Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2577▼ 295 respecto a la semana anterior
Críticas / altas1354▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

222 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.45%—Ivanti Neurons FOR Secure AccessIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway9/9/202517/6/2026
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure…
AnalizadaMedia (5.4)0.33%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to execute limited actions on behalf of the victim user. User…
AnalizadaAlta (7.6)0.56%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure…
AnalizadaAlta (8.8)0.61%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
CSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to execute sensitive actions on behalf of the victim user.…
AnalizadaMedia (4.9)0.80%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
An unchecked return value in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial…
AnalizadaAlta (8.9)0.65%—Ivanti Neurons FOR Secure AccessIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway9/9/202517/6/2026
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker to hijack existing HTML5 connections.
AnalizadaMedia (5.4)0.56%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure…
AnalizadaMedia (6.1)0.71%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
Reflected text injection in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to inject arbitrary text into a crafted…
AnalizadaAlta (8.8)0.93%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure…
AnalizadaAlta (8.8)0.93%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
Missing authorization in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with read-only admin privileges to configure…
AnalizadaMedia (6.8)0.91%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access9/9/202517/6/2026
SSRF in Ivanti Connect Secure before 22.7R2.9 or 22.8R2, Ivanti Policy Secure before 22.7R1.6, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to enumerate internal services.
AnalizadaMedia (5.5)0.36%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access12/8/202517/6/2026
Improper handling of symbolic links in Ivanti Connect Secure before version 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a local authenticated attacker to read arbitrary files…
AnalizadaMedia (4.9)0.68%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access12/8/202517/6/2026
XEE in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote authenticated attacker with admin privileges to trigger a denial of service
AnalizadaAlta (7.5)1.1%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access12/8/202517/6/2026
A heap-based buffer overflow in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 22.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.
AnalizadaAlta (7.5)1.1%—Ivanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access GatewayIvanti Neurons FOR Secure Access12/8/202517/6/2026
A buffer over-read vulnerability in Ivanti Connect Secure before 22.7R2.8 or 22.8R2, Ivanti Policy Secure before 22.7R1.5, Ivanti ZTA Gateway before 2.8R2.3-723 and Ivanti Neurons for Secure Access before 22.8R1.4 (Fix deployed on 02-Aug-2025) allows a remote unauthenticated attacker to trigger a denial of service.…
AnalizadaMedia (5.5)0.35%—Ivanti Connect Secure8/7/202517/6/2026
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 allows a local authenticated attacker to obtain that information.
AnalizadaBaja (2.7)0.46%—Ivanti Connect SecureIvanti Policy Secure8/7/202517/6/2026
CLRF injection in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to write to a protected configuration file on disk.
AnalizadaMedia (4.9)0.64%—Ivanti Connect SecureIvanti Policy Secure8/7/202517/6/2026
SSRF in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to access internal network services.
AnalizadaMedia (5.5)0.35%—Ivanti Connect SecureIvanti Policy Secure8/7/202517/6/2026
Insertion of sensitive information into a log file in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a local authenticated attacker to obtain that information.
AnalizadaMedia (4.9)0.79%—Ivanti Connect SecureIvanti Policy Secure8/7/202517/6/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated attacker with admin rights to trigger a denial of service.
AnalizadaBaja (2.7)0.30%—Ivanti Connect SecureIvanti Policy Secure8/7/202517/6/2026
Improper access control in the certificate management component of Ivanti Connect Secure before version 22.7R2.8 and Ivanti Policy Secure before version 22.7R1.5 allows a remote authenticated admin with read-only rights to modify settings that should be restricted.
AnalizadaCrítica (9.8)100%⚠ Explotación activaIvanti Connect SecureIvanti Policy SecureIvanti Zero Trust Access Gateway3/4/20254/8/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6, Ivanti Policy Secure before version 22.7R1.4, and Ivanti ZTA Gateways before version 22.8R2.2 allows a remote unauthenticated attacker to achieve remote code execution.
AnalizadaMedia (4.9)1.6%—Ivanti Connect SecureIvanti Policy Secure21/2/202517/6/2026
External control of a file name in Ivanti Connect Secure before version 22.7R2.4 and Ivanti Policy Secure before version 22.7R1.3 allows a remote authenticated attacker with admin privileges to write arbitrary files.
AnalizadaMedia (5.6)0.23%—Cisco Anyconnect Secure Mobility Client12/2/202517/6/2026
A vulnerability in the uninstaller component of Cisco AnyConnect Secure Mobility Client for Mac OS could allow an authenticated, local attacker to corrupt the content of any file in the filesystem. The vulnerability is due to the incorrect handling of directory paths. An attacker could exploit this vulnerability by…
AnalizadaAlta (8.8)4.7%—Ivanti Connect Secure11/2/202517/6/2026
A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.6 allows a remote authenticated attacker to achieve remote code execution.