Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

1881 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.6)1.1%⚠ Explotación activa💥 PoCTanstack/arktype-adapterTanstack/eslint-plugin-routerTanstack/eslint-plugin-startTanstack/history+16712/5/202617/6/2026
On 2026-05-11, between approximately 19:20 and 19:26 UTC, 84 malicious versions across 42 @tanstack/* packages were published to the npm registry. The publishes were authenticated via the legitimate GitHub Actions OIDC trusted-publisher binding for TanStack/router, but the publish workflow itself was not modified. The…
AplazadaAlta (7.5)0.41%—Meari Client ApplicationsAIMeari CloudedgeAIMeari ArentiAI11/5/202617/6/2026
In Meari client applications embedding "com.meari.sdk" (including CloudEdge 5.5.0 build 220, Arenti 1.8.1 build 220, and related white-label <= 1.8.x), the integrated call path to openapi-euce.mearicloud.com can be abused to retrieve WAN IP data for arbitrary devices. The root cause is a server-side authorization…
AplazadaAlta (7.5)0.64%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a directory traversal allowing attackers to read arbitrary files via crafted url.
AplazadaMedia (6.1)0.24%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a reflected cross site scripting attack via the login page of the application.
AplazadaMedia (6.3)0.27%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to arbitrary file upload via pmupdate.php.
AplazadaMedia (5.4)0.22%—Docuform Managed Print Service ClientAI11/5/202617/6/2026
docuFORM Managed Print Service Client 11.11c is vulnerable to a session fixation attack via the login page of the application.
AplazadaAlta (7.4)0.44%—Akamai Guardicore Platform AgentAIAkamai Zero Trust ClientAI8/5/202617/6/2026
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs()…
Pendiente de análisisMedia (6.8)0.15%—Netskope ClientAI29/4/202617/6/2026
Netskope was notified about a potential gap in the Endpoint DLP Module for Netskope Client on Windows systems. The successful exploitation of the gap can potentially allow an unprivileged user to trigger an out-of-bounds read within a driver, leading to a Blue-Screen-of-Death (BSOD). Successful exploitation would…
ModificadaAlta (7.3)0.70%—Apache Httpclient22/4/20269/9/2026
Missing critical step in authentication in Apache HttpClient 5.6 allows an attacker to cause the client to accept SCRAM-SHA-256 authentication without proper mutual authentication verification. Users are recommended to upgrade to version 5.6.1, which fixes this issue.
AnalizadaMedia (5.7)0.17%—Canonical Livepatch Client20/4/202617/6/2026
An improper access control vulnerability in the canonical-livepatch snap client prior to version 10.15.0 allows a local unprivileged user to obtain a sensitive, root-level authentication token by sending an unauthenticated request to the livepatchd.sock Unix domain socket. This vulnerability is exploitable on systems…
AnalizadaAlta (8.5)0.15%—Skygroup Skymec IT ManagerSkygroup Skysea Client View20/4/202617/6/2026
SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the…
AplazadaMedia (6.8)0.48%—AsynchttpclientAI18/4/202617/6/2026
The AsyncHttpClient (AHC) library allows Java applications to easily execute HTTP requests and asynchronously process HTTP responses. When redirect following is enabled (followRedirect(true)), versions of AsyncHttpClient prior to 3.0.9 and 2.14.5 forward Authorization and Proxy-Authorization headers along with Realm…
AnalizadaAlta (7.5)0.53%—Freedom Securedrop-client18/4/202617/6/2026
SecureDrop Client is a desktop app for journalists to securely communicate with sources and handle submissions on the SecureDrop Workstation. In versions 0.17.4 and below, a compromised SecureDrop Server can achieve code execution on the Client's virtual machine (sd-app) by exploiting improper filename validation in…
Pendiente de análisisMedia (5.1)0.18%—Dell Client Platform BiosAI16/4/202617/6/2026
Dell Client Platform BIOS contains a Weak Password Recovery Mechanism vulnerability. An unauthenticated attacker with physical access to the system could potentially exploit this vulnerability, leading to unauthorized access.
