Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
404 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 2.3% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 2.3% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 3.2% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Remote Code Execution Vulnerability | |
| Analizada | Alta (7.2) | 2.3% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 3.2% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Remote Code Execution Vulnerability | |
| Analizada | Alta (7.2) | 3.1% | — | Microsoft Defender FOR IOT | 9/4/2024 | 17/6/2026 | Microsoft Defender for IoT Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 0.73% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability in the UpdateServer component of Bitdefender GravityZone allows an attacker to execute arbitrary code on vulnerable instances. This issue affects the following products that include the vulnerable component: Bitdefender… | |
| Analizada | Crítica (9.8) | 0.52% | — | Bitdefender Endpoint SecurityBitdefender Gravityzone Control Center | 9/4/2024 | 17/6/2026 | An Incorrect Regular Expression vulnerability in Bitdefender GravityZone Update Server allows an attacker to cause a Server Side Request Forgery and reconfigure the relay. This issue affects the following products that include the vulnerable component: Bitdefender Endpoint Security for Linux version 7.0.5.200089… | |
| Analizada | Alta (7.8) | 0.20% | — | Bitdefender AntivirusBitdefender Antivirus PlusBitdefender Internet SecurityBitdefender Total Security | 1/4/2024 | 17/6/2026 | A configuration setting issue in seccenter.exe as used in Bitdefender Total Security, Bitdefender Internet Security, Bitdefender Antivirus Plus, Bitdefender Antivirus Free allows an attacker to change the product's expected behavior and potentially load a third-party library upon execution. This issue affects Total… | |
| Aplazada | Media (6.1) | 0.31% | — | Opswat Metadefender CoreAI | 27/3/2024 | 17/6/2026 | Opswat Metadefender Core before 5.2.1 does not properly defend against potential HTML injection and XSS attacks. | |
| Analizada | Media (5.5) | 0.91% | — | Microsoft Windows Defender Antimalware Platform | 12/3/2024 | 17/6/2026 | Microsoft Defender Security Feature Bypass Vulnerability | |
| Modificada | Alta (7.8) | 0.64% | — | Microsoft Defender FOR Endpoint | 13/2/2024 | 10/8/2026 | Microsoft Defender for Endpoint Protection Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.13% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 contains hard-coded credentials, such as a password or cryptographic key, which it uses for its own inbound authentication, outbound communication to external components, or encryption of internal data. IBM X-Force ID: 278749. | |
| Modificada | Media (5.5) | 0.15% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 stores user credentials in plain clear text which can be read by a local user. IBM X-Force ID: 278748. | |
| Modificada | Alta (7.2) | 0.42% | — | IBM Storage Defender Resiliency Service | 10/2/2024 | 17/6/2026 | IBM Storage Defender - Resiliency Service 2.0 could allow a privileged user to perform unauthorized actions after obtaining encrypted data from clear text key storage. IBM X-Force ID: 275783. | |
| Modificada | Media (5.4) | 0.33% | — | IBM Storage Defender Data Protect | 19/1/2024 | 17/6/2026 | IBM Storage Defender - Data Protect 1.0.0 through 1.4.1 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM… | |
| Modificada | Alta (7.5) | 0.48% | — | Wpmudev Defender Security | 8/1/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in WPMU DEV Defender Security – Malware Scanner, Login Security & Firewall.This issue affects Defender Security – Malware Scanner, Login Security & Firewall: from n/a through 4.1.0. | |
| Modificada | Alta (7.8) | 0.81% | — | Microsoft Windows Defender | 14/11/2023 | 17/6/2026 | Microsoft Windows Defender Elevation of Privilege Vulnerability | |
| Analizada | Alta (8.8) | 4.5% | ⚠ Explotación activa | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Carrier-grade NATF5 Big-ip Ddos Hybrid Defender+16 | 26/10/2023 | 17/6/2026 | An authenticated SQL injection vulnerability exists in the BIG-IP Configuration utility which may allow an authenticated attacker with network access to the Configuration utility through the BIG-IP management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached… | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Carrier-grade NAT+16 | 26/10/2023 | 17/6/2026 | Undisclosed requests may bypass configuration utility authentication, allowing an attacker with network access to the BIG-IP system through the management port and/or self IP addresses to execute arbitrary system commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Modificada | Media (5.3) | 2.2% | 💥 Exploit | Wpmudev Defender Security | 16/10/2023 | 17/6/2026 | The Defender Security WordPress plugin before 4.1.0 does not prevent redirects to the login page via the auth_redirect WordPress function, allowing an unauthenticated visitor to access the login page, even when the hide login page functionality of the plugin is enabled. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Media (4.4) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 10/10/2023 | 17/6/2026 | Exposure of Sensitive Information vulnerability exist in an undisclosed BIG-IP TMOS shell (tmsh) command which may allow an authenticated attacker with resource administrator role privileges to view sensitive information. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Modificada | Alta (8.7) | 0.43% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Application Security ManagerF5 Big-ip Domain Name System+14 | 10/10/2023 | 17/6/2026 | When running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing BIG-IP external monitor on a BIG-IP system. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of… | |
| Modificada | Alta (7.8) | 0.15% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+15 | 10/10/2023 | 17/6/2026 | The BIG-IP Edge Client Installer on macOS does not follow best practices for elevating privileges during the installation process. This vulnerability is due to an incomplete fix for CVE-2023-38418. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated |