Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
1567 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 0.42% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAI | 14/8/2025 | 17/6/2026 | A vulnerability in the certificate processing of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to cause the device to reload unexpectedly, resulting in a denial of service (DoS) condition. This… | |
| Analizada | Alta (7.7) | 0.66% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 14/8/2025 | 11/8/2026 | A vulnerability in the TLS 1.3 implementation for a specific cipher for Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Firepower 3100 and 4200 Series devices could allow an authenticated, remote attacker to consume resources that are… | |
| Analizada | Media (5.8) | 0.71% | — | Cisco Secure Firewall Threat DefenseCisco Adaptive Security Appliance Software | 14/8/2025 | 18/9/2026 | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Secure Firewall Threat Defense (FTD) Software could allow an unauthenticated, remote attacker to trigger a memory leak, resulting in a denial of service (DoS) condition. This… | |
| Aplazada | Crítica (9.3) | 4.2% | 💥 Exploit | Proofpoint Email Security Virtual ApplianceAI | 8/8/2025 | 16/6/2026 | The E-Mail Security Virtual Appliance (ESVA) (tested on version ESVA_2057) contains an unauthenticated command injection vulnerability in the learn-msg.cgi script. The CGI handler fails to sanitize user-supplied input passed via the id parameter, allowing attackers to inject arbitrary shell commands. Exploitation… | |
| Aplazada | Crítica (9.3) | 1.5% | 💥 Exploit | Dell Kace K1000 System Management ApplianceAI | 5/8/2025 | 17/6/2026 | An unrestricted file upload vulnerability exists in Dell (acquired by Quest) KACE K1000 System Management Appliance version 5.0 - 5.3, 5.4 prior to 5.4.76849, and 5.5 prior to 5.5.90547 in the download_agent.php endpoint. An attacker can upload arbitrary PHP files to a temporary web-accessible directory, which are… | |
| Aplazada | Alta (8.7) | 0.39% | — | Avid NexisAIAvid Nexis AgentAIAvid System Director ApplianceAIGenivia GsoapAI | 14/7/2025 | 17/6/2026 | The Avid Nexis Agent uses a vulnerable gSOAP version. An undocumented vulnerability impacting gSOAP v2.8 makes the application vulnerable to an Unauthenticated Path Traversal vulnerability. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1;… | |
| Aplazada | Alta (7.1) | 0.40% | — | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 14/7/2025 | 17/6/2026 | An authenticated Arbitrary File Deletion vulnerability enables an attacker to delete critical files. This issue affects Avid NEXIS E-series: before 2025.5.1; Avid NEXIS F-series: before 2025.5.1; Avid NEXIS PRO+: before 2025.5.1; System Director Appliance (SDA+): before 2025.5.1. | |
| Aplazada | Alta (8.7) | 1.1% | 💥 Exploit | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 14/7/2025 | 17/6/2026 | An Unauthenticated Arbitrary File Read vulnerability affects the Agent when installed on a system. The parameter filename does not validate the path thus allowing users to read arbitrary files. As the application runs with the highest privileges (root/NT_AUTHORITY SYSTEM) by default attackers are able to obtain… | |
| Analizada | Alta (7.5) | 0.35% | — | IBM MQ Appliance | 11/7/2025 | 17/6/2026 | An IBM MQ 9.3 and 9.4 Client connecting to an MQ Queue Manager can cause a SIGSEGV in the AMQRMPPA channel process terminating it. | |
| Aplazada | Crítica (9.3) | 0.18% | — | Quest Kace Systems Management ApplianceAI | 5/7/2025 | 17/6/2026 | The agent in Quest KACE Systems Management Appliance (SMA) before 14.0.97 and 14.1.x before 14.1.19 potentially allows privilege escalation on managed systems. | |
