Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 17% | — | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 8/1/2025 | 17/6/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a local authenticated attacker to escalate their privileges. | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 8/1/2025 | 1/10/2026 | A stack-based buffer overflow in Ivanti Connect Secure before version 22.7R2.5, Ivanti Policy Secure before version 22.7R1.2, and Ivanti Neurons for ZTA gateways before version 22.7R2.3 allows a remote unauthenticated attacker to achieve remote code execution. | |
| Analizada | Alta (8.2) | 100% | ⚠ Explotación activa💥 Exploit | Ivanti Connect SecureIvanti Policy SecureIvanti Neurons FOR Zero-trust Access | 31/1/2024 | 4/8/2026 | A server-side request forgery vulnerability in the SAML component of Ivanti Connect Secure (9.x, 22.x) and Ivanti Policy Secure (9.x, 22.x) and Ivanti Neurons for ZTA allows an attacker to access certain restricted resources without authentication. | |
| Modificada | Alta (7.5) | 2.7% | — | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 5/12/2022 | 17/6/2026 | An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1. | |
| Modificada | Alta (7.5) | 2.7% | — | Ivanti Connect SecureIvanti Neurons FOR Zero-trust AccessIvanti Policy Secure | 5/12/2022 | 17/6/2026 | An unauthenticated attacker can cause a denial-of-service to the following products: Ivanti Connect Secure (ICS) in versions prior to 9.1R14.3, 9.1R15.2, 9.1R16.2, and 22.2R4, Ivanti Policy Secure (IPS) in versions prior to 9.1R17 and 22.3R1, and Ivanti Neurons for Zero-Trust Access in versions prior to 22.3R1. |