Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

222 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (10)47%⚠ Explotación activa💥 PoCIvanti Connect Secure23/4/202112/8/2026
Pulse Connect Secure 9.0R3/9.1R1 and higher is vulnerable to an authentication bypass vulnerability exposed by the Windows File Share Browser and Pulse Secure Collaboration features of Pulse Connect Secure that can allow an unauthenticated user to perform remote arbitrary code execution on the Pulse Connect Secure…
ModificadaMedia (5.5)0.23%—Cisco Anyconnect Secure Mobility Client24/2/202117/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the device. The…
ModificadaAlta (7.8)1.3%💥 PoCCisco Anyconnect Secure Mobility Client17/2/202117/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack on an affected device if the VPN Posture (HostScan) Module is installed on the AnyConnect client. This vulnerability is…
ModificadaMedia (5.5)0.34%—Cisco Anyconnect Secure Mobility ClientMcafee Agent Epolicy Orchestrator Extension13/1/202117/6/2026
A vulnerability in the upgrade component of Cisco AnyConnect Secure Mobility Client could allow an authenticated, local attacker with low privileges to read arbitrary files on the underlying operating system (OS) of an affected device. The vulnerability is due to insufficient file permission restrictions. An attacker…
ModificadaAlta (7.8)0.40%—Cisco Anyconnect Secure Mobility Client13/1/202117/6/2026
A vulnerability in the Network Access Manager and Web Security Agent components of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL injection attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.…
ModificadaAlta (7.3)0.45%—Cisco Anyconnect Secure Mobility Client6/11/202017/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client Software could allow an authenticated, local attacker to cause a targeted AnyConnect user to execute a malicious script. The vulnerability is due to a lack of authentication to the IPC listener. An attacker could…
ModificadaMedia (5.5)0.33%—Cisco Anyconnect Secure Mobility Client6/11/202017/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to read arbitrary files on the underlying operating system of an affected device. The vulnerability is due to an exposed IPC function. An attacker could…
ModificadaMedia (6.1)1.8%—Ivanti Connect SecureIvanti Policy SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure28/10/202017/6/2026
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure below 9.1R9 could allow attackers to conduct Cross-Site Scripting (XSS) and Open Redirection for authenticated user web interface.
ModificadaMedia (4.3)2.2%—Ivanti Connect SecureIvanti Policy SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure28/10/202017/6/2026
A vulnerability in the Pulse Connect Secure / Pulse Policy Secure < 9.1R9 is vulnerable to arbitrary cookie injection.
AnalizadaAlta (7.2)96%⚠ Explotación activa💥 ExploitIvanti Connect Secure28/10/202017/6/2026
A vulnerability in the Pulse Connect Secure < 9.1R9 admin web interface could allow an authenticated attacker to perform an arbitrary code execution using uncontrolled gzip extraction.
ModificadaAlta (7.2)3.2%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure27/10/202017/6/2026
An XML external entity (XXE) vulnerability in Pulse Connect Secure (PCS) before 9.1R9 and Pulse Policy Secure (PPS) before 9.1R9 allows remote authenticated admins to conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
ModificadaMedia (4.9)3.4%—Ivanti Connect SecurePulsesecure Pulse Connect Secure30/9/202017/6/2026
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to gain arbitrary file reading access through Pulse Collaboration via XML External Entity (XXE) vulnerability.
AnalizadaAlta (7.2)91%⚠ Explotación activaIvanti Connect SecureIvanti Policy Secure30/9/202017/6/2026
A vulnerability in the Pulse Connect Secure < 9.1R8.2 admin web interface could allow an authenticated attacker to upload custom template to perform an arbitrary code execution.
ModificadaMedia (6.1)1.7%—Ivanti Connect SecureIvanti Policy SecurePulsesecure Pulse Connect SecurePulsesecure Pulse Policy Secure30/9/202017/6/2026
A vulnerability in the authenticated user web interface of Pulse Connect Secure and Pulse Policy Secure < 9.1R8.2 could allow attackers to conduct Cross-Site Scripting (XSS).
ModificadaAlta (7.1)0.36%—Cisco Anyconnect Secure Mobility Client23/9/202017/6/2026
A vulnerability in the inter-service communication of Cisco AnyConnect Secure Mobility Client for Android could allow an unauthenticated, local attacker to perform a service hijack attack on an affected device or cause a denial of service (DoS) condition. The vulnerability is due to the use of implicit service…
ModificadaMedia (5.5)0.34%—Cisco Anyconnect Secure Mobility Client17/8/202017/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to overwrite VPN profiles on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system.…
ModificadaMedia (5.5)0.46%—Cisco Anyconnect Secure Mobility Client17/8/202017/6/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to cause a denial of service (DoS) condition on an affected device. To exploit this vulnerability, the attacker would need to have valid credentials on the…
AnalizadaAlta (7.8)10%⚠ Explotación activa💥 ExploitCisco Anyconnect Secure Mobility Client17/8/202012/8/2026
A vulnerability in the interprocess communication (IPC) channel of Cisco AnyConnect Secure Mobility Client for Windows could allow an authenticated, local attacker to perform a DLL hijacking attack. To exploit this vulnerability, the attacker would need to have valid credentials on the Windows system. The…
ModificadaMedia (6.8)2.3%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 that allowed an authenticated attacker via the administrator web interface to perform an arbitrary file reading vulnerability through Meeting.
ModificadaMedia (4.9)2.3%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A path traversal vulnerability exists in Pulse Connect Secure <9.1R8 which allows an authenticated attacker to read arbitrary files via the administrator web interface.
ModificadaMedia (6.5)2.5%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A denial of service vulnerability exists in Pulse Connect Secure <9.1R8 that allows an authenticated attacker to perform command injection via the administrator web which can cause DOS.
ModificadaAlta (7.2)2.2%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
An insufficient permission check vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to change the password of a full administrator.
AnalizadaAlta (7.2)32%⚠ Explotación activa💥 PoCIvanti Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A code injection vulnerability exists in Pulse Connect Secure <9.1R8 that allows an attacker to crafted a URI to perform an arbitrary code execution via the admin web interface.
ModificadaMedia (5.4)1.4%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
A cross site scripting (XSS) vulnerability in Pulse Connect Secure <9.1R8 allowed attackers to exploit in the URL used for Citrix ICA.
ModificadaMedia (4.3)2.3%—Ivanti Connect SecurePulsesecure Pulse Connect SecureIvanti Policy SecurePulsesecure Pulse Policy Secure30/7/202017/6/2026
An information disclosure vulnerability in meeting of Pulse Connect Secure <9.1R8 allowed an authenticated end-users to find meeting details, if they know the Meeting ID.