Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
703 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 0.74% | — | Theeventscalendar Events Calendar PRO | 30/8/2024 | 17/6/2026 | The Events Calendar Pro plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 7.0.2 via deserialization of untrusted input from the 'filters' parameter in widgets. This makes it possible for authenticated attackers, with administrator-level access and above, to inject a PHP… | |
| Analizada | Crítica (9.8) | 0.75% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | An Improper Input Validation vulnerability in Zscaler Client Connector on MacOS allows OS Command Injection. This issue affects Zscaler Client Connector on MacOS <4.2. | |
| Analizada | Media (4.9) | 0.43% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | In certain cases, Zscaler Internet Access (ZIA) can be disabled by PowerShell commands with admin rights. This affects Zscaler Client Connector on Windows <4.2.1 | |
| Analizada | Alta (7.8) | 0.13% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | The Zscaler Updater process does not validate the digital signature of the installer before execution, allowing arbitrary code to be locally executed. This affects Zscaler Client Connector on MacOS <4.2. | |
| Analizada | Alta (7.8) | 0.11% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | While copying individual autoupdater log files, reparse point check was missing which could result into crafted attacks, potentially leading to a local privilege escalation. This issue affects Zscaler Client Connector on Windows <4.2.0.190. | |
| Analizada | Alta (7.5) | 0.23% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | Anti-tampering can be disabled under certain conditions without signature validation. This affects Zscaler Client Connector <4.2.0.190 with anti-tampering enabled. | |
| Analizada | Media (6.5) | 0.19% | — | Zscaler Client Connector | 6/8/2024 | 17/6/2026 | An Improper Validation of signature in Zscaler Client Connector on Windows allows an authenticated user to disable anti-tampering. This issue affects Client Connector on Windows <4.2.0.190. | |
| Analizada | Alta (7.1) | 0.74% | — | Citrix Netscaler AgentCitrix Netscaler ConsoleCitrix Netscaler SDX | 10/7/2024 | 17/6/2026 | Denial of Service in NetScaler Console (formerly NetScaler ADM), NetScaler Agent, and NetScaler SDX | |
| Analizada | Crítica (9.4) | 21% | 💥 Exploit | Citrix Netscaler Console | 10/7/2024 | 17/6/2026 | Sensitive information disclosure in NetScaler Console | |
| Analizada | Media (5.1) | 0.55% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Open redirect vulnerability allows a remote unauthenticated attacker to redirect users to arbitrary websites in NetScaler ADC and NetScaler Gateway | |
| Analizada | Alta (7.2) | 0.76% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 10/7/2024 | 17/6/2026 | Denial of Service in NetScaler ADC and NetScaler Gateway in NetScaler | |
| Modificada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability to gain root-level access. | |
| Modificada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access. | |
| Modificada | Media (6.7) | 0.15% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an incorrect privilege assignment vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Denial of service and Elevation of privileges. | |
| Modificada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to unauthorized gain of root-level access. | |
| Modificada | Media (6.7) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.8.0.0 contain an improper privilege management vulnerability. A local high privilege attacker could potentially exploit this vulnerability, leading to privilege escalation. | |
| Modificada | Alta (7.8) | 0.16% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.2 contain an execution with unnecessary privileges vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Modificada | Alta (7.5) | 0.21% | — | Dell Powerscale Onefs | 2/7/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.2.x through 9.7.0.0 contain use of a broken or risky cryptographic algorithm vulnerability. An unprivileged network malicious attacker could potentially exploit this vulnerability, leading to data leaks. | |
| Analizada | Alta (8.1) | 0.26% | — | Dell Powerscale Onefs | 4/6/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.8.0.x contain a use of hard coded credentials vulnerability. An adjacent network unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure of network traffic and denial of service. | |
| Aplazada | Media (6.5) | 0.48% | — | Theeventscalendar BookitAI | 17/5/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in The Events Calendar BookIt allows Manipulating Hidden Fields.This issue affects BookIt: from n/a through 2.4.0. | |
| Analizada | Media (6.5) | 0.68% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an improper input validation vulnerability. A low privileged remote attacker could potentially exploit this vulnerability, leading to loss of integrity. | |
| Analizada | Media (5.5) | 0.21% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an allocation of resources without limits or throttling vulnerability. A local unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. | |
| Analizada | Alta (7.5) | 0.44% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains a use of a broken or risky cryptographic algorithm vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to information disclosure. | |
| Analizada | Media (6.7) | 0.26% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.1 contains an execution with unnecessary privileges vulnerability. A local high privileged attacker could potentially exploit this vulnerability, leading to escalation of privileges. | |
| Analizada | Alta (7.5) | 0.92% | — | Dell Powerscale Onefs | 14/5/2024 | 17/6/2026 | Dell PowerScale OneFS versions 8.2.x through 9.7.0.2 contains an improper handling of unexpected data type vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability, leading to denial of service. |