Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2561▼ 314 respecto a la semana anterior
Críticas / altas1347▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
187 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 1.0% | — | Ivanti Endpoint Manager Mobile | 8/9/2026 | 9/9/2026 | Missing authorization in Ivanti Endpoint Manager Mobile before version 12.10.0.0, 12.9.0.2, and 12.8.0.4 allows a remote authenticated attacker to escalate their privileges to admin. | |
| Pendiente de análisis | Alta (8.1) | 1.5% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | Cleartext transmission of sensitive information in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker in a MITM position to leak credentials for external SQL connections. | |
| Pendiente de análisis | Alta (7.7) | 0.72% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | External control of a filename in the Core of Ivanti Endpoint Manager before version 2024 SU7 allows a remote authenticated attacker full write control over an S3 bucket configured for session recording storage. | |
| Pendiente de análisis | Alta (7.5) | 1.6% | — | Ivanti Endpoint ManagerAI | 11/8/2026 | 31/8/2026 | An out-of-bounds read in the Agent of Ivanti Endpoint Manager before version 2024 SU7 allows a remote unauthenticated attacker to crash an agent service. | |
| Analizada | Media (5.9) | 0.26% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | An Improper Input Validation in the BlackBerry UEM Management Console of BlackBerry UEM 12.23.0 QF8 and earlier allows Arbitrary File Download and Potential Denial of Service. | |
| Analizada | Alta (8.6) | 0.25% | — | Blackberry Unified Endpoint Manager | 28/7/2026 | 14/8/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in BlackBerry UEM Management Console of BlackBerry UEM allows Cross-Site Scripting (XSS). This issue affects UEM: 12.23.0 QF8 or earlier. | |
| Analizada | Alta (8.8) | 1.6% | — | Ivanti Endpoint Manager | 12/5/2026 | 17/6/2026 | SQL injection in the web console of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to achieve remote code execution. | |
| Analizada | Alta (7.8) | 0.37% | — | Ivanti Endpoint Manager | 12/5/2026 | 17/6/2026 | Incorrect permissions assignment in the agent of Ivanti Endpoint Manager before version 2024 SU6 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Media (6.5) | 1.1% | — | Ivanti Endpoint Manager | 12/5/2026 | 17/6/2026 | An exposed dangerous method on the Core Server of Ivanti Endpoint Manager before version 2024 SU6 allows a remote authenticated attacker to leak access credentials. | |
| Analizada | Crítica (9.1) | 0.86% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | Improper certificate validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to enroll a device belonging to a restricted set of unenrolled devices, leading to information disclosure about EPMM appliance and impacting on the integrity of the newly enrolled… | |
| Analizada | Alta (7.2) | 2.5% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Input Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remotely authenticated user with administrative access to achieve remote code execution. | |
| Analizada | Crítica (9.8) | 1.5% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to invoke arbitrary methods. | |
| Analizada | Crítica (9.1) | 0.85% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Certificate Validation in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote unauthenticated attacker to impersonate registered Sentry hosts and obtain valid CA-signed client certificates. | |
| Analizada | Alta (8.8) | 1.2% | — | Ivanti Endpoint Manager Mobile | 7/5/2026 | 17/6/2026 | An Improper Access Control vulnerability in Ivanti EPMM before versions 12.6.1.1, 12.7.0.1, and 12.8.0.1 allows a remote authenticated attacker to gain administrative access. | |
| Analizada | Crítica (9.3) | 0.86% | — | Motex Lanscope Endpoint Manager | 25/2/2026 | 17/6/2026 | Path traversal vulnerability exists in Lanscope Endpoint Manager (On-Premises) Sub-Manager Server Ver.9.4.7.3 and earlier, which may allow an attacker to tamper with arbitrary files and execute arbitrary code on the affected system. | |
| Analizada | Alta (7.5) | 88% | ⚠ Explotación activa | Ivanti Endpoint Manager | 10/2/2026 | 17/6/2026 | An authentication bypass in Ivanti Endpoint Manager before version 2024 SU5 allows a remote unauthenticated attacker to leak specific stored credential data. | |
| Analizada | Media (6.5) | 0.73% | — | Ivanti Endpoint Manager | 10/2/2026 | 17/6/2026 | SQL injection in Ivanti Endpoint Manager before version 2024 SU5 allows a remote authenticated attacker to read arbitrary data from the database. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Analizada | Crítica (9.8) | 99% | ⚠ Explotación activa | Ivanti Endpoint Manager Mobile | 29/1/2026 | 17/6/2026 | A code injection in Ivanti Endpoint Manager Mobile allowing attackers to achieve unauthenticated remote code execution. | |
| Aplazada | Media (6.9) | 0.27% | — | Freepbx Endpoint ManagerAI | 10/12/2025 | 25/9/2026 | FreePBX Endpoint Manager is a module for managing telephony endpoints in FreePBX systems. Versions prior to 16.0.96 and 17.0.1 through 17.0.9 have a weak default password. By default, this is a 6 digit numeric value which can be brute forced. (This is the app_password parameter). Depending on local configuration, this… | |
| Analizada | Alta (7.8) | 0.58% | — | Ivanti Endpoint Manager | 9/12/2025 | 17/6/2026 | Improper verification of cryptographic signatures in the patch management component of Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary code. User Interaction is required. | |
| Analizada | Alta (8) | 1.4% | — | Ivanti Endpoint Manager | 9/12/2025 | 17/6/2026 | Path traversal in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote authenticated attacker to write arbitrary files outside of the intended directory. User interaction is required. | |
| Analizada | Alta (8.8) | 2.0% | — | Ivanti Endpoint Manager | 9/12/2025 | 17/6/2026 | Improper control of dynamically managed code resources in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote, unauthenticated attacker to write arbitrary files on the server, potentially leading to remote code execution. User interaction is required. | |
| Analizada | Media (6.1) | 33% | — | Ivanti Endpoint Manager | 9/12/2025 | 17/6/2026 | Stored XSS in Ivanti Endpoint Manager prior to version 2024 SU4 SR1 allows a remote unauthenticated attacker to execute arbitrary JavaScript in the context of an administrator session. User interaction is required. | |
| Analizada | Alta (7.1) | 0.24% | — | Ivanti Endpoint Manager | 11/11/2025 | 17/6/2026 | Insecure default permissions in the agent of Ivanti Endpoint Manager before version 2024 SU4 allows a local authenticated attacker to write arbitrary files anywhere on disk |