Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2767▼ 5 respecto a la semana anterior
Críticas / altas1280▼ 248 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)240▲ 207 respecto a la semana anterior
1611 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.30% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing Channel | 12/5/2026 | 17/6/2026 | Use after free in Microsoft Office allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Crítica (9.9) | 0.85% | — | TermixAI | 8/5/2026 | 24/7/2026 | Termix es una plataforma de gestión de servidores basada en web con capacidades de terminal SSH, tunelización y edición de archivos. Antes de la versión 2.1.0, todos los puntos finales de gestión de contenedores Docker en Termix interpolan el parámetro de ruta URL containerId y el campo de mensaje WebSocket… | |
| Aplazada | Alta (8.7) | 1.6% | — | TermixAI | 8/5/2026 | 25/7/2026 | Termix es una plataforma de gestión de servidores basada en web con capacidades de terminal SSH, tunelización y edición de archivos. Antes de la versión 2.1.0, los endpoints extractArchive y compressFiles en file-manager.ts utilizan cadenas de caracteres entre comillas dobles para la construcción de comandos de shell,… | |
| Aplazada | Alta (8.1) | 0.40% | — | TermixAI | 8/5/2026 | 25/7/2026 | Termix es una plataforma de gestión de servidores basada en web con capacidades de terminal SSH, tunelización y edición de archivos. Antes de la versión 2.1.0, /users/login emite un JWT temporal (temp_token) para cuentas con TOTP habilitado. Ese token lleva un estado pendingTOTP y solo debería ser válido para el flujo… | |
| Analizada | Alta (8.7) | 0.34% | — | Smartertools Smartermail | 8/5/2026 | 17/6/2026 | SmarterTools SmarterMail builds prior to 9560 contain a local file inclusion vulnerability in the /api/v1/report/summary/{type} API endpoint that allows authenticated users to read arbitrary .json files on the system. Attackers can exploit this vulnerability combined with weak encryption algorithms and hardcoded keys… | |
| Modificada | Crítica (9.4) | 0.65% | — | Electerm Project Electerm | 8/5/2026 | 17/6/2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. From versions 3.0.6 to before 3.8.15, electerm is vulnerable to arbitrary local code execution via deep links, CLI --opts, or crafted shortcuts. Exploit requires clicking a crafted electerm://... link or opening a crafted… | |
| Analizada | Alta (7.8) | 0.24% | — | Electerm Project Electerm | 8/5/2026 | 17/6/2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.9, a code execution (RCE) vulnerability exists in electerm's SFTP open with system editor or "Edit with custom editor" feature. When a user opts to edit a file using open with system editor or open with a… | |
| Analizada | Media (5.5) | 0.11% | — | Electerm Project Electerm | 8/5/2026 | 17/6/2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, the getConstants() IPC handler in src/app/lib/ipc-sync.js serialises the entire process.env object and sends it to the renderer. The data is stored as window.pre.env and is accessible from any… | |
| Analizada | Crítica (9.6) | 0.51% | — | Electerm Project Electerm | 8/5/2026 | 17/6/2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. In versions 3.8.15 and prior, Electerm's terminal hyperlink handler passes any URL clicked in the terminal directly to shell.openExternal without any protocol validation. An attacker who controls terminal output (e.g., via a… | |
| Analizada | Alta (8.4) | 0.22% | — | Electerm Project Electerm | 8/5/2026 | 17/6/2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.7.16, the runWidget function in src/app/widgets/load-widget.js constructs a file path by directly concatenating user‑supplied widget identifiers without any sanitisation. Because runWidget is exposed to the… | |
| Analizada | Crítica (9.8) | 2.5% | — | Electerm Project Electerm | 8/5/2026 | 17/6/2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:130. The runLinux() function appends attacker-controlled remote version strings directly into an exec("rm -rf ...")… | |
| Analizada | Crítica (9.8) | 2.5% | — | Electerm Project Electerm | 8/5/2026 | 17/6/2026 | electerm is an open-sourced terminal/ssh/sftp/telnet/serialport/RDP/VNC/Spice/ftp client. Prior to version 3.3.8, a command injection vulnerability exists in github.com/elcterm/electerm/npm/install.js:150. The runMac() function appends attacker-controlled remote releaseInfo.name directly into an exec("open ...")… | |
