Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2727▼ 85 respecto a la semana anterior
Críticas / altas1416▲ 186 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
–

423 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5.4)0.17%—Devolutions ServerAI29/9/202630/9/2026
Improper access control in the partial connection API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to read, create, modify, and delete System Vault entries via a crafted API request.
Pendiente de análisisMedia (4.3)0.19%—Devolutions ServerAI29/9/202629/9/2026
Improper rule enforcement in the PAM Active Directory provider in Devolutions Server 2026.3.5 allows a user with PAM edit permissions to bypass the Devolutions Gateway host ruleset.
Pendiente de análisisMedia (5)0.16%—DevolutionsAI29/9/202629/9/2026
Missing authorization in the gateway network scan token API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to generate a network scan token and perform internal network discovery and port scanning through the gateway via a crafted API request.
Pendiente de análisisAlta (7.2)0.07%—Devolutions ServerAI29/9/202630/9/2026
Cleartext storage of sensitive information in the database in Devolutions Server 2026.3.5.0 and earlier allows an attacker with read access to the database to obtain external identity provider tokens and active session identifiers via direct inspection of stored records.
Pendiente de análisisMedia (5.4)0.17%—Devolutions ServerAI29/9/202629/9/2026
Missing authorization in the attachment history API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated low-privileged user to permanently delete or restore vault attachments via a crafted API request.
Pendiente de análisisMedia (6.5)0.22%—Devolutions ServerAI29/9/202629/9/2026
Missing authorization in the data source settings API in Devolutions Server 2026.3.5.0 and earlier allows an authenticated non-administrative user to disclose integration secrets via a crafted API request.
AplazadaBaja (2.1)0.45%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI21/9/202630/9/2026
A vulnerability was determined in ST Engineering iDirect Evolution and Velocity WebServer Evolution. This vulnerability affects unknown code of the file /authorize of the component HTTP Request Handler. Executing a manipulation of the argument Success can lead to http response splitting. It is possible to launch the…
AplazadaBaja (2.1)0.46%—ST Engineering Idirect EvolutionAIST Engineering Velocity Webserver EvolutionAI21/9/202630/9/2026
A vulnerability was found in ST Engineering iDirect Evolution and Velocity WebServer Evolution up to 20260717. This affects an unknown part of the component Location Header Handler. Performing a manipulation of the argument Host results in open redirect. It is possible to initiate the attack remotely. The exploit has…
AplazadaCrítica (9.2)0.85%—B2evolution CMSAI17/9/202623/9/2026
b2evolution CMS versions 6.7.8 through 7.2.5 contain an incomplete fix for CVE-2016-8901 where the serialized-array object check in param_check_serialized_array() fails to reject payloads with negative integer array keys. Unauthenticated attackers can submit crafted serialized PHP objects via POST requests to…
Pendiente de análisisMedia (6.5)0.37%—Devolutions Powershell UniversalAI15/9/202616/9/2026
Insertion of sensitive information into log file in the slow query logging feature in Devolutions PowerShell Universal 2026.2.5 and earlier allows an authenticated user with log read permission to obtain application tokens, data protection key material and other stored credentials via SQL parameter values written to…
Pendiente de análisisAlta (8.3)0.13%—DevolutionsAI15/9/202619/9/2026
Improper certificate validation on LDAPS connections to Active Directory in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept privileged directory service credentials via a spoofed domain controller certificate.
Pendiente de análisisMedia (6.5)0.34%—DevolutionsAI15/9/202619/9/2026
Server-Side Request Forgery (SSRF) in the VMware synchronization feature in Devolutions Server 2026.2.16 and earlier allows a low-privileged authenticated user to obtain other users' credentials and reach internal or cloud-metadata network endpoints via a crafted connection definition submitted for datacenter…
Pendiente de análisisMedia (6.5)0.35%—DevolutionsAI15/9/202619/9/2026
Improper access control in the vault entry listing feature in Devolutions Server 2026.2.16 and earlier allows an authenticated user lacking the view-password permission to obtain cleartext passwords via a request to the entry listing endpoint with password disclosure parameters.
