Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
1881 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.47% | — | Microsoft Remote Desktop ClientMicrosoft Windows APPMicrosoft Windows 10 1607Microsoft Windows 10 1809+11 | 9/6/2026 | 23/7/2026 | Concurrent execution using shared resource with improper synchronization ('race condition') in Remote Desktop Client allows an unauthorized attacker to execute code over a network. | |
| Aplazada | Alta (8.7) | 0.79% | — | Xcitium Client SecurityAIComodo Internet SecurityAI | 7/6/2026 | 23/7/2026 | Xcitium Client Security (XCS) before 13.8.2.10019 and Comodo Internet Security (CIS) through 12.3.4.8162 (fix expected by 2026 Q3) contain an integer underflow vulnerability in the firewall driver Inspect.sys that allows remote unauthenticated attackers to crash the system by sending a crafted IPv6 packet with a… | |
| Analizada | Alta (7.4) | 0.46% | — | Asynchttpclient Project Async-http-client | 5/6/2026 | 23/7/2026 | The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. Versions on the 2.x branch prior to 2.15.0 and the 3.x branch prior to 3.0.10 leak `Cookie` headers to cross-origin redirect targets. When following a redirect to a different origin,… | |
| Analizada | Alta (8.5) | 0.10% | — | Forcepoint VPN Client | 4/6/2026 | 22/7/2026 | A local privilege escalation vulnerability exists in Forcepoint VPN Client that allows a local non-administrative user to escalate privileges to SYSTEM. This issue affects VPN Client for Windows: versions 6.11.3 and prior. | |
| Analizada | Media (5.9) | 0.13% | — | Synology Note Station Client | 3/6/2026 | 22/7/2026 | A cleartext transmission of sensitive information vulnerability in Synology Note Station Client before 2.2.4-703 allows man-in-the-middle attackers to obtain user credential. | |
| Aplazada | Media (6.5) | 0.39% | — | Slovak EID Client Ecosystem D.launcherAI | 2/6/2026 | 22/7/2026 | D.Launcher 2 component of Slovak eID client ecosystem contains Improper URL Handler Processing vulnerability. Application registers multiple custom URL handlers that could be exploited to initiate full NTLM autentication or SMB connection to attacker infrastructure and to conduct SSRF (Server Side Request Forgery)… | |
| Analizada | Alta (8.8) | 0.81% | — | IBM I Access Client Solutions | 1/6/2026 | 26/8/2026 | IBM i Access Family 1.1.5.0 through 1.1.9.12 IBM i Access Client Solutions (ACS) is vulnerable to remote code execution when configured to listen for requests from IBM i Navigator. | |
| Pendiente de análisis | Baja (2) | 0.13% | — | Strongdm Desktop ApplicationAIStrongdm Desktop ClientAIMicrosoft WindowsAI | 29/5/2026 | 6/10/2026 | StrongDM Desktop Application before 23.74.0 (Desktop Client before 53.77.0) on Microsoft Windows stores authentication state, including a JSON Web Token and asymmetric key material, in cleartext in a per-user state file located at C:\Users\<username>\.sdm\state.kv. The file is protected only by default user-level NTFS… | |
| Aplazada | Media (5.3) | 0.18% | — | Northern.tech Mender ClientAI | 27/5/2026 | 17/6/2026 | Northern.tech Mender Client 5 before 5.0.4 allows a Cryptographic signature verification bypass. | |
| Pendiente de análisis | Alta (8.8) | 0.44% | — | LibvncclientAI | 27/5/2026 | 17/6/2026 | LibVNCClient is a library for easy implementation of a VNC client. In 0.9.15 and earlier, LibVNCClient's Tight encoding decoder uses fixed-size 2048-pixel scratch buffers for the Gradient filter, but it does not reject Tight rectangles whose width is larger than 2048 pixels. A malicious VNC server can send a crafted… | |
| Aplazada | Alta (8.1) | 0.19% | — | Epa4all-clientAI | 26/5/2026 | 24/7/2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker on the network path between the ePA service and the Konnektor can present any TLS certificate (self-signed, expired, wrong CN) and intercept all SOAP traffic. This includes patient identifiers (KVNR),… | |
| Aplazada | Alta (8.1) | 0.16% | — | Epa4all ClientAI | 26/5/2026 | 24/7/2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.1, in SignedPublicKeysTrustValidatorImpl.isTrusted(), the ECDSA signature verification at line 45 discards the boolean return value of Signature.verify(). The method performs certificate chain validation, OCSP check,… | |
