Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.4)0.44%—Akamai Guardicore Platform AgentAIAkamai Zero Trust ClientAI8/5/202617/6/2026
Akamai Guardicore Platform Agent (GPA) and Zero Trust Client on Linux and macOS allow TOCTOU-based local privilege escalation. The GPA service creates an IPC socket in the world-writable /tmp directory. It accepts unauthenticated IPC control messages. This enables a TOCTOU vulnerability in the HandleSaveLogs()…
AplazadaMedia (4)0.27%—Akamai GhostAIAkamai CDNAI23/2/202617/6/2026
Akamai Ghost on Akamai CDN edge servers before 2026-02-06 mishandles processing of custom hop-by-hop HTTP headers, where an incoming request containing the header "Connection: Transfer-Encoding" could result in a forward request with invalid message framing, depending on the Akamai processing path. This could result…
AnalizadaMedia (4.8)0.26%—Akamaighost4/12/202517/6/2026
Akamai Ghost on Akamai CDN edge servers before 2025-11-17 has a chunked request body processing error that can result in HTTP request smuggling. When Akamai Ghost receives an invalid chunked body that includes a chunk size different from the actual size of the following chunk data, under certain circumstances, Akamai…
AplazadaAlta (7.8)0.15%—Akamai Guardicore Platform AgentAIOpensslAI3/12/202517/6/2026
The GC-AGENTS-SERVICE running as part of Akamai´s Guardicore Platform Agent for Windows versions prior to v49.20.1, v50.15.0, v51.12.0, v52.2.0 is affected by a local privilege escalation vulnerability. The service will attempt to read an OpenSSL configuration file from a non-existent location that standard Windows…
AplazadaMedia (4)0.27%—Akamai GhostAI29/8/202517/6/2026
Akamai Ghost before 2025-07-21 allows HTTP Request Smuggling via an OPTIONS request that has an entity body, because there can be a subsequent request within the persistent connection between an Akamai proxy server and an origin server, if the origin server violates certain Internet standards.
AplazadaMedia (4)0.56%—Akamai GhostAIAkamai CDNAI7/8/202517/6/2026
An issue was discovered in Akamai Ghost, as used for the Akamai CDN platform before 2025-03-26. Under certain circumstances, a client making an HTTP/1.x OPTIONS request with an "Expect: 100-continue" header, and using obsolete line folding, can lead to a discrepancy in how two in-path Akamai servers interpret the…
AplazadaBaja (3.7)0.33%—Akamai Rate ControlAI25/7/202517/6/2026
Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separately for each edge node.
AplazadaMedia (5.8)0.34%—Akamai CloudtestAI30/6/202517/6/2026
Akamai CloudTest before 60 2025.06.09 (12989) allows SSRF.
AplazadaMedia (5.8)2.1%—Akamai CloudtestAI30/6/202517/6/2026
Akamai CloudTest before 60 2025.06.02 (12988) allows file inclusion via XML External Entity (XXE) injection.
AplazadaMedia (5.4)0.23%—Akamai APP & API ProtectorAIAkamai ASEAI17/3/202517/6/2026
Rule 3000216 (before version 2) in Akamai App & API Protector (with Akamai ASE) before 2024-12-10 does not properly consider JavaScript variable assignment to built-in functions and properties.
AplazadaAlta (8)0.35%—Akamai Enterprise Application AccessAI29/1/202517/6/2026
An issue was discovered in Akamai Enterprise Application Access (EAA) before 2025-01-17. If an admin knows another tenant's 128-bit connector GUID, they can execute debug commands on that connector.
ModificadaAlta (7.1)0.31%—Akamai Secure Internet Access Enterprise Threatavert4/11/202417/6/2026
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can…
ModificadaAlta (7.8)0.44%—Akamai Enterprise Application Access4/10/202117/6/2026
In Akamai EAA (Enterprise Application Access) Client before 2.3.1, 2.4.x before 2.4.1, and 2.5.x before 2.5.3, an unquoted path may allow an attacker to hijack the flow of execution.
ModificadaCrítica (9.8)2.3%—Akamai Enterprise Application Access26/8/202017/6/2026
Enterprise Access Client Auto-Updater allows for Remote Code Execution prior to version 2.0.1.
ModificadaCrítica (9.8)2.6%—Akamai Cloudtest21/6/201917/6/2026
Akamai CloudTest before 58.30 allows remote code execution.
ModificadaCrítica (9.8)2.3%—Akamai Netsession23/1/201717/6/2026
Akamai NetSession 1.9.3.1 is vulnerable to DLL Hijacking: it tries to load CSUNSAPI.dll without supplying the complete path. The issue is aggravated because the mentioned DLL is missing from the installation, thus making it possible to hijack the DLL and subsequently inject code within the Akamai NetSession process…
ModificadaAlta (9.3)3.3%—Akamai Technologies Download Manager23/7/200916/6/2026
Stack-based buffer overflow in manager.exe in Akamai Download Manager (aka DLM or dlmanager) before 2.2.4.8 allows remote web servers to execute arbitrary code via a malformed HTTP response during a Redswoosh download, a different vulnerability than CVE-2007-1891 and CVE-2007-1892.
ModificadaAlta (7.1)0.77%—Akamai Technologies ClientRED Swoosh Client9/6/200816/6/2026
The management interface in Akamai Client (formerly Red Swoosh) 3322 and earlier allows remote attackers to bypass authentication via an HTTP request that contains (1) no Referer header, or (2) a spoofed Referer header that matches an approved domain, which allows remote attackers to conduct cross-site request forgery…
ModificadaAlta (9.3)10%—Akamai Download Manager4/6/200816/6/2026
CRLF injection vulnerability in Akamai Download Manager ActiveX control before 2.2.3.6 allows remote attackers to force the download and execution of arbitrary files via a URL parameter containing an encoded LF followed by a malicious target line.
ModificadaMedia (6.8)11%—Akamai Technologies Download Manager1/5/200816/6/2026
The Akamai Download Manager (aka DLM or dlmanager) ActiveX control (DownloadManagerV2.ocx) before 2.2.3.5 allows remote attackers to force the download and execution of arbitrary code via unspecified "undocumented object parameters."
ModificadaAlta (9.3)5.6%—Akamai Technologies Download Manager18/4/200716/6/2026
Stack-based buffer overflow in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) before 2.2.1.0 allows remote attackers to execute arbitrary code via unspecified vectors, a different issue than CVE-2007-1891.
ModificadaAlta (9.3)6.8%—Akamai Technologies Download Manager18/4/200716/6/2026
Stack-based buffer overflow in the GetPrivateProfileSectionW function in Akamai Technologies Download Manager ActiveX Control (DownloadManagerV2.ocx) after 2.0.4.4 but before 2.2.1.0 allows remote attackers to execute arbitrary code, related to misinterpretation of the nSize parameter as a byte count instead of a wide…