Pendiente de análisisMedia (4.8)0.14%—DevolutionsAI15/9/202619/9/2026
Improper certificate validation in the shared HTTP client used by synchronization and integration features in Devolutions Server 2026.2.16 and earlier allows a network-positioned attacker to intercept and tamper with outbound TLS connections via a spoofed or self-signed certificate.
AplazadaMedia (6.9)0.45%—Evolution APIAI15/9/202624/9/2026
evolution-api through 2.3.7 contains an incorrect array comparison in the metricsIPWhitelist middleware that always evaluates to false, allowing unauthenticated access to the /metrics endpoint. Attackers can bypass IP whitelist restrictions to access sensitive metrics disclosing server version, database client name,…
Pendiente de análisisMedia (6.3)0.53%—EvolutionAI10/9/202610/9/2026
A flaw was found in Evolution. A remote attacker can exploit this vulnerability by sending a specially crafted HTML email containing a spoofed vCard control. When a victim clicks on this control, Evolution's trusted JavaScript handler incorrectly assigns an attacker-controlled JavaScript URL to an iframe's source.…
Pendiente de análisisMedia (4.3)0.15%—Devolutions Remote Desktop ManagerAIIronvncAI24/8/202628/8/2026
Insufficient verification of data authenticity in the IronVNC client in Devolutions Remote Desktop Manager 2026.2.17.0 and earlier, 2026.1.24.0 and earlier, allows an on-path attacker to intercept and tamper with VNC sessions via automatic acceptance of the server's RSA key during RSA-AES authentication.
Pendiente de análisisAlta (8.1)0.39%—Devolutions Powershell UniversalAI14/8/202628/8/2026
Improper control of generation of code ('Code Injection') in the settings feature in Devolutions PowerShell Universal 2026.2.3 and earlier allows an authenticated user with settings management permission to execute arbitrary PowerShell code via a crafted setting value that is not properly escaped when written to the…
AnalizadaAlta (7.4)0.13%—Devolutions Password Manager29/7/202621/8/2026
Improper certificate validation in the Devolutions Server connection handling in Devolutions Password Manager 2026.2.1.0 and earlier on Android, iOS, and macOS allows an adjacent-network attacker to intercept and modify sensitive information via a forged TLS certificate.
AnalizadaMedia (4.3)0.25%—Devolutions Server27/7/20263/8/2026
Improper access control in the PAM password history endpoints in Devolutions Server allows an authenticated low-privileged user to disclose plaintext credential secrets via crafted API requests. This issue affects :
AnalizadaMedia (4.3)0.27%—Devolutions Server27/7/20263/8/2026
Improper access control in the NetBox synchronizer in Devolutions Server allows an authenticated user with view-only permission on an entry to obtain a stored API token via the partial connection endpoint. This issue affects :
AnalizadaAlta (8.8)0.42%—Devolutions Server27/7/20263/8/2026
Improper access control in the role membership management endpoint in Devolutions Server allows an authenticated non-administrative user holding the user-group membership management permission to escalate privileges to administrator via a crafted API request. This issue affects :
AnalizadaMedia (6.5)0.10%—Devolutions Powershell Universal24/7/202629/7/2026
Cleartext storage of sensitive information in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows a local actor with file system access to read secret values via secret variables stored in cleartext on disk when no vault is selected.
AnalizadaAlta (8.8)0.53%—Devolutions Powershell Universal24/7/202629/7/2026
Improper control of generation of code ('Code Injection') in the variables feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with variable write permission to execute arbitrary PowerShell code via a crafted variable value that is not properly escaped when written to the…
AnalizadaAlta (8.8)0.53%—Devolutions Powershell Universal24/7/202629/7/2026
Improper control of generation of code ('Code Injection') in the schedule feature in Devolutions PowerShell Universal 2026.2.2 and earlier allows an authenticated user with schedule creation permission to execute arbitrary PowerShell code via crafted schedule parameter names concatenated into a script invocation.