Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.33%—Ivanti Cloud Services Appliance13/5/202517/6/2026
Default credentials in Ivanti Cloud Services Application before version 5.0.5 allows a local authenticated attacker to escalate their privileges.
AnalizadaAlta (7.2)22%—Ivanti Cloud Services Appliance11/2/202517/6/2026
OS command injection in the admin web console of Ivanti CSA before version 5.0.5 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaMedia (5.3)1.2%—Ivanti Cloud Services Appliance11/2/202517/6/2026
Path traversal in Ivanti CSA before version 5.0.5 allows a remote unauthenticated attacker to access restricted functionality.
AnalizadaAlta (7.2)23%—Ivanti Cloud Services Appliance10/12/202417/6/2026
SQL injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
AnalizadaAlta (7.2)7.7%—Ivanti Cloud Services Appliance10/12/202417/6/2026
Command injection in the admin web console of Ivanti CSA before version 5.0.3 allows a remote authenticated attacker with admin privileges to achieve remote code execution.
AnalizadaCrítica (9.8)4.9%—Ivanti Cloud Services Appliance10/12/202417/6/2026
An authentication bypass in the admin web console of Ivanti CSA before 5.0.3 allows a remote unauthenticated attacker to gain administrative access
AnalizadaAlta (7.2)16%—Ivanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
Path traversal in Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to bypass restrictions.
AnalizadaAlta (7.2)60%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/202417/6/2026
An OS command injection vulnerability in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to obtain remote code execution.
AnalizadaAlta (7.2)44%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/10/20241/10/2026
SQL injection in the admin web console of Ivanti CSA before version 5.0.2 allows a remote authenticated attacker with admin privileges to run arbitrary SQL statements.
AnalizadaCrítica (9.1)99%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance19/9/202417/6/2026
Path Traversal in the Ivanti CSA before 4.6 Patch 519 allows a remote unauthenticated attacker to access restricted functionality.
AnalizadaAlta (7.2)89%⚠ Explotación activaIvanti Cloud Services Appliance10/9/202417/6/2026
An OS command injection vulnerability in Ivanti Cloud Services Appliance versions 4.6 Patch 518 and before allows a remote authenticated attacker to obtain remote code execution. The attacker must have admin level privileges to exploit this vulnerability.
AnalizadaCrítica (9.8)99%⚠ Explotación activaIvanti Endpoint Manager Cloud Services Appliance8/12/20214/8/2026
A code injection vulnerability in the Ivanti EPM Cloud Services Appliance (CSA) allows an unauthenticated user to execute arbitrary code with limited permissions (nobody).