| Analizada | Alta (8.2) | 0.26% | — | Smartertools Smartermail | 27/4/2026 | 17/6/2026 | SmarterTools SmarterMail builds prior to 9610 contain a cryptographic weakness in the file and email sharing endpoints that use DES-CBC encryption with keys and initialization vectors derived from System.Random seeded with insufficient entropy, reducing the seed space to approximately 19,000 possible values. An… | |
| Analizada | Alta (8.6) | 0.19% | — | Lizardsystems Terminal Services Manager | 22/4/2026 | 17/6/2026 | Terminal Services Manager 3.1 contains a stack-based buffer overflow vulnerability in the computer names field that allows local attackers to execute arbitrary code by triggering structured exception handling. Attackers can craft a malicious input file with shellcode and jump instructions that overwrite the SEH… | |
| Analizada | Alta (7.8) | 0.20% | — | Iterm2 | 18/4/2026 | 17/6/2026 | In iTerm2 through 3.6.9, displaying a .txt file can cause code execution via DCS 2000p and OSC 135 data, if the working directory contains a malicious file whose name is valid output from the conductor encoding path, such as a pathname with an initial ace/c+ substring, aka "hypothetical in-band signaling abuse." This… | |
| Aplazada | Media (6.4) | 0.16% | 💥 PoC | Mobatek Mobaxterm Home EditionAI | 17/4/2026 | 17/6/2026 | A vulnerability has been found in Mobatek MobaXterm Home Edition up to 26.1. This affects an unknown part in the library msimg32.dll. The manipulation leads to uncontrolled search path. An attack has to be approached locally. The attack is considered to have high complexity. It is indicated that the exploitability is… | |
| Analizada | Media (6.5) | 0.22% | — | Mattermost Server | 15/4/2026 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to enforce atomic single-use consumption of guest magic link tokens, which allows an attacker with access to a valid magic link to establish multiple independent authenticated sessions via concurrent requests..… | |
| Analizada | Alta (8.1) | 0.18% | — | Mattermost Server | 15/4/2026 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.12, 11.5.x <= 11.5.0, 11.4.x <= 11.4.2, 11.3.x <= 11.3.2 fail to validate CSRF tokens on an authentication endpoint which allows an attacker to update a user's authentication method via a CSRF attack by tricking a user into visiting a malicious page. Mattermost Advisory ID:… | |
| Analizada | Baja (2.7) | 0.27% | — | Mattermost Server | 15/4/2026 | 17/6/2026 | Mattermost versions 10.11.x <= 10.11.12 fail to validate whether users were correctly owned by the correct Connected Workspace which allows a malicious remote server connected using the Conntexted Workspaces feature to change the displayed status of local users via the Connected Workspaces API.. Mattermost Advisory… | |
| Analizada | Media (6.1) | 0.46% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/4/2026 | 24/7/2026 | Lectura fuera de límites en Microsoft Office Word permite a un atacante no autorizado divulgar información localmente. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/4/2026 | 24/7/2026 | Uso después de liberar en Microsoft Office Word permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (8.4) | 0.36% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/4/2026 | 24/7/2026 | Desreferencia de puntero no confiable en Microsoft Office Word permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft Office Long Term Servicing Channel | 14/4/2026 | 24/7/2026 | Uso después de liberación en Microsoft Office Word permite a un atacante no autorizado ejecutar código localmente. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft OfficeMicrosoft Office Long Term Servicing ChannelMicrosoft Powerpoint | 14/4/2026 | 17/6/2026 | Use after free in Microsoft Office PowerPoint allows an unauthorized attacker to execute code locally. | |
| Analizada | Alta (7.8) | 0.47% | — | Microsoft 365 AppsMicrosoft ExcelMicrosoft OfficeMicrosoft Office Long Term Servicing Channel+1 | 14/4/2026 | 17/6/2026 | Un uso después de liberar (use-after-free) en Microsoft Office Excel permite a un atacante no autorizado ejecutar código localmente. |