| Analizada | Alta (7.2) | 0.65% | — | Dell Solutions Enabler Virtual ApplianceDell Unisphere FOR Powermax Virtual Appliance | 27/6/2025 | 17/6/2026 | Dell Unisphere for PowerMax vApp, version(s) 9.2.4.x, contain(s) an Improper Neutralization of Directives in Statically Saved Code ('Static Code Injection') vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability, leading to Code execution. | |
| Aplazada | Alta (7.5) | 0.91% | — | Quest Kace Systems Management ApplianceAI | 24/6/2025 | 17/6/2026 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to replace system licenses through a web interface intended for license renewal. Attackers can exploit… | |
| Aplazada | Crítica (9.6) | 0.41% | — | Quest Kace Systems Management ApplianceAI | 24/6/2025 | 17/6/2026 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) allows unauthenticated users to upload backup files to the system. While signature validation is implemented, weaknesses in the… | |
| Aplazada | Alta (8.8) | 0.84% | — | Quest Kace Systems Management ApplianceAI | 24/6/2025 | 17/6/2026 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains a logic flaw in its two-factor authentication implementation that allows authenticated users to bypass TOTP-based 2FA… | |
| Analizada | Crítica (10) | 2.5% | ⚠ Explotación activa | Quest Kace Systems Management Appliance | 24/6/2025 | 17/6/2026 | Quest KACE Systems Management Appliance (SMA) 13.0.x before 13.0.385, 13.1.x before 13.1.81, 13.2.x before 13.2.183, 14.0.x before 14.0.341 (Patch 5), and 14.1.x before 14.1.101 (Patch 4) contains an authentication bypass vulnerability that allows attackers to impersonate legitimate users without valid credentials.… | |
| Analizada | Alta (7.8) | 0.33% | — | Ivanti Cloud Services Appliance | 13/5/2025 | 17/6/2026 | Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Alta (8.6) | 0.56% | — | Cisco Adaptive Security Appliance SoftwareCisco Secure Firewall Threat Defense | 7/5/2025 | 11/8/2026 | A vulnerability in the Internet Key Exchange version 2 (IKEv2) protocol processing of Cisco Adaptive Security Appliance (ASA) Software, Cisco Firepower Threat Defense (FTD) Software, Cisco IOS Software, and Cisco IOS XE Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS)… | |
| Aplazada | Alta (8.7) | 0.52% | — | Avid Nexis E-seriesAIAvid Nexis F-seriesAIAvid Nexis Pro+AIAvid System Director ApplianceAI | 12/3/2025 | 17/6/2026 | Improper Input Validation vulnerability in Avid Avid NEXIS E-series on Linux, Avid Avid NEXIS F-series on Linux, Avid Avid NEXIS PRO+ on Linux, Avid System Director Appliance (SDA+) on Linux allows code execution on underlying operating system with root permissions.This issue affects Avid NEXIS E-series: before… | |
| Modificada | Alta (7.5) | 0.38% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Configuration File Contains CA & Private Key V-2022-001. | |
| Modificada | Alta (7.5) | 0.59% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Debug Bundle Contains Sensitive Data V-2022-003. | |
| Modificada | Alta (8.8) | 0.73% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Driver Unrestricted Upload of File with Dangerous Type V-2022-006. | |
| Modificada | Crítica (9.8) | 0.70% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 allows Insecure Log Permissions V-2022-005. | |
| Modificada | Crítica (9.8) | 0.76% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.735 Application 20.0.1330 mishandles Client Inter-process Security V-2022-004. | |
| Modificada | Crítica (9.1) | 0.32% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 1.0.750 Application 20.0.1442 allows Insecure Firmware Image with Insufficient Verification of Data Authenticity V-2024-004. | |
| Modificada | Media (6.1) | 0.40% | — | Printerlogic Vasion PrintPrinterlogic Virtual Appliance | 5/3/2025 | 17/6/2026 | Vasion Print (formerly PrinterLogic) before Virtual Appliance Host 22.0.843 Application 20.0.1923 allows Cross-Site Scripting in Badge Registration V-2023-005. |