Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
1832 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.30% | — | Dell Powerprotect ONE | 26/8/2026 | 28/8/2026 | Dell PowerProtect One, versions 20.1.0.0 and below, contain a Reliance on Insufficiently Trustworthy Component vulnerability. An unauthenticated attacker with remote access could potentially exploit this vulnerability, leading to Cache poisoning. | |
| Analizada | Media (6.5) | 0.38% | — | Dell Powerprotect Cyber Recovery | 26/8/2026 | 2/9/2026 | Dell PowerProtect Cyber Recovery, versions 20.2 and prior, contain an Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Aplazada | Crítica (9.8) | 0.55% | — | UI Unifi Protect AI KEYAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect AI Key to escalate privileges on the device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (10) | 1.6% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Aplazada | Crítica (9.9) | 1.4% | — | UI Unifi ProtectAI | 26/8/2026 | 28/8/2026 | A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Protect Application to execute a Command Injection on the host device. | |
| Modificada | Alta (7.8) | 0.33% | 💥 PoC | Microsoft Malware Protection Engine | 14/8/2026 | 3/9/2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "ShieldBreak ". | |
| Aplazada | Media (5.3) | 0.47% | — | Prevent Direct Access Protect Wordpress FilesAI | 13/8/2026 | 14/8/2026 | The Prevent Direct Access – Protect WordPress Files plugin for WordPress is vulnerable to unauthorized access of protected files due to insufficient token validation in the `get_advance_file_by_url()` method in all versions up to, and including, 2.8.8.8 The method uses a SQL `LIKE` operator for token lookup without… | |
| Analizada | Media (5.9) | 0.20% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 3/9/2026 | Local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app enable a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows, and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The GlobalProtect… | |
| En análisis | Media (5.2) | 0.33% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 10/9/2026 | An improper input validation vulnerability exists in the Windows Pre-Logon Access Provider (PLAP) component of the Palo Alto Networks GlobalProtect™ app on Windows devices which enables a man-in-the-middle (MitM) attacker to execute arbitrary code with SYSTEM privileges on an affected client. The GlobalProtect app on… | |
| En análisis | Media (5.2) | 0.31% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 10/9/2026 | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man-in-the-middle (MitM) attacker or a rogue gateway to disrupt system processes and potentially execute arbitrary code with elevated privileges (SYSTEM privileges on Windows, and root privileges on macOS and Linux). | |
| En análisis | Media (4.5) | 0.14% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 10/9/2026 | Improper certificate validation vulnerabilities in Palo Alto Networks GlobalProtect™ app enable an unauthenticated attacker with man-in-the-middle (MitM) access to intercept and modify application communications. VPN tunnel traffic is not impacted. The GlobalProtect app on iOS, Android, and Chrome OS is not affected. | |
| Analizada | Media (4.1) | 0.07% | — | Paloaltonetworks Globalprotect | 13/8/2026 | 10/9/2026 | A race condition in the Palo Alto Networks GlobalProtect™ client on macOS enables a locally authenticated low-privileged attacker to escalate their privileges to root. The GlobalProtect app on Linux, Windows, iOS, Android, and Chrome OS is not affected. | |
| Aplazada | Alta (7.5) | 0.44% | — | Wpexperts Password ProtectedAI | 7/8/2026 | 26/8/2026 | The Password Protected — Lock Entire Site, Pages, Posts, Categories, and Partial Content WordPress plugin before 2.8.4 does not restrict REST API access to authenticated users when a specific option is enabled, allowing unauthenticated visitors to bypass the sitewide password gate and read otherwise-protected content… | |
| Aplazada | Media (6.5) | 0.33% | — | Acnam AD Invalid Click ProtectorAI | 27/7/2026 | 28/7/2026 | Unauthenticated Broken Access Control in Ad Invalid Click Protector (AICP) <= 1.3.0 versions. | |
| Aplazada | Alta (7.1) | 0.25% | — | Cleantalk Spam ProtectionAICleantalk AntispamAICleantalk FirewallAI | 27/7/2026 | 28/7/2026 | Unauthenticated Cross Site Scripting (XSS) in Spam protection, AntiSpam, FireWall by CleanTalk <= 6.82 versions. | |
| Analizada | Alta (8.8) | 0.42% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) a Generation of Incorrect Security Tokens vulnerability in the IAM. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.63% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (4.4) | 0.15% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Exposure of Sensitive Information to an Unauthorized Actor vulnerability in the REST API. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Information exposure. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.2) | 0.50% | — | Dell Powerprotect Data Manager | 22/7/2026 | 29/7/2026 | Dell PowerProtect Data Manager, versions prior to 20.2.0.0, contain(s) an Improper Input Validation vulnerability in the REST API. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.1) | 0.28% | — | Oracle Price Protection | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Price Protection | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful… | |
| Analizada | Media (6.3) | 0.26% | — | Oracle Price Protection | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful… |