Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 331 respecto a la semana anterior
Críticas / altas1352▲ 94 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.57% | — | Ncp-e NCP Secure Entry ClientNcp-e Secure Enterprise Client | 26/11/2025 | 17/6/2026 | NCP Secure Enterprise Client 13.18 and NCP Secure Entry Windows Client 13.19 have an Untrusted Search Path vulnerability. | |
| Modificada | Alta (8.8) | 0.77% | — | Ncp-e Secure Enterprise Client | 25/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 13.10 allows attackers to execute DLL files with SYSTEM privileges by creating a symbolic link from a %LOCALAPPDATA%\Temp\NcpSupport* location. | |
| Modificada | Media (4.3) | 0.59% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to read registry information of the operating system by creating a symbolic link. | |
| Modificada | Media (6.5) | 0.70% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Insecure File Permissions in Support Assistant in NCP Secure Enterprise Client before 12.22 allow attackers to write to configuration files from low-privileged user accounts. | |
| Modificada | Media (6.5) | 0.77% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers read the contents of arbitrary files on the operating system by creating a symbolic link. | |
| Modificada | Alta (8.1) | 0.85% | — | Ncp-e Secure Enterprise Client | 9/12/2023 | 17/6/2026 | Support Assistant in NCP Secure Enterprise Client before 12.22 allows attackers to delete arbitrary files on the operating system by creating a symbolic link. | |
| Modificada | Alta (7.8) | 0.19% | — | Fabasoft CloudFabasoft Cloud Enterprise ClientFabasoft Folio / Egov-suite | 3/8/2023 | 17/6/2026 | Fabasoft Cloud Enterprise Client 23.3.0.130 allows a user to escalate their privileges to local administrator. | |
| Modificada | Alta (7.8) | 0.23% | — | Fabasoft Cloud Enterprise Client | 19/9/2022 | 17/6/2026 | The folioupdate service in Fabasoft Cloud Enterprise Client 22.4.0043 allows Local Privilege Escalation. | |
| Modificada | Alta (8.8) | 0.50% | — | Nomachine Enterprise Client | 7/12/2021 | 17/6/2026 | NoMachine Enterprise Client is affected by Integer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Client above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (8.8) | 0.48% | — | Nomachine Enterprise Client | 7/12/2021 | 17/6/2026 | NoMachine Enterprise Client is affected by Buffer Overflow. IOCTL Handler 0x22001B in the NoMachine Enterprise Client above 4.0.346 and below 7.7.4 allow local attackers to execute arbitrary code in kernel mode or cause a denial of service (memory corruption and OS crash) via specially crafted I/O Request Packet. | |
| Modificada | Alta (7.8) | 0.53% | — | Ncp-e Secure Enterprise Client | 28/7/2020 | 17/6/2026 | NCP Secure Enterprise Client before 10.15 r47589 allows a symbolic link attack on enumusb.reg via Support Assistant. | |
| Modificada | Alta (7.8) | 1.2% | — | WhatsappWhatsapp BusinessWhatsapp Enterprise Client | 14/11/2019 | 17/6/2026 | A stack-based buffer overflow could be triggered in WhatsApp by sending a specially crafted MP4 file to a WhatsApp user. The issue was present in parsing the elementary stream metadata of an MP4 file and could result in a DoS or RCE. This affects Android versions prior to 2.19.274, iOS versions prior to 2.19.100,… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x802022E0. By crafting an input buffer we can control the execution path to the point where the constant 0x12 will be written to a user-controlled… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x8020601C. By crafting an input buffer we can control the execution path to the point where a global variable will be written to a user controlled… | |
| Modificada | Alta (7.8) | 0.54% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80202014. By crafting an input buffer we can control the execution path to the point where the constant 0xFFFFFFF will be written to a user-controlled… | |
| Modificada | Alta (7.8) | 0.60% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via multiple IOCTLs, e.g., 0x8810200B, 0x8810200F, 0x8810201B, 0x8810201F, 0x8810202B, 0x8810202F, 0x8810203F, 0x8810204B, 0x88102003, 0x88102007, 0x88102013,… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206024. By crafting an input buffer we can control the execution path to the point where a global variable will be written to a user controlled… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80202298. By crafting an input buffer we can control the execution path to the point where the nt!memset function is called to zero out contents of a… | |
| Modificada | Alta (7.8) | 0.61% | — | Sophos Safeguard Easy Device Encryption ClientSophos Safeguard Enterprise ClientSophos Safeguard LAN Crypt Client | 9/7/2018 | 17/6/2026 | Sophos SafeGuard Enterprise before 8.00.5, SafeGuard Easy before 7.00.3, and SafeGuard LAN Crypt before 3.95.2 are vulnerable to Local Privilege Escalation via IOCTL 0x80206040. By crafting an input buffer we can control the execution path to the point where the constant DWORD 0 will be written to a user-controlled… | |
| Modificada | Alta (7.8) | 0.85% | — | Puppet Enterprise Client Tools | 14/6/2018 | 17/6/2026 | On Windows only, with a specifically crafted configuration file an attacker could get Puppet PE client tools (aka pe-client-tools) 16.4.x prior to 16.4.6, 17.3.x prior to 17.3.6, and 18.1.x prior to 18.1.2 to load arbitrary code with privilege escalation. | |
| Modificada | Media (6.9) | 0.35% | — | Ncp-e Secure ClientNcp-e Secure Enterprise ClientNcp-e Secure Entry Client | 6/9/2012 | 16/6/2026 | Multiple untrusted search path vulnerabilities in NCP Secure Enterprise Client before 9.21 Build 68, Secure Entry Client before 9.23 Build 18, and Secure Client - Juniper Edition before 9.23 Build 18 allow local users to gain privileges via a Trojan horse (1) dvccsabase002.dll, (2) conman.dll, (3) kmpapi32.dll, or (4)… |