AnalizadaAlta (8.8)0.82%—Microsoft Remote Desktop ClientMicrosoft Windows 10 1607Microsoft Windows 10 1809Microsoft Windows 10 21h2+1114/4/202625/9/2026
Use after free in Remote Desktop Client allows an unauthorized attacker to execute code over a network.
AnalizadaMedia (5.5)0.15%—Fortinet Forticlientems14/4/202617/6/2026
A use of hard-coded cryptographic key vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5 may allow attacker to information disclosure via decrypting database dump.
AnalizadaMedia (6.7)0.20%—Fortinet Forticlientems14/4/202617/6/2026
A improper neutralization of special elements used in an sql command ('sql injection') vulnerability in Fortinet FortiClientEMS 7.4.0 through 7.4.5, FortiClientEMS 7.2.0 through 7.2.12, FortiClientEMS 7.0 all versions may allow attacker to execute unauthorized code or commands via sending crafted requests
AnalizadaAlta (8.1)0.32%—Synology SSL VPN Client10/4/202617/6/2026
A plaintext storage of a password vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access or influence the user's PIN code due to insecure storage. This may lead to unauthorized VPN configuration and potential interception of subsequent VPN traffic when combined with user…
AnalizadaMedia (6.5)0.19%—Synology SSL VPN Client10/4/202617/6/2026
A files or directories accessible to external parties vulnerability in Synology SSL VPN Client before 1.4.5-0684 allows remote attackers to access files within the installation directory via a local HTTP server bound to the loopback interface. By leveraging user interaction with a crafted web page, attackers may…
AplazadaCrítica (9.8)1.1%💥 PoCProsolution WP ClientAI8/4/202625/7/2026
The ProSolution WP Client plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the 'proSol_fileUploadProcess' function in all versions up to, and including, 1.9.9. This makes it possible for unauthenticated attackers to upload arbitrary files on the affected site's server…
AnalizadaAlta (7.5)0.21%—Trailofbits Rfc3161-client8/4/202624/7/2026
rfc3161-client is a Python library implementing the Time-Stamp Protocol (TSP) described in RFC 3161. Prior to 1.0.6, an Authorization Bypass vulnerability in rfc3161-client's signature verification allows any attacker to impersonate a trusted TimeStamping Authority (TSA). By exploiting a logic flaw in how the library…
AplazadaMedia (5.3)0.29%—Boldgrid Client Invoicing BY Sprout InvoicesAI8/4/202624/7/2026
Missing Authorization vulnerability in BoldGrid Client Invoicing by Sprout Invoices sprout-invoices allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Client Invoicing by Sprout Invoices: from n/a through <= 20.8.10.
AnalizadaMedia (5.5)0.14%—Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+17/4/202617/6/2026
Buffer Overflow Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -…
AnalizadaCrítica (9.8)0.61%—Hitachi JOB Management Partner 1/it Desktop Management-managerHitachi Jp1/it Desktop Management 2-managerHitachi Jp1/it Desktop Management 2-operations DirectorHitachi Jp1/netm/dm Manager+17/4/202617/6/2026
Remote Code Execution Vulnerability in JP1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management 2 - Operations Director on Windows, Job Management Partner 1/IT Desktop Management 2 - Manager on Windows, JP1/IT Desktop Management - Manager on Windows, Job Management Partner 1/IT Desktop Management -…
AnalizadaMedia (6.9)0.17%—Filezilla-project Filezilla Client5/4/202624/7/2026
FileZilla 3.40.0 contains a denial of service vulnerability in the local search functionality that allows local attackers to crash the application by supplying a malformed path string. Attackers can trigger the crash by entering a crafted path containing 384 'A' characters followed by 'BBBB' and 'CCCC' sequences in…