Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2622▼ 226 respecto a la semana anterior
Críticas / altas1383▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
804 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.9) | 0.44% | — | Steeltoe.management.endpointAI | 17/9/2026 | 23/9/2026 | Steeltoe is an open source project that provides a collection of libraries that helps users build cloud-native applications. Prior to 4.3.0, the Steeltoe.Management.Endpoint /actuator/httpexchanges endpoint passes recorded request URIs through MaskedUri, which masks URI user information but does not inspect query… | |
| Aplazada | Alta (8.8) | 0.51% | — | BE Rest EndpointsAI | 12/9/2026 | 14/9/2026 | The BE REST Endpoints WordPress plugin through 1.0.0 does not perform any authorization check before allowing widgets to be read, created, updated and deleted, and does not sanitize the values it stores in them, allowing unauthenticated users to inject arbitrary web scripts which will execute in the browser of any… | |
| Pendiente de análisis | Alta (8.7) | 0.13% | — | Netskope Endpoint DLPAI | 10/9/2026 | 18/9/2026 | Netskope was notified about a potential gap in Netskope Endpoint DLP (EPDLP) running on Windows systems. Successful exploitation of the gap could potentially allow a privileged user to send a crafted message to the EPDLP process port to trigger an integer overflow, leading to memory corruption. Successful exploitation… | |
| Pendiente de análisis | Media (6) | 0.11% | — | Netskope ClientAINetskope Endpoint DLPAI | 10/9/2026 | 18/9/2026 | Netskope was notified of an out-of-bounds heap read affecting the Endpoint DLP (EPDLP) service of the Netskope Client. A local standard user could potentially send a specially crafted message that is not properly validated with a bounds check, likely crashing the kernel driver handler. Successful exploitation could… | |
| Analizada | Alta (8.8) | 1.0% | — | Ivanti Endpoint Manager Mobile | 8/9/2026 | 9/9/2026 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin. | |
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zoho Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component | |
| Pendiente de análisis | Media (5) | 0.29% | — | Zoho Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. | |
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction | |
| Pendiente de análisis | Media (5.7) | 0.35% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Beyondtrust Endpoint Privilege ManagementAI | 17/8/2026 | 18/8/2026 | A memory-corruption vulnerability exists in a kernel-mode component of BeyondTrust Endpoint Privilege Management (Windows deployments) prior to version 26.1.2. Insufficient validation of input processed by the component may result in memory being accessed outside its intended bounds. | |
| Pendiente de análisis | Media (4.8) | 0.16% | — | Forcepoint ONE EndpointAI | 13/8/2026 | 3/9/2026 | This vulnerability allows a normal (non-admin) user to disable the Forcepoint One Endpoint SafariExtension and bypass DLP protection in F1E Mac OS before v26.04.5758. | |
| Analizada | Media (5.5) | 0.48% | — | Microsoft Defender FOR Endpoint | 11/8/2026 | 17/8/2026 | Exposure of sensitive information to an unauthorized actor in Microsoft Defender for Endpoint allows an authorized attacker to disclose information locally. | |
| Pendiente de análisis | Alta (8.1) | 1.5% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections. | |
| Pendiente de análisis | Alta (7.7) | 0.72% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage. | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service. | |
| Analizada | Alta (7.5) | 0.46% | — | Cisco Secure Endpoint | 7/8/2026 | 19/8/2026 | A vulnerability in the XAR file format parser of ClamAV could allow an unauthenticated, remote attacker to cause a DoS condition or possibly other expanded impacts as a result of memory corruption on an affected device. This vulnerability is due to improper boundary checks for content in XAR files during… | |
| Pendiente de análisis | Crítica (9.3) | 0.18% | — | Sophos Endpoint FOR MacosAISophos Home FOR MacosAI | 6/8/2026 | 1/9/2026 | A privilege escalation vulnerability allows local users to execute arbitrary code as root via Sophos Endpoint for macOS older than version 2026.1.1 and Sophos Home for macOS older than version 10.11.6. | |
| Pendiente de análisis | Crítica (9.3) | 1.4% | — | Keysight Ixchariot EndpointAI | 4/8/2026 | 26/8/2026 | Keysight IxChariot Endpoint and associated products contain a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet and execute arbitrary code with administrative privileges. | |
| Pendiente de análisis | Crítica (9.3) | 1.3% | — | Keysight Ixchariot EndpointAI | 4/8/2026 | 26/8/2026 | Keysight IxChariot Endpoint before 9.5.102 contains a stack-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code. | |
| Pendiente de análisis | Crítica (9.3) | 1.3% | — | Keysight Ixchariot EndpointAI | 4/8/2026 | 26/8/2026 | Keysight IxChariot Endpoint before 9.5.102 contains a heap-based buffer overflow. An unauthenticated remote attacker can send a specially crafted packet to crash the endpoint or potentially execute arbitrary code. | |
| Analizada | Media (5.9) | 0.26% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service. | |
| Analizada | Alta (8.6) | 0.25% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier. | |
| Pendiente de análisis | Media (4.3) | 0.65% | — | Zohocorp Manageengine Endpoint CentralAI | 21/7/2026 | 21/7/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.4.2528.34 are affected by cleartext transmission of sensitive information vulnerability. | |
| Analizada | Alta (7) | 0.23% | — | Microsoft Defender FOR Endpoint | 14/7/2026 | 22/7/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender for Endpoint allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.20% | — | Microsoft Defender FOR Endpoint | 14/7/2026 | 22/7/2026 | Time-of-check time-of-use (toctou) race condition in Microsoft Defender allows an authorized attacker to elevate privileges locally. |