Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2764▲ 64 respecto a la semana anterior
Críticas / altas1288▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)230▲ 212 respecto a la semana anterior
–

3076 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)0.36%—Phpscriptpoint Bloodbank23/7/202317/6/2026
A vulnerability was found in phpscriptpoint BloodBank 1.1. It has been rated as problematic. This issue affects some unknown processing of the file page.php. The manipulation leads to cross site scripting. The attack may be initiated remotely. The identifier VDB-235205 was assigned to this vulnerability. NOTE: The…
ModificadaAlta (7.8)5.7%—Checkpoint Endpoint Security23/7/202317/6/2026
Local privilege escalation in Check Point Endpoint Security Client (version E87.30) via crafted OpenSSL configuration file
ModificadaAlta (7.8)0.21%—Pointware Easyinventory23/7/202317/6/2026
A vulnerability was found in Pointware EasyInventory 1.0.12.0 and classified as critical. This issue affects some unknown processing of the file C:\Program Files (x86)\EasyInventory\Easy2W.exe. The manipulation leads to unquoted search path. Attacking locally is a requirement. The identifier VDB-235193 was assigned to…
ModificadaAlta (7.5)2.2%—Ivanti Endpoint Manager21/7/202317/6/2026
An out-of-bounds write vulnerability on windows operating systems causes the Ivanti AntiVirus Product to crash. Update to Ivanti AV Product version 7.9.1.285 or above.
ModificadaAlta (8.8)0.26%—Easy-appointments Easy Appointments17/7/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Nikola Loncar Easy Appointments plugin <= 3.11.9 versions.
ModificadaMedia (4.3)0.44%—Easyappointments17/7/202317/6/2026
Authorization Bypass Through User-Controlled Key in GitHub repository alextselegidis/easyappointments prior to 1.5.0.
ModificadaAlta (7.5)1.1%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Server Security Feature Bypass Vulnerability
ModificadaAlta (8.8)4.3%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaAlta (8.8)1.3%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Server Spoofing Vulnerability
ModificadaAlta (8.8)38%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Remote Code Execution Vulnerability
ModificadaAlta (8.8)2.6%—Microsoft Sharepoint Server11/7/202317/6/2026
Microsoft SharePoint Server Remote Code Execution Vulnerability
ModificadaMedia (6.1)0.38%—Gzscripts PHP GZ Appointment Scheduling Script10/7/202317/6/2026
A vulnerability classified as problematic was found in GZ Scripts PHP GZ Appointment Scheduling Script 1.8. Affected by this vulnerability is an unknown functionality of the file /load.php. The manipulation of the argument first_name/second_name/phone/address_1/country leads to cross site scripting. The attack can be…
ModificadaCrítica (9.8)13%💥 ExploitIvanti Endpoint Manager1/7/202317/6/2026
A improper input validation vulnerability exists in Ivanti Endpoint Manager 2022 and below that could allow privilege escalation or remote code execution.
ModificadaCrítica (9.8)3.1%—Ivanti Endpoint Manager1/7/202317/6/2026
A deserialization of untrusted data exists in EPM 2022 Su3 and all prior versions that allows an unauthenticated user to elevate rights. This exploit could potentially be used in conjunction with other OS (Operating System) vulnerabilities to escalate privileges on the machine or be used as a stepping stone to get to…
ModificadaMedia (5.5)0.28%—Malwarebytes Endpoint Detection AND ResponseMalwarebytes30/6/202317/6/2026
In Malwarebytes EDR 1.0.11 for Linux, it is possible to bypass the detection layers that depend on inode identifiers, because an identifier may be reused when a file is replaced, and because two files on different filesystems can have the same identifier.
ModificadaAlta (7.8)0.31%—Malwarebytes Endpoint Detection AND ResponseMalwarebytes30/6/202317/6/2026
The Malwarebytes EDR 1.0.11 for Linux driver doesn't properly ensure whitelisting of executable libraries loaded by executable files, allowing arbitrary code execution. The attacker can set LD_LIBRARY_PATH, set LD_PRELOAD, or run an executable file in a debugger.
ModificadaMedia (4.3)0.39%—Stormshield Endpoint Security27/6/202317/6/2026
Stormshield Endpoint Security Evolution 2.0.0 through 2.4.2 has Insecure Permissions. An ACL entry on the SES Evolution agent directory that contains the agent logs displayed in the GUI allows interactive users to read data, which could allow access to information reserved to administrators.
ModificadaMedia (5.5)0.19%—Stormshield Endpoint Security27/6/202317/6/2026
Stormshield Endpoint Security Evolution 2.0.0 through 2.3.2 has Insecure Permissions. An interactive user can use the SES Evolution agent to create arbitrary files with local system privileges.
ModificadaMedia (4.3)0.25%—Proofpoint Insider Threat Management Server27/6/202317/6/2026
A missing authorization check in multiple URL validation endpoints of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to smuggle content via DNS lookups. All versions before 7.14.3 are affected.
ModificadaMedia (6.5)0.31%—Proofpoint Insider Threat Management Server27/6/202317/6/2026
A missing authorization check in the MacOS agent configuration endpoint of the Insider Threat Management Server enables an anonymous attacker on an adjacent network to obtain sensitive information. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before…
ModificadaMedia (4.6)0.24%—Proofpoint Insider Threat Management Server27/6/202317/6/2026
A missing authorization check in multiple SOAP endpoints of the Insider Threat Management Server enables an attacker on an adjacent network to read and write unauthorized objects. Successful exploitation requires an attacker to first obtain a valid agent authentication token. All versions before 7.14.3 are affected.
ModificadaMedia (5.5)0.15%—Proofpoint Insider Threat Management27/6/202317/6/2026
An insecure filesystem permission in the Insider Threat Management Agent for Windows enables local unprivileged users to disrupt agent monitoring. All versions prior to 7.14.3 are affected. Agents for MacOS and Linux and Cloud are unaffected.
ModificadaCrítica (9.8)0.51%—Forcepoint Email SecurityForcepoint WEB Security15/6/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Forcepoint Cloud Security Gateway (CSG) Portal on Web Cloud Security Gateway, Email Security Cloud allows Blind SQL Injection.
ModificadaAlta (7.8)0.15%—Eset Cyber SecurityEset Endpoint AntivirusEset Server Security15/6/202317/6/2026
During internal security analysis, a local privilege escalation vulnerability has been identified. On a machine with the affected ESET product installed, it was possible for a user with lower privileges due to improper privilege management to trigger actions with root privileges. ESET remedied this possible attack…
ModificadaMedia (6.8)0.25%—Proofpoint Threat Response Auto Pull14/6/202317/6/2026
An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could…