Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.34% | — | Tanium Threat ResponseAI | 16/9/2026 | 18/9/2026 | Tanium addressed a server-side request forgery vulnerability in Threat Response. | |
| Pendiente de análisis | Media (6.3) | 0.26% | — | Tanium Threat ResponseAI | 16/9/2026 | 18/9/2026 | Tanium addressed an improper access controls vulnerability in Threat Response. | |
| Pendiente de análisis | Alta (8.8) | 0.43% | — | Tanium Threat ResponseAI | 16/9/2026 | 18/9/2026 | Tanium addressed a SQL injection vulnerability in Threat Response. | |
| Pendiente de análisis | Baja (3.8) | 0.26% | — | Tanium Threat ResponseAI | 16/9/2026 | 18/9/2026 | Tanium addressed an improper access controls vulnerability in Threat Response. | |
| Pendiente de análisis | Baja (3.1) | 0.29% | — | Tanium Threat ResponseAI | 19/8/2026 | 1/9/2026 | Tanium addressed a compression bomb vulnerability in Threat Response. | |
| Analizada | Baja (2.7) | 0.32% | — | Tanium Threat Response | 22/4/2026 | 17/6/2026 | Tanium addressed an information disclosure vulnerability in Threat Response. | |
| Analizada | Media (4.3) | 0.26% | — | Tanium Threat Response | 5/2/2026 | 17/6/2026 | Tanium addressed an information disclosure vulnerability in Threat Response. | |
| Analizada | Media (4.3) | 0.26% | — | Tanium Threat Response | 5/2/2026 | 17/6/2026 | Tanium addressed an information disclosure vulnerability in Threat Response. | |
| Analizada | Media (4.3) | 0.25% | — | Tanium Threat Response | 5/2/2026 | 17/6/2026 | Tanium addressed an information disclosure vulnerability in Threat Response. | |
| Analizada | Media (4.9) | 0.37% | — | Tanium Threat Response | 5/2/2026 | 17/6/2026 | Tanium addressed an information disclosure vulnerability in Threat Response. | |
| Analizada | Media (4.9) | 0.39% | — | Tanium Threat Response | 5/2/2026 | 17/6/2026 | Tanium addressed an information disclosure vulnerability in Threat Response. | |
| Modificada | Media (6.8) | 0.25% | — | Proofpoint Threat Response Auto Pull | 14/6/2023 | 17/6/2026 | An information disclosure vulnerability in the faye endpoint in Proofpoint Threat Response / Threat Response Auto-Pull (PTR/TRAP) could be used by an attacker on an adjacent network to obtain credentials to integrated services via a man-in-the-middle position or cryptanalysis of the session traffic. An attacker could… | |
| Modificada | Media (4.3) | 0.26% | — | Proofpoint Threat Response Auto Pull | 14/6/2023 | 17/6/2026 | A stored cross-site scripting vulnerability in the Sources UI in Proofpoint Threat Response/ Threat Response Auto Pull (PTR/TRAP) could allow an authenticated administrator on an adjacent network to replace the image file with an arbitrary MIME type. This could result in arbitrary javascript code execution in an admin… | |
| Modificada | Crítica (9.8) | 100% | — | Apache Commons TextNetapp BluexpJuniper Security Threat Response Manager | 13/10/2022 | 17/6/2026 | Apache Commons Text performs variable interpolation, allowing properties to be dynamically evaluated and expanded. The standard format for interpolation is "${prefix:name}", where "prefix" is used to locate an instance of org.apache.commons.text.lookup.StringLookup that performs the interpolation. Starting with… | |
| Modificada | Media (5) | 7.2% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | OpenSSL 0.9.6 before 0.9.6d does not properly handle unknown message types, which allows remote attackers to cause a denial of service (infinite loop), as demonstrated using the Codenomicon TLS Test Tool. | |
| Modificada | Alta (7.5) | 9.5% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+62 | 23/11/2004 | 16/6/2026 | The do_change_cipher_spec function in OpenSSL 0.9.6c to 0.9.6k, and 0.9.7a to 0.9.7c, allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that triggers a null dereference. | |
| Modificada | Media (5) | 10% | — | Cisco Firewall Services ModuleHP AAA ServerHP Apache-based WEB ServerSymantec Clientless VPN Gateway 4400+61 | 23/11/2004 | 16/6/2026 | The SSL/TLS handshaking code in OpenSSL 0.9.7a, 0.9.7b, and 0.9.7c, when using Kerberos ciphersuites, does not properly check the length of Kerberos tickets during a handshake, which allows remote attackers to cause a denial of service (crash) via a crafted SSL/TLS handshake that causes an out-of-bounds read. |