Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
194 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.37% | — | Ivanti Secure Access Client | 15/11/2023 | 17/6/2026 | A vulnerability exists on all versions of the Ivanti Secure Access Client below 22.6R1.1, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to a denial of service (DoS) condition on the user machine and, in some cases, resulting in a full compromise of the… | |
| Modificada | Alta (7.8) | 0.71% | 💥 PoC | Ivanti Secure Access Client | 15/11/2023 | 17/6/2026 | A vulnerability has been identified in the Ivanti Secure Access Windows client, which could allow a locally authenticated attacker to exploit a vulnerable configuration, potentially leading to various security risks, including the escalation of privileges, denial of service, or information disclosure. | |
| Modificada | Alta (7) | 0.67% | 💥 PoC | Ivanti Secure Access Client | 25/10/2023 | 17/6/2026 | A logged in user may elevate its permissions by abusing a Time-of-Check to Time-of-Use (TOCTOU) race condition. When a particular process flow is initiated, an attacker can exploit this condition to gain unauthorized elevated privileges on the affected system. | |
| Modificada | Alta (8.8) | 0.88% | — | Citrix Secure Access Client | 11/7/2023 | 17/6/2026 | A vulnerability has been discovered in the Citrix Secure Access client for Ubuntu which, if exploited, could allow an attacker to remotely execute code if a victim user opens an attacker-crafted link and accepts further prompts. | |
| Modificada | Alta (7.8) | 0.20% | — | Citrix Secure Access Client | 11/7/2023 | 17/6/2026 | A vulnerability has been discovered in the Citrix Secure Access client for Windows which, if exploited, could allow an attacker with access to an endpoint with Standard User Account that has the vulnerable client installed to escalate their local privileges to that of NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (8.8) | 1.3% | — | Pulsesecure Secure Access Series SSL VPN Sa-4000 | 21/12/2018 | 17/6/2026 | Certain Secure Access SA Series SSL VPN products (originally developed by Juniper Networks but now sold and supported by Pulse Secure, LLC) allow privilege escalation, as demonstrated by Secure Access SSL VPN SA-4000 5.1R5 (build 9627) 4.2 Release (build 7631). This occurs because appropriate controls are not… | |
| Modificada | Media (5.7) | 1.8% | — | Cisco Secure Access Control Server Solution Engine | 5/10/2018 | 17/6/2026 | A vulnerability in the web-based UI of Cisco Secure Access Control Server could allow an authenticated, remote attacker to gain read access to certain information in an affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an XML file. An attacker could exploit… | |
| Modificada | Crítica (9.8) | 6.8% | — | Cisco Secure Access Control System | 2/5/2018 | 17/6/2026 | A vulnerability in the ACS Report component of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected system. Commands executed by the attacker are processed at the targeted user's privilege level. The vulnerability is due to insufficient… | |
| Modificada | Baja (3.3) | 1.5% | — | Cisco Secure Access Control Server Solution Engine | 8/3/2018 | 17/6/2026 | A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an… | |
| Modificada | Baja (3.3) | 1.5% | — | Cisco Secure Access Control Server Solution Engine | 8/3/2018 | 17/6/2026 | A vulnerability in the web-based user interface of the Cisco Secure Access Control Server prior to 5.8 patch 9 could allow an unauthenticated, remote attacker to gain read access to certain information in the affected system. The vulnerability is due to improper handling of XML External Entities (XXEs) when parsing an… | |
| Analizada | Crítica (9.8) | 18% | ⚠ Explotación activa | Cisco Secure Access Control System | 8/3/2018 | 17/6/2026 | A vulnerability in Java deserialization used by Cisco Secure Access Control System (ACS) prior to release 5.8 patch 9 could allow an unauthenticated, remote attacker to execute arbitrary commands on an affected device. The vulnerability is due to insecure deserialization of user-supplied content by the affected… | |
