMS 7.4.0 through 7.4.1, FortiClientEMS 7.2 all versions may allow attacker to information disclosure via <insert attack vector here> | |
| Pendiente de análisis | Media (6.8) | 0.18% | — | Citrix Secure Access ClientAI | 14/7/2026 | 15/7/2026 | Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20. | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Citrix Secure Access ClientAICitrix Endpoint Analysis ClientAI | 14/7/2026 | 15/7/2026 | Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7. | |
| Pendiente de análisis | Media (4.1) | 0.26% | — | SAP CRM Webclient UIAI | 14/7/2026 | 14/7/2026 | SAP CRM WebClient UI allows an attacker to inject and execute malicious scripts in the context of the application due to the absence of a Content Security Policy (CSP) configuration for certain restrictive directives. This vulnerability has a low impact on the integrity of the application. Confidentiality and… | |
| Aplazada | Media (6.5) | 0.34% | — | Webventures Client Invoicing BY Sprout InvoicesAI | 13/7/2026 | 13/7/2026 | Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.13. |