Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
72 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.7) | 0.21% | — | Opswat Outpost Security Suite | 11/11/2025 | 17/6/2026 | An issue in Agnitum Outpost Security Suite 7.5.3 (3942.608.1810) and 7.6 (3984.693.1842) allows a local attacker to execute arbitrary code via the lock function. The manufacturer fixed the vulnerability in version 8.0 (4164.652.1856) from December 17, 2012. | |
| Aplazada | Alta (8.1) | 0.48% | — | Astra Security SuiteAI | 11/11/2025 | 17/6/2026 | The Astra Security Suite – Firewall & Malware Scan plugin for WordPress is vulnerable to arbitrary file uploads due to insufficient validation of remote URLs for zip downloads and an easily guessable key in all versions up to, and including, 0.2. This makes it possible for unauthenticated attackers to upload arbitrary… | |
| Analizada | Alta (8.1) | 0.24% | — | Dieboldnixdorf Vynamic Security Suite | 29/8/2025 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR01 does not validate file attributes or the contents of /root during integrity validation. This allows code execution, recovery of TPM Disk Encryption keys, decryption of the Windows system partition, and full control of the Windows OS, e.g., through ~/.profile… | |
| Analizada | Alta (8.1) | 0.37% | — | Dieboldnixdorf Vynamic Security Suite | 29/8/2025 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite through 4.3.0 SR06 contains functionality that allows the removal of critical system files before the filesystem is properly mounted (e.g., leveraging a delete call in /etc/rc.d/init.d/mountfs to remove the /etc/fstab file). This can allow code execution and, in some versions,… | |
| Aplazada | Media (5.3) | 0.49% | — | Webprotect.ai Astra Security SuiteAI | 1/4/2025 | 17/6/2026 | Missing Authorization vulnerability in WebProtect.ai Astra Security Suite getastra allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Astra Security Suite: from n/a through <= 0.2. | |
| Aplazada | Crítica (9.8) | 0.59% | — | Norman Security SuiteAI | 6/1/2025 | 17/6/2026 | An Escalation of Privilege security vulnerability was found in SecureAge Security Suite software 7.0.x before 7.0.38, 7.1.x before 7.1.11, 8.0.x before 8.0.18, and 8.1.x before 8.1.18 that allows arbitrary file creation, modification and deletion. | |
| Modificada | Media (6.8) | 0.36% | — | Dieboldnixdorf Vynamic Security Suite | 8/8/2024 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR17, 4.0.0 SR07, 4.1.0 SR04, 4.2.0 SR04, and 4.3.0 SR02 fails to validate file attributes during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk. | |
| Analizada | Media (6.8) | 0.28% | — | Dieboldnixdorf Vynamic Security Suite | 8/8/2024 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR16, 4.0.0 SR06, 4.1.0 SR04, 4.2.0 SR03, and 4.3.0 SR01 fails to validate symlinks during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk. | |
| Analizada | Media (6.6) | 0.26% | — | Dieboldnixdorf Vynamic Security Suite | 8/8/2024 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR15, 4.0.0 SR05, 4.1.0 SR03, and 4.2.0 SR02 fails to validate the directory contents of certain directories (e.g., ensuring the expected hash sum) during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to… | |
| Analizada | Media (6.8) | 0.41% | — | Dieboldnixdorf Vynamic Security Suite | 8/8/2024 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR4 fails to validate /etc/initab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk. | |
| Modificada | Media (6.8) | 0.26% | — | Dieboldnixdorf Vynamic Security Suite | 8/8/2024 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR10 fails to validate /etc/mtab during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's hard disk. | |
| Modificada | Media (6.8) | 0.41% | — | Dieboldnixdorf Vynamic Security Suite | 8/8/2024 | 17/6/2026 | Diebold Nixdorf Vynamic Security Suite (VSS) before 3.3.0 SR12, 4.0.0 SR04, 4.1.0 SR02, and 4.2.0 SR01 fails to validate the directory structure of the root file system during the Pre-Boot Authorization (PBA) process. This can be exploited by a physical attacker who is able to manipulate the contents of the system's… | |