| Modificada | Media (5.3) | 2.2% | — | Cisco Secure Access Control System | 30/11/2017 | 17/6/2026 | A vulnerability in the web-based interface of Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to view sensitive information on an affected system. The vulnerability exists because the affected software does not sufficiently protect system software version information when the… | |
| Modificada | Media (5.4) | 0.89% | — | Cisco Secure Access Control System | 7/8/2017 | 17/6/2026 | A vulnerability in the web-based management interface of the Cisco Secure Access Control System (ACS) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web interface of the affected system. More Information: CSCve70587. Known Affected Releases:… | |
| Modificada | Alta (7.5) | 2.4% | — | Cisco Secure Access Control System | 22/2/2017 | 17/6/2026 | A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to disclose sensitive information. More Information: CSCvc04854. Known Affected Releases: 5.8(2.5). | |
| Modificada | Media (6.1) | 1.5% | — | Cisco Secure Access Control System | 22/2/2017 | 17/6/2026 | A vulnerability in the web interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to redirect a user to a malicious web page, aka an Open Redirect Vulnerability. More Information: CSCvc04849. Known Affected Releases: 5.8(2.5). | |
| Modificada | Media (4.3) | 1.6% | — | Cisco Secure Access Control System | 22/2/2017 | 17/6/2026 | An XML External Entity vulnerability in the web-based user interface of the Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to have read access to part of the information stored in the affected system. More Information: CSCvc04845. Known Affected Releases: 5.8(2.5). | |
| Modificada | Media (6.1) | 1.5% | — | Cisco Secure Access Control System | 22/2/2017 | 17/6/2026 | A vulnerability in Cisco Secure Access Control System (ACS) could allow an unauthenticated, remote attacker to conduct a DOM-based cross-site scripting (XSS) attack against the user of the web interface of the affected system. More Information: CSCvc04838. Known Affected Releases: 5.8(2.5). | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Secure Access Control Server | 30/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (4) | 1.4% | — | Cisco Secure Access Control Server | 30/10/2015 | 17/6/2026 | The report-generation web interface in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and read report or status information, by visiting an unspecified web page. | |
| Modificada | Media (4) | 1.4% | — | Cisco Secure Access Control Server | 30/10/2015 | 17/6/2026 | The Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to bypass intended RBAC restrictions, and create a dashboard or portlet, by visiting an unspecified web page. | |
| Modificada | Media (4.3) | 1.4% | — | Cisco Secure Access Control Server | 30/10/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Media (6.5) | 1.4% | — | Cisco Secure Access Control Server | 30/10/2015 | 17/6/2026 | SQL injection vulnerability in the Solution Engine in Cisco Secure Access Control Server (ACS) 5.7(0.15) allows remote authenticated users to execute arbitrary SQL commands via a crafted URL, aka Bug ID CSCuw24700. | |
| Modificada | Media (4) | 1.6% | — | Cisco Secure Access Control Server | 20/9/2015 | 17/6/2026 | Cisco Secure Access Control Server (ACS) Solution Engine 5.7(0.15) allows remote authenticated users to cause a denial of service (SSH screen process crash) via crafted (1) CLI or (2) GUI commands, aka Bug ID CSCuw24694. | |
| Modificada | Media (4) | 2.0% | — | Cisco Identity Services Engine SoftwareCisco Secure Access Control System | 24/6/2015 | 17/6/2026 | Cisco Secure Access Control System before 5.4(0.46.2) and 5.5 before 5.5(0.46) and Cisco Identity Services Engine 1.0(4.573) do not properly implement access control for support bundles, which allows remote authenticated users to obtain sensitive information via brute-force attempts to send valid credentials, aka Bug… | |
| Modificada | Media (5) | 1.2% | — | Cisco Secure Access Control Server | 22/5/2015 | 17/6/2026 | The REST API in Cisco Access Control Server (ACS) 5.5(0.46.2) allows remote attackers to cause a denial of service (API outage) by sending many requests, aka Bug ID CSCut62022. |