Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

2632 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (2.1)0.32%—Absolute Secure Access15/7/202616/7/2026
CVE-2026-40955 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client.
ModificadaBaja (2.1)0.32%—Absolute Secure Access15/7/202616/7/2026
CVE-2026-40954 is an integer underflow vulnerability in the traffic parsing function of Secure Access clients prior to 14.55. Attackers with intimate knowledge of and total control over the tunnel protocol can create a non-persistent DoS against their client
ModificadaMedia (6.7)0.10%—Absolute Secure Access15/7/202616/7/2026
CVE-2026-40953 is a heap overflow in the certificate parsing function of Secure Access clients prior to 14.55. Attackers with local access and administrator permissions can create a denial of service attack against the client over which they have control.
ModificadaAlta (8.5)0.14%—Absolute Secure Access15/7/202616/7/2026
CVE-2026-40952 is a privilege misconfiguration in the Secure Access installer for the Windows client and server prior to version 14.55. Attackers with local access to the client or server can use it to elevate privileges to Administrator when Secure Access is installed in a non-default location.
ModificadaAlta (7.1)0.37%—Absolute Secure Access15/7/202616/7/2026
CVE-2026-33443 is a memory management error in Secure Access servers prior to 14.55. Attackers with an intimate knowledge of and total control over the tunnel protocol can create a persistent DoS against the server.
Pendiente de análisisMedia (6.8)0.18%—Citrix Secure Access ClientAI14/7/202615/7/2026
Out-of-bounds read vulnerability in Citrix Citrix Secure Access Client for Windows. This issue affects Citrix Secure Access Client for Windows: before 26.6.1.20.
Pendiente de análisisAlta (8.5)0.17%—Citrix Secure Access ClientAICitrix Endpoint Analysis ClientAI14/7/202615/7/2026
Improper Privilege Management vulnerability in Citrix Secure Access Client for Windows, Citrix Citrix Endpoint Analysis Client for Windows. This issue affects Secure Access Client for Windows: before 26.6.1.20; Citrix Endpoint Analysis Client for Windows: before 26. 5.1.7.
AnalizadaMedia (5.8)0.15%—Paloaltonetworks Prisma Access Agent9/7/202616/7/2026
Multiple protection mechanism failures in the Prisma Access Agent Data Loss Prevention (DLP) component for Windows allow a local user to bypass DLP policy enforcement controls. The Prisma Access Agent on macOS is not affected.
AnalizadaMedia (5.7)0.20%—Paloaltonetworks Prisma Access Agent9/7/202616/7/2026
An improper certificate validation vulnerability in the Prisma® Access Agent for iOS enables an attacker to perform a man-in-the-middle (MitM) attack to intercept VPN traffic. The Prisma Access Agent on Windows, macOS, Linux, Android and ChromeOS are not affected.
AnalizadaMedia (6.9)0.45%—Openvpn Access Server8/7/202629/9/2026
OpenVPN Access Server 2.7.2 through 3.1.0 accepts bare line-feed sequences inside HTTP header values, allowing remote attackers to perform HTTP request smuggling when deployed behind a reverse proxy
AplazadaAlta (7.5)0.45%—Backstage Customizer Demo AccessAI8/7/20268/7/2026
The Backstage - Customizer Demo Access plugin for WordPress is vulnerable to Privilege Escalation in all versions up to, and including, 1.4.2. This is due to the plugin assigning the `manage_options` capability to the `backstage_customizer_user` demo role, which is more permissive than necessary for Customizer-only…
AplazadaAlta (8.2)0.34%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (5.4)0.23%—Armiya Information Technologies Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (6.1)0.25%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (6.1)0.25%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS Targeting HTML Attributes. This issue affects Access Control System (GKS): before Version 2.
AnalizadaAlta (8.8)0.11%—Qualcomm Wsa8835 FirmwareQualcomm 5G Fixed Wireless Access Platform FirmwareQualcomm Ar8035 FirmwareQualcomm Cq7790 Firmware+1246/7/20267/7/2026
Memory Corruption when processing invalid HT40 channel layouts during dynamic channel switching operations.
AnalizadaAlta (8.5)0.53%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support6/7/20267/7/2026
A high-severity vulnerability exists in a web application component of BeyondTrust Remote Support and Privileged Remote Access related to the processing of certain input parameters. Insufficient validation of user-supplied input may allow an authenticated attacker with limited privileges to access unintended resources…
AnalizadaAlta (8.7)0.65%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support6/7/20267/7/2026
BeyondTrust Remote Support and Privileged Remote Access contain a high-severity pre-authentication vulnerability in the network communication subsystem. Insufficient validation of client-supplied input may allow an unauthenticated remote attacker to trigger a denial-of-service condition affecting appliance…
AnalizadaCrítica (9.2)0.75%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support6/7/20267/7/2026
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support. Improper processing of authentication requests may allow an unauthenticated remote attacker to bypass access controls and gain unauthorized access to the appliance, including accounts with elevated…
AnalizadaCrítica (9.2)0.46%—Beyondtrust Privileged Remote AccessBeyondtrust Remote Support6/7/20267/7/2026
A critical pre-authentication vulnerability exists in the authentication subsystem of BeyondTrust Remote Support and Privileged Remote Access. Improper validation of authentication data may allow a network-positioned attacker to bypass access controls and gain unauthorized access to the appliance, including accounts…
AnalizadaAlta (8.6)0.56%—UI Unifi Access2/7/202617/8/2026
A malicious actor with access to the network could exploit a Path Traversal vulnerability found in UniFi Access Application to access files on the host device.
AnalizadaCrítica (9.1)0.52%—UI Unifi Access2/7/202617/8/2026
A malicious actor with access to the network and high privileges could exploit an Improper Access Control vulnerability found in UniFi Access Application to escalate privileges on the host device.
AnalizadaCrítica (9.9)1.6%—UI Unifi Access2/7/202617/8/2026
A malicious actor with access to the network and low privileges could exploit an Improper Input Validation vulnerability found in UniFi Access Application to execute a Command Injection on the host device.
AplazadaMedia (5.9)0.12%—Honeywell IQ MultiaccessAI29/6/202627/9/2026
Honeywell IQ MultiAccess, all versions prior to and including version 28, contain an improper digital signature verification vulnerability. An attacker could potentially exploit this vulnerability, leading to the replacement of downloaded file with a malicious one. Honeywell also recommends updating to the most recent…
AplazadaMedia (6.8)0.17%💥 PoCToshiba Generic IO Memory Access DriverAIDynabook Generic IO Memory Access DriverAI25/6/202625/6/2026
Generic IO & Memory Access driver for PCs provided by TOSHIBA CORPORATION and Dynabook Inc. exposes its IOCTL with insufficient access control. A logged-in user with no administrative privilege may access physical memory.