Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2540▼ 352 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

129 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.2)1.3%—Ivanti Avalanche12/8/202517/6/2026
Incomplete restriction of configuration in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to achieve remote code execution
AnalizadaAlta (7.2)1.1%—Ivanti Avalanche12/8/202517/6/2026
SQL injection in Ivanti Avalanche before version 6.4.8.8008 allows a remote authenticated attacker with admin privileges to execute arbitrary SQL queries. In certain conditions, this can also lead to remote code execution
AnalizadaCrítica (9.8)3.0%—Ivanti Avalanche12/7/202517/6/2026
A security vulnerability within Ivanti Avalanche Manager before version 6.4.1 may allow an unauthenticated attacker to create a buffer overflow that could result in service disruption or arbitrary code execution.
AnalizadaCrítica (9.8)32%—Ivanti Avalanche14/1/202517/6/2026
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication. This CVE addresses incomplete fixes from CVE-2024-47010.
AnalizadaAlta (7.5)28%—Ivanti Avalanche14/1/202517/6/2026
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to leak sensitive information. This CVE addresses incomplete fixes from CVE-2024-47011.
AnalizadaCrítica (9.8)63%—Ivanti Avalanche14/1/202517/6/2026
Path Traversal in Ivanti Avalanche before version 6.4.7 allows a remote unauthenticated attacker to bypass authentication.
AnalizadaAlta (7.5)1.1%—Ivanti Avalanche12/11/202417/6/2026
An out-of-bounds read vulnerability in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to leak sensitive information in memory.
AnalizadaAlta (7.5)1.2%—Ivanti Avalanche12/11/202417/6/2026
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)40%—Ivanti Avalanche12/11/202417/6/2026
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)1.2%—Ivanti Avalanche12/11/202417/6/2026
An infinite loop in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)1.2%—Ivanti Avalanche12/11/202417/6/2026
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)1.2%—Ivanti Avalanche12/11/202417/6/2026
A null pointer dereference in Ivanti Avalanche before 6.4.6 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)56%—Ivanti Avalanche8/10/202417/6/2026
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information
AnalizadaCrítica (9.8)38%—Ivanti Avalanche8/10/202417/6/2026
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
AnalizadaCrítica (9.8)1.7%—Ivanti Avalanche8/10/202417/6/2026
Path Traversal in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to bypass authentication.
AnalizadaAlta (7.5)47%—Ivanti Avalanche8/10/202417/6/2026
Server-side request forgery in Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to leak sensitive information.
AnalizadaAlta (7.5)1.7%—Ivanti Avalanche8/10/202417/6/2026
A NULL pointer dereference in WLAvalancheService.exe of Ivanti Avalanche before version 6.4.5 allows a remote unauthenticated attacker to cause a denial of service.
AnalizadaAlta (7.5)92%—Ivanti Avalanche14/8/202417/6/2026
XXE in SmartDeviceServer in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to read arbitrary files on the server.
AnalizadaCrítica (9.1)7.6%—Ivanti Avalanche14/8/202417/6/2026
Path traversal in the skin management component of Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to achieve denial of service via arbitrary file deletion.
AnalizadaAlta (7.5)28%—Ivanti Avalanche14/8/202417/6/2026
A NULL pointer dereference in WLAvalancheService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
AnalizadaAlta (7.2)1.6%—Ivanti Avalanche14/8/202417/6/2026
Improper input validation in the Central Filestore in Ivanti Avalanche 6.3.1 allows a remote authenticated attacker with admin rights to achieve RCE.
AnalizadaAlta (7.5)2.2%—Ivanti Avalanche14/8/202417/6/2026
An off-by-one error in WLInfoRailService in Ivanti Avalanche 6.3.1 allows a remote unauthenticated attacker to crash the service, resulting in a DoS.
AnalizadaAlta (7.2)64%—Ivanti Avalanche31/5/202417/6/2026
An unrestricted file upload vulnerability in web component of Ivanti Avalanche before 6.4.x allows an authenticated, privileged user to execute arbitrary commands as SYSTEM.
AnalizadaAlta (7.5)2.0%—Ivanti Avalanche25/4/202417/6/2026
An out-of-bounds read vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3, in certain conditions can allow an unauthenticated remote attacker to read sensitive information in memory.
AnalizadaCrítica (9.8)4.3%—Ivanti Avalanche19/4/202417/6/2026
A Heap Overflow vulnerability in WLAvalancheService component of Ivanti Avalanche before 6.4.3 allows a remote unauthenticated attacker to execute arbitrary commands