Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
–

88 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.3)0.34%—Teamviewer DEX Platform On-premisesAI13/5/202617/6/2026
A command injection vulnerability was discovered in TeamViewer DEX Platform On-Premises (former 1E DEX Platform On-Premises) prior to version 9.2. Improper input validation allows authenticated users with at least questioner privileges to inject commands in specific instructions. Exploitation could lead to execution…
AplazadaAlta (8.8)0.33%—Therefore Corporation Gmbh Therefore OnlineAITherefore Corporation Gmbh Therefore On-premisesAI31/10/202517/6/2026
Therefore Corporation GmbH has recently become aware that Therefore™ Online and Therefore™ On-Premises contain an account impersonation vulnerability. A malicious user may potentially be able to impersonate the web service account or the account of a service using the API when connecting to the Therefore™ Server. If…
AplazadaMedia (6.8)0.28%—Okta On-premises ProvisioningAI22/7/202517/6/2026
Okta On-Premises Provisioning (OPP) agents log certain user data during administrator-initiated password resets. This vulnerability allows an attacker with access to the local servers running OPP agents to retrieve user personal information and temporary passwords created during password reset. You are affected by…
AplazadaCrítica (9.1)0.44%—Menlo On-premise ApplianceAI14/12/202417/6/2026
In Menlo On-Premise Appliance before 2.88, web policy may not be consistently applied properly to intentionally malformed client requests. This is fixed in 2.88.2+, 2.89.1+, and 2.90.1+.
AplazadaMedia (6.5)0.48%—Zohocorp Manageengine Analytics PlusAIZoho Analytics On-premiseAI3/10/202417/6/2026
Zohocorp ManageEngine Analytics Plus versions before 5410 and Zoho Analytics On-Premise versions before 5410 are vulnerable to Path traversal.
AnalizadaAlta (7.5)0.52%—IBM Security Verify Privilege On-premises16/4/202417/6/2026
IBM Security Verify Privilege 11.6.25 could allow an unauthenticated actor to obtain sensitive information from the SOAP API. IBM X-Force ID: 287651.
AnalizadaAlta (7.5)0.42%—IBM Security Verify Privilege On-premises4/3/202417/6/2026
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240453.
ModificadaMedia (5.3)0.30%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 does not validate, or incorrectly validates, a certificate which could disclose sensitive information which could aid further attacks against the system. IBM X-Force ID: 240455.
ModificadaMedia (5.3)0.68%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. IBM X-Force ID: 240454.
ModificadaMedia (4.4)0.45%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow a privileged user to cause by using a malicious payload. IBM X-Force ID: 240634.
ModificadaMedia (5.3)0.52%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information through an HTTP request that could aid an attacker in further attacks against the system. IBM X-Force ID: 240452.
ModificadaMedia (5.9)0.48%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221963.
ModificadaAlta (7.5)0.41%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could disclose sensitive information to an attacked due to the transmission of data in clear text. IBM X-Force ID: 221962.
ModificadaMedia (4.3)0.24%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to spoof a trusted entity due to improperly validating certificates. IBM X-Force ID: 221957.
ModificadaAlta (8.8)1.2%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow a remote authenticated attacker to execute arbitrary commands on the system by sending a specially crafted request. IBM X-Force ID: 221681.
ModificadaMedia (5.3)0.61%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain version number information using a specially crafted HTTP request that could be used in further attacks against the system. IBM X-Force ID: 207899.
ModificadaAlta (7.1)0.47%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premise 11.5 could allow an authenticated user to obtain sensitive information or perform unauthorized actions due to improper input validation. IBM X-Force ID: 207898.
ModificadaMedia (4.3)0.44%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow a user to obtain sensitive information due to insufficient session expiration. IBM X-Force ID: 199324.
ModificadaMedia (4.3)0.44%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow an attacker to modify messages returned from the server due to hazardous input validation. IBM X-Force ID: 221961.
ModificadaMedia (5.3)0.48%—IBM Security Verify Privilege On-premises17/10/202317/6/2026
IBM Security Verify Privilege On-Premises 11.5 could allow a remote attacker to obtain sensitive information, caused by the failure to properly enable HTTP Strict Transport Security. An attacker could exploit this vulnerability to obtain sensitive information using man in the middle techniques. IBM X-Force ID: 221827.
ModificadaMedia (6.1)1.2%—Structurizr On-premises Installation12/10/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194.
ModificadaMedia (6.5)0.53%—Sysaid On-premises30/7/202317/6/2026
Sysaid - CWE-552: Files or Directories Accessible to External Parties - Authenticated users may exfiltrate files from the server via an unspecified method.
ModificadaAlta (7.2)0.65%—Sysaid On-premises30/7/202317/6/2026
Sysaid - CWE-434: Unrestricted Upload of File with Dangerous Type - A malicious user with administrative privileges may be able to upload a dangerous filetype via an unspecified method.
ModificadaMedia (6.5)0.74%—Zoom On-premise Meeting Connector MMR14/10/202217/6/2026
Zoom On-Premise Meeting Connector MMR before version 4.8.20220916.131 contains an improper access control vulnerability. As a result, a malicious actor in a meeting or webinar they are authorized to join could prevent participants from receiving audio and video causing meeting disruptions.
ModificadaMedia (6.5)0.56%—Zoom On-premise Meeting Connector MMR14/10/202217/6/2026
Zoom On-Premise Meeting Connector MMR before version 4.8.20220815.130 contains an improper access control vulnerability. As a result, a malicious actor could obtain the audio and video feed of a meeting they were not authorized to join and cause other meeting disruptions.