Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

1829 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.36%—Oracle Price Protection21/7/202629/7/2026
Vulnerability in the Oracle Price Protection product of Oracle E-Business Suite (component: Internal Operations). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Price Protection. Successful…
AnalizadaCrítica (9.8)0.67%—IBM Storage Protect17/7/202611/8/2026
IBM Storage Protect Client 8.1.0.0 through 8.1.27.0, 8.1.27.1, and 8.2.0.0 through 8.2.1.0 IBM Storage Protect is vulnerable to a heap-based buffer overflow, caused by improper bounds checking. A remote attacker could overflow a buffer and execute arbitrary code on the system or cause the server to crash.
AplazadaMedia (6.7)0.15%—Txone Networks SafeportagentAITxone Networks StellarprotectAI17/7/202627/7/2026
Improper Access Control vulnerability in the Removable Media Validation function of TXOne Networks products allows a local attacker with administrator privileges to bypass the file lockdown mechanism, resulting in unauthorized file transfer to the victim device. The attacker needs to deploy unauthorized file on the…
AnalizadaAlta (7.8)0.47%—Microsoft Malware Protection Engine14/7/202624/7/2026
Integer overflow or wraparound in Microsoft Defender allows an unauthorized attacker to execute code locally.
AnalizadaAlta (7.8)0.47%—Microsoft Malware Protection Engine14/7/202624/7/2026
Integer underflow (wrap or wraparound) in Microsoft Defender allows an unauthorized attacker to execute code locally.
Pendiente de análisisMedia (6.4)0.78%—Milestonesys XprotectAI14/7/202611/8/2026
Milestone has released a new version of XProtect® (and several cumulative patch updates) which fix security vulnerability in Management Server API. The vulnerability causes users with edit permissions to the Management Server to be able to execute arbitrary code in context of the Management Server Service.
Pendiente de análisisMedia (5.9)0.31%—Drupal Brute Force Attack ProtectionAI10/7/202613/7/2026
vulnerability in Drupal Brute force attack protection allows . This issue affects Brute force attack protection versions: *.*.
AnalizadaAlta (8.8)0.49%—UI Unifi Protect2/7/20266/7/2026
A malicious actor with access to the network and low privileges could exploit an authenticated SQL Injection vulnerability found in UniFi Protect Application to escalate privileges on the host device.
AnalizadaCrítica (9.9)0.47%—UI Unifi Protect2/7/20267/7/2026
A malicious actor with access to the network and low privileges could exploit a Server-Side Request Forgery (SSRF) in UniFi Protect Application to escalate privileges on the host device.
AnalizadaAlta (7.5)0.50%—UI Protect Floodlight Firmware2/7/20269/7/2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Protect Floodlight devices to access files on the UniFi Protect Floodlight.
AnalizadaAlta (8.1)0.44%—UI Unifi Protect2/7/20267/7/2026
A malicious actor with access to the network and under certain conditions could exploit an Improper Initialization vulnerability found in UniFi Protect Application to bypass authentication in UniFi Protect Cameras.
AnalizadaCrítica (9.8)0.57%—UI Unifi Protect2/7/20267/7/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication for data streaming.
AnalizadaAlta (8.6)0.45%—UI Unifi Protect2/7/20266/7/2026
A malicious actor with access to the network could exploit an Improper Access Control vulnerability found in UniFi Protect Application to bypass authentication in certain UniFi Protect Application API endpoints.
En análisisCrítica (9.1)0.63%—IBM Storage Protect22/6/202626/6/2026
IBM Storage Protect Client 8.1.0.0 through 8.2.1.0 and IBM Storage Protect Snapshot For Windows 8.1.0.0 through 8.2.1.0 could allow a remote attacker to bypass authentication due to the use of a hardcoded credential in the FlashCopy Manager (FCM) authentication mechanism. The application contains a static credential…
ModificadaAlta (7)0.37%💥 PoCMicrosoft Malware Protection Engine16/6/202612/8/2026
Microsoft is aware of an elevation of privilege in the Microsoft Malware Protection Engine in Microsoft Defender publicly referred to as "RoguePlanet ".
AplazadaBaja (3.5)0.24%—Ays-pro Secure Copy Content Protection AND Content LockingAI12/6/202617/6/2026
The Secure Copy Content Protection and Content Locking WordPress plugin before 5.1.5 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite…
AnalizadaMedia (4.4)0.10%—Paloaltonetworks Globalprotect10/6/202623/7/2026
An information exposure vulnerability in the Palo Alto Networks GlobalProtect app on macOS enables a local user to learn the configured passcodes for disabling, disconnecting, or uninstalling the GlobalProtect app. After the passcode is known, the user can perform these actions even if the GlobalProtect app…
Pendiente de análisisAlta (8.3)0.11%—Draeger Protector SoftwareAI2/6/202622/7/2026
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM…
Pendiente de análisisAlta (8.3)0.11%—Draeger Protector SoftwareAI2/6/202622/7/2026
Dräger Protector Software prior to version 6.4.2 contains a local privilege escalation vulnerability due to insecure file system permissions that allows local attackers to execute arbitrary code with elevated privileges. Attackers can replace binaries or loaded modules on the host system to execute code with NT SYSTEM…
AnalizadaMedia (6.5)0.38%—IBM Guardium Data Protection27/5/202617/6/2026
IBM Guardium Data Protection 12.2.1, and 12.2.2 's add-on feature of Guardium Data Protection named "Long Term Retention" (LTR) can expose sensitive credentials in debug mode.
AnalizadaMedia (5.6)0.09%—Synology Activeprotect Agent27/5/20267/10/2026
Origin validation error vulnerability in Synology ActiveProtect Agent before 1.1.0-0439 allows local users to write arbitrary files with restricted content and conduct denial-of-service during installation.
AnalizadaAlta (8.1)0.71%💥 PoCMicrosoft Malware Protection Engine20/5/202623/7/2026
Heap-based buffer overflow in Microsoft Defender allows an unauthorized attacker to execute code over a network.
AnalizadaAlta (7.8)0.44%⚠ Explotación activa💥 PoCMicrosoft Malware Protection Engine20/5/202624/7/2026
Improper link resolution before file access ('link following') in Microsoft Defender allows an authorized attacker to elevate privileges locally.
AnalizadaMedia (5.9)0.18%—Paloaltonetworks Globalprotect13/5/202614/7/2026
Multiple local privilege escalation vulnerabilities in the Palo Alto Networks GlobalProtect™ app allow a local user to escalate their privileges to NT AUTHORITY\SYSTEM on Windows and root on macOS and Linux. This enables a non-administrative user to execute arbitrary commands with administrative privileges. The…
AnalizadaMedia (5.2)0.39%—Paloaltonetworks Globalprotect13/5/202614/7/2026
A buffer overflow vulnerability exists in the Palo Alto Networks GlobalProtect™ app that enables a man in the middle attacker to disrupt system processes and potentially execute arbitrary code with SYSTEM privileges. This vulnerability is triggered during the processing of requests and responses exchanged between…