| Aplazada | Media (6.5) | 0.24% | — | Epa4all-clientAI | 26/5/2026 | 24/7/2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. In 1.2.4 and earlier, any network-reachable caller can write arbitrary documents to any patient's electronic health record accessible by the institution's SMC-B card. In a misconfigured deployment (e.g., following the production… | |
| Aplazada | Alta (7.4) | 0.15% | — | Epa4all-clientAI | 26/5/2026 | 24/7/2026 | epa4all-client is the Java Client for epa4all / ePA 3.0 in the Telematik Infrastruktur. Prior to 1.2.2, an attacker who can MITM the TLS connection between the client and the IDP (within the TI network) can substitute a forged discovery document. The forged document redirects uri_puk_idp_enc and uri_puk_idp_sig to… | |
| Analizada | Alta (8.8) | 1.2% | — | Ivanti Secure Access Client | 22/5/2026 | 23/7/2026 | An improper certificate validation vulnerability in Ivanti Secure Access Client before 22.8R6 allows a remote unauthenticated attacker to execute arbitrary code. | |
| Aplazada | Baja (2.3) | 0.09% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Insufficient Verification of Data Authenticity in the feedback function of Mesalvo MEONA (MEONA Client and MEONA Server). The MEONA Client transmits the recipient address of a feedback report to the MEONA Server, and the server sends the report to the transmitted address instead of the address configured on the… | |
| Rechazada | Sin puntuar | — | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| Aplazada | Alta (7.9) | 0.28% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 1/10/2026 | Vendor disputed record. The reported behaviour is documented administrative functionality restricted to dedicated administrative permissions assigned by the operating hospital; its use by a permission holder is not a vulnerability. Unauthorised access to the functions is addressed under CVE-2026-0856. Improper Control… | |
| Aplazada | Media (4.4) | 0.10% | — | Mesalvo Meona Client LauncherAIMesalvo Meona ServerAI | 20/5/2026 | 25/9/2026 | Use of a Password Hash With Insufficient Computational Effort in Mesalvo MEONA (MEONA Server and MEONA Client) for user accounts whose password was last set under a version before MEONA 2024.10. MEONA versions before 2024.10 protected stored passwords with SHA-1 (versions from October 2015) or stored them without… | |
| Aplazada | Alta (7.8) | 0.13% | — | Mesalvo Meona Client Launcher ComponentAIMesalvo Meona Server ComponentAI | 20/5/2026 | 25/9/2026 | Improper Access Control vulnerability in Mesalvo MEONA (MEONA Client and MEONA Server) allows an authenticated MEONA user to access administrative functions of the MEONA Client (admin panel). The MEONA Server does not independently verify the role asserted by the MEONA Client. A user who holds a valid MEONA user… | |
| Aplazada | Crítica (9.8) | 1.4% | — | Prosolution WP ClientAI | 20/5/2026 | 24/7/2026 | The ProSolution WP Client plugin for WordPress is vulnerable to Arbitrary File Upload in versions up to, and including, 2.0.0. This is due to an array validation mismatch where only the first file in the upload array undergoes extension and MIME type validation, while all files are processed and uploaded to a… | |
| Analizada | Media (5.5) | 0.14% | — | Fortinet Forticlient | 12/5/2026 | 17/6/2026 | A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientWindows 7.4.0 through 7.4.2, FortiClientWindows 7.2 all versions may allow attacker to information disclosure via <insert attack vector here> | |
| Analizada | Alta (7.5) | 0.41% | — | Opentelemetry.opamp.client | 12/5/2026 | 17/6/2026 | OpenTelemetry.OpAmp.Client is the OpAMP client for OpenTelemetry .NET. Prior to 0.2.0-alpha.1, when receiving responses from the OpAMP server over HTTP, the OpAMP client allocates an unbounded buffer to read all bytes from the server, with no upper-bound on the number of bytes consumed. This could cause memory… | |
| Analizada | Alta (7) | 0.38% | — | Ivanti Secure Access Client | 12/5/2026 | 17/6/2026 | A race condition in Ivanti Secure Access Client before 22.8R6 allows a locally authenticated user to escalate privileges to SYSTEM | |
| Analizada | Media (4.4) | 0.24% | — | Ivanti Secure Access Client | 12/5/2026 | 17/6/2026 | An incorrect permission assignment for critical resource of Ivanti Secure Access Client before 22.8R6 allows a local authenticated user to read or modify sensitive log data via write access to a shared memory section. |