Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
129 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 1.3% | — | Ivanti Avalanche | 12/8/2025 | 17/6/2026 | Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution | |
| Analizada | Alta (7.2) | 1.1% | — | Ivanti Avalanche | 12/8/2025 | 17/6/2026 | SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution | |
| Analizada | Crítica (9.8) | 3.0% | — | Ivanti Avalanche | 12/7/2025 | 17/6/2026 | A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service disruption or arbitrary code execution. | |
| Analizada | Crítica (9.8) | 32% | — | Ivanti Avalanche | 14/1/2025 | 17/6/2026 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010. | |
| Analizada | Alta (7.5) | 28% | — | Ivanti Avalanche | 14/1/2025 | 17/6/2026 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011. | |
| Analizada | Crítica (9.8) | 63% | — | Ivanti Avalanche | 14/1/2025 | 17/6/2026 | Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. | |
| Analizada | Alta (7.5) | 1.1% | — | Ivanti Avalanche | 12/11/2024 | 17/6/2026 | An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory. | |
| Analizada | Alta (7.5) | 1.2% | — | Ivanti Avalanche | 12/11/2024 | 17/6/2026 | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 40% | — | Ivanti Avalanche | 12/11/2024 | 17/6/2026 | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 1.2% | — | Ivanti Avalanche | 12/11/2024 | 17/6/2026 | An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 1.2% | — | Ivanti Avalanche | 12/11/2024 | 17/6/2026 | A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 1.2% | — | Ivanti Avalanche | 12/11/2024 | 17/6/2026 | A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 56% | — | Ivanti Avalanche | 8/10/2024 | 17/6/2026 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information | |
| Analizada | Crítica (9.8) | 38% | — | Ivanti Avalanche | 8/10/2024 | 17/6/2026 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication. | |
| Analizada | Crítica (9.8) | 1.7% | — | Ivanti Avalanche | 8/10/2024 | 17/6/2026 | Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication. | |
| Analizada | Alta (7.5) | 47% | — | Ivanti Avalanche | 8/10/2024 | 17/6/2026 | Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information. | |
| Analizada | Alta (7.5) | 1.7% | — | Ivanti Avalanche | 8/10/2024 | 17/6/2026 | A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service. | |
| Analizada | Alta (7.5) | 92% | — | Ivanti Avalanche | 14/8/2024 | 17/6/2026 | XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server. | |
| Analizada | Crítica (9.1) | 7.6% | — | Ivanti Avalanche | 14/8/2024 | 17/6/2026 | Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion. | |
| Analizada | Alta (7.5) | 28% | — | Ivanti Avalanche | 14/8/2024 | 17/6/2026 | A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS. | |
| Analizada | Alta (7.2) | 1.6% | — | Ivanti Avalanche | 14/8/2024 | 17/6/2026 | Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE. | |
| Analizada | Alta (7.5) | 2.2% | — | Ivanti Avalanche | 14/8/2024 | 17/6/2026 | An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS. | |
| Analizada | Alta (7.2) | 64% | — | Ivanti Avalanche | 31/5/2024 | 17/6/2026 | An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM. | |
| Analizada | Alta (7.5) | 2.0% | — | Ivanti Avalanche | 25/4/2024 | 17/6/2026 | An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory. | |
| Analizada | Crítica (9.8) | 4.3% | — | Ivanti Avalanche | 19/4/2024 | 17/6/2026 | A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands |