Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2571▼ 296 respecto a la semana anterior
Críticas / altas1355▲ 107 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

19 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (4.4)0.20%—Zscaler Internet AccessAI18/9/202618/9/2026
A file type attribution issue in Zscaler Internet Access File Type Control evaluation rules may allow improper evaluation of File Type Control policies in rare circumstances.
AnalizadaBaja (2.7)0.17%—Zscaler Internet Access Admin Portal23/2/202617/6/2026
Improper neutralization of special elements in user-supplied input within the ZIA Admin UI could allow an authenticated administrator to access or retrieve unauthorized internal information in rare conditions.
AnalizadaBaja (2.7)0.20%—Zscaler Internet Access Admin Portal23/2/202617/6/2026
Improper validation of user-supplied input in the ZIA Admin UI could allow an authenticated administrator to initiate backend functions through specific input fields in limited scenarios.
AplazadaAlta (8.5)0.21%—Privateinternetaccess Private Internet AccessAI13/1/202617/6/2026
Private Internet Access 3.3 contains an unquoted service path vulnerability that allows local users to potentially execute arbitrary code with elevated system privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during…
ModificadaAlta (7.1)0.31%—Akamai Secure Internet Access Enterprise Threatavert4/11/202417/6/2026
Akamai SIA (Secure Internet Access Enterprise) ThreatAvert, in SPS (Security and Personalization Services) before the latest 19.2.0 patch and Apps Portal before 19.2.0.3 or 19.2.0.20240814, has incorrect authorization controls for the Admin functionality on the ThreatAvert Policy page. An authenticated user can…
ModificadaCrítica (9.8)0.39%—Zscaler Internet Access Admin Portal31/8/202317/6/2026
An Improper Verification of Cryptographic Signature in the SAML authentication of the Zscaler Admin UI allows a Privilege Escalation.This issue affects Admin UI: from 6.2 before 6.2r.
ModificadaAlta (7.5)0.95%—Bluedon Internet Access Detector24/3/202217/6/2026
Bluedon Information Security Technologies Co.,Ltd Internet Access Detector v1.0 was discovered to contain an information leak which allows attackers to access the contents of the password file via unspecified vectors.
ModificadaAlta (7.5)2.5%—Privateinternetaccess Private Internet Access VPN Client14/9/202017/6/2026
A vulnerability in the Private Internet Access (PIA) VPN Client for Linux 1.5 through 2.3+ allows remote attackers to bypass an intended VPN kill switch mechanism and read sensitive information via intercepting network traffic. Since 1.5, PIA has supported a “split tunnel” OpenVPN bypass option. The PIA killswitch &…
ModificadaAlta (7.8)0.81%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA Linux/macOS binary openvpn_launcher.64 binary is setuid root. This binary accepts several parameters to update…
ModificadaAlta (7.8)0.81%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher.64 binary is setuid root. This binary executes /opt/pia/openvpn-64/openvpn, passing the parameters provided…
ModificadaAlta (7.8)0.63%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The macOS binary openvpn_launcher.64 is setuid root. This binary creates /tmp/pia_upscript.sh when executed. Because the file…
ModificadaAlta (7.8)0.86%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for macOS could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The openvpn_launcher binary is setuid root. This program is called during the connection process and executes several operating…
ModificadaAlta (7.8)0.91%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The root_runner.64 binary is setuid root. This binary executes /opt/pia/ruby/64/ruby, which in turn attempts to load several…
ModificadaAlta (7.8)2.1%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v1.0 for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. The PIA client is vulnerable to a DLL injection vulnerability during the software update process. The updater loads several…
ModificadaAlta (7.1)0.58%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v82 for Linux and macOS could allow an authenticated, local attacker to overwrite arbitrary files. The openvpn_launcher binary is setuid root. This binary supports the --log option, which accepts a path as an argument. This parameter is…
ModificadaAlta (7.1)0.64%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, local attacker to overwrite arbitrary files. When the client initiates a connection, the XML /tmp/pia-watcher.plist file is created. If the file exists, it will be…
ModificadaAlta (7.8)0.93%—Londontrustmedia Private Internet Access21/6/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. On startup, the PIA Windows service (pia-service.exe) loads the OpenSSL library from %PROGRAMFILES%\Private…
ModificadaAlta (7.8)0.33%—Londontrustmedia Private Internet Access17/4/201817/6/2026
A vulnerability in London Trust Media Private Internet Access (PIA) VPN Client v77 for Windows could allow an unauthenticated, local attacker to run executable files with elevated privileges. The vulnerability is due to insufficient implementation of access controls. The "Changelog" and "Help" options available from…
ModificadaAlta (7.5)1.8%—Londontrustmedia Private Internet Access26/10/201717/6/2026
The London Trust Media Private Internet Access (PIA) application before 1.3.3.1 for Android allows remote attackers to cause a denial of service (application crash) via a large VPN server-list file.