Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1829 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.1) | 0.36% | — | Oracle Price Protection | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful… | |
| Analizada | Crítica (9.8) | 0.67% | — | IBM Storage Protect | 17/7/2026 | 11/8/2026 | IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash. | |
| Aplazada | Media (6.7) | 0.15% | — | Txone Networks SafeportagentAITxone Networks StellarprotectAI | 17/7/2026 | 27/7/2026 | Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file transfer to the victim device. The attacker needs to deploy unauthorized file on the… | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Malware Protection Engine | 14/7/2026 | 24/7/2026 | Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft Malware Protection Engine | 14/7/2026 | 24/7/2026 | Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally. | |
| Pendiente de análisis | Media (6.4) | 0.78% | — | Milestonesys XprotectAI | 14/7/2026 | 11/8/2026 | Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service. | |
| Pendiente de análisis | Media (5.9) | 0.31% | — | Drupal Brute Force Attack ProtectionAI | 10/7/2026 | 13/7/2026 | vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*. | |
| Analizada | Alta (8.8) | 0.49% | — | UI Unifi Protect | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device. | |
| Analizada | Crítica (9.9) | 0.47% | — | UI Unifi Protect | 2/7/2026 | 7/7/2026 | A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device. | |
| Analizada | Alta (7.5) | 0.50% | — | UI Protect Floodlight Firmware | 2/7/2026 | 9/7/2026 | A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight. | |
| Analizada | Alta (8.1) | 0.44% | — | UI Unifi Protect | 2/7/2026 | 7/7/2026 | A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras. | |
| Analizada | Crítica (9.8) | 0.57% | — | UI Unifi Protect | 2/7/2026 | 7/7/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming. | |
| Analizada | Alta (8.6) | 0.45% | — | UI Unifi Protect | 2/7/2026 | 6/7/2026 | A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints. | |
| En análisis | Crítica (9.1) | 0.63% | — | IBM Storage Protect | 22/6/2026 | 26/6/2026 | IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential… | |
| Modificada | Alta (7) | 0.37% | 💥 PoC | Microsoft Malware Protection Engine | 16/6/2026 | 12/8/2026 | Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ". | |
| Aplazada | Baja (3.5) | 0.24% | — | Ays-pro Secure Copy Content Protection AND Content LockingAI | 12/6/2026 | 17/6/2026 | The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite… | |
| Analizada | Media (4.4) | 0.10% | — | Paloaltonetworks Globalprotect | 10/6/2026 | 23/7/2026 | An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app… | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Draeger Protector SoftwareAI | 2/6/2026 | 22/7/2026 | Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM… | |
| Pendiente de análisis | Alta (8.3) | 0.11% | — | Draeger Protector SoftwareAI | 2/6/2026 | 22/7/2026 | Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM… | |
| Analizada | Media (6.5) | 0.38% | — | IBM Guardium Data Protection | 27/5/2026 | 17/6/2026 | IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode. | |
| Analizada | Media (5.6) | 0.09% | — | Synology Activeprotect Agent | 27/5/2026 | 7/10/2026 | Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation. | |
| Analizada | Alta (8.1) | 0.71% | 💥 PoC | Microsoft Malware Protection Engine | 20/5/2026 | 23/7/2026 | Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network. | |
| Analizada | Alta (7.8) | 0.44% | ⚠ Explotación activa💥 PoC | Microsoft Malware Protection Engine | 20/5/2026 | 24/7/2026 | Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally. | |
| Analizada | Media (5.9) | 0.18% | — | Paloaltonetworks Globalprotect | 13/5/2026 | 14/7/2026 | Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The… | |
| Analizada | Media (5.2) | 0.39% | — | Paloaltonetworks Globalprotect | 13/5/2026 | 14/7/2026 | A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between… |