| Modificada | Alta (7.8) | 0.09% | — | Dell EncryptionDell Endpoint Security Suite EnterpriseDell Security Management Server | 6/2/2024 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in… | |
| Modificada | Alta (7.3) | 0.15% | — | Dell Endpoint Security Suite EnterpriseDell EncryptionDell Security Management Server | 16/11/2023 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a… | |
| Modificada | Alta (7.8) | 0.18% | — | Dell EncryptionDell Endpoint Security Suite Enterprise | 18/8/2020 | 17/6/2026 | Dell Encryption versions prior to 10.8 and Dell Endpoint Security Suite versions prior to 2.8 contain a privilege escalation vulnerability because of an incomplete fix for CVE-2020-5358. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected… | |
| Modificada | Media (6.1) | 0.64% | — | Carson-saint Saint Security Suite | 10/8/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Permissions component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link. | |
| Modificada | Alta (8.8) | 1.2% | — | Carson-saint Saint Security Suite | 10/8/2020 | 17/6/2026 | An SQL injection vulnerability in the Analytics component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database. | |
| Modificada | Alta (8.8) | 1.2% | — | Carson-saint Saint Security Suite | 10/8/2020 | 17/6/2026 | An SQL injection vulnerability in the Assets component of SAINT Security Suite 8.0 through 9.8.20 allows a remote, authenticated attacker to gain unauthorized access to the database. | |
| Modificada | Media (6.1) | 0.64% | — | Carson-saint Saint Security Suite | 10/8/2020 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in the Credential Manager component in SAINT Security Suite 8.0 through 9.8.20 could allow arbitrary script to run in the context of a logged-in user when the user clicks on a specially crafted link. | |
| Modificada | Alta (7.8) | 0.19% | — | Dell EncryptionDell Endpoint Security Suite Enterprise | 15/6/2020 | 17/6/2026 | Dell Encryption versions prior to 10.7 and Dell Endpoint Security Suite versions prior to 2.7 contain a privilege escalation vulnerability due to incorrect permissions. A local malicious user with low privileges could potentially exploit this vulnerability to gain elevated privilege on the affected system with the… | |
| Modificada | Media (5.5) | 2.9% | — | Avira Anti-malware SDKAvira Antivirus ServerAvira Antivirus FOR EndpointAvira Antivirus FOR Small Business+4 | 20/2/2020 | 17/6/2026 | Avira AV Engine before 8.3.54.138 allows virus-detection bypass via a crafted ISO archive. This affects versions before 8.3.54.138 of Antivirus for Endpoint, Antivirus for Small Business, Exchange Security (Gateway), Internet Security Suite for Windows, Prime, Free Security Suite for Windows, and Cross Platform… | |
| Modificada | Alta (7.3) | 0.29% | — | Dell EncryptionDell Endpoint Security Suite Enterprise | 7/10/2019 | 17/6/2026 | The vulnerability is limited to the installers of Dell Encryption Enterprise versions prior to 10.4.0 and Dell Endpoint Security Suite Enterprise versions prior to 2.4.0. This issue is exploitable only during the installation of the product by an administrator. A local authenticated low privileged user potentially… | |
| Modificada | Alta (7.8) | 0.57% | — | Avira Free Security SuiteAvira Software Updater | 29/8/2019 | 17/6/2026 | An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM… | |
| Modificada | Alta (7.5) | 0.55% | — | Dell EncryptionDell Endpoint Security Suite Enterprise | 11/10/2018 | 17/6/2026 | On install, Dell Encryption versions prior 10.0.1 and Dell Endpoint Security Suite Enterprise versions prior 2.0.1 will overwrite and manually set the "Minimum Password Length" group policy object to a value of 1 on that device. This allows for users to bypass any existing policy for password length and potentially… | |
| Modificada | Media (5.5) | 0.29% | — | Escanav Escan Internet Security Suite | 13/7/2018 | 17/6/2026 | In MicroWorld eScan Internet Security Suite (ISS) for Business 14.0.1400.2029, the driver econceal.sys allows a non-privileged user to send a 0x830020E0 IOCTL request to \\.\econceal to cause a denial of service (BSOD). |