Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2538▼ 392 respecto a la semana anterior
Críticas / altas1301▲ 22 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
48 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.54% | — | Logto TunnelAI | 19/8/2026 | 9/9/2026 | Logto is the modern, open-source auth infrastructure for SaaS and AI apps. Prior to 0.3.9, the Logto Tunnel npm package enabled createStaticFileProxy from packages/tunnel/src/commands/tunnel/index.ts and passed request.url from static asset requests through packages/tunnel/src/commands/tunnel/utils.ts using… | |
| Pendiente de análisis | Alta (7.6) | 0.19% | — | RsyncAIRsync-sslAIOpensslAIStunnelAI | 13/8/2026 | 8/9/2026 | rsync 3.2.0 through 3.2.3 (openssl mode) and rsync-ssl through 3.4.4 (stunnel mode) contain a TLS certificate validation vulnerability that allows on-path attackers to intercept encrypted sessions by presenting self-signed or otherwise invalid certificates. Attackers can exploit the failure to validate server TLS… | |
| Pendiente de análisis | Media (6.5) | 0.44% | — | StunnelAI | 4/8/2026 | 6/8/2026 | A stack-based out-of-bounds read vulnerability exists in the "s_vlog" function of stunnel, when handling oversized log messages via "vsnprintf". A remote attacker with network access to a stunnel service can send protocol inputs that trigger a log message longer than 1024 bytes, leading to an out-of-bounds stack read… | |
| Pendiente de análisis | Media (5.4) | 0.26% | — | StunnelAI | 4/8/2026 | 6/8/2026 | A Server-Side Request Forgery (SSRF) bypass vulnerability exists in “stunnel” 5.79 and lower when configured in SOCKS proxy mode. This flaw allows a client to bypass intended localhost restrictions by using IPv4-mapped IPv6 addresses (e.g., “::ffff:127.0.0.1”) or unspecified addresses ("0.0.0.0", "::"), enabling… | |
| Analizada | Alta (7.8) | 0.18% | — | Omnissa Workspace ONE Tunnel | 8/7/2026 | 10/7/2026 | Omnissa Workspace ONE® Tunnel for Windows addresses a Local Privilege Escalation Vulnerability. | |
| Analizada | Media (6.8) | 0.19% | — | Tunnelblick | 5/5/2026 | 25/7/2026 | Tunnelblick is an open source graphic user interface for OpenVPN on macOS. In versions 3.3beta26 through 9.0beta01, any local user can read arbitrary root-owned files by exploiting a symlink following vulnerability in tunnelblick-helper, reachable through the world-accessible tunnelblickd Unix socket. The socket is… | |
| Analizada | Media (5.3) | 0.29% | — | Adguard Trusttunnel | 29/1/2026 | 17/6/2026 | TrustTunnel is an open-source VPN protocol with a rule bypass issue in versions prior to 0.9.115. In `tls_listener.rs`, `TlsListener::listen()` peeks 1024 bytes and calls `extract_client_random(...)`. If `parse_tls_plaintext` fails (for example, a fragmented/partial ClientHello split across TCP writes),… | |
| Analizada | Alta (7.1) | 0.26% | — | Adguard Trusttunnel | 29/1/2026 | 17/6/2026 | TrustTunnel is an open-source VPN protocol with a server-side request forgery and and private network restriction bypass in versions prior to 0.9.114. In `tcp_forwarder.rs`, SSRF protection for `allow_private_network_connections = false` was only applied in the `TcpDestination::HostName(peer)` path. The… | |
| Aplazada | Alta (8.1) | 0.18% | — | TunnelblickAI | 5/7/2025 | 17/6/2026 | Tunnelblick 3.5beta06 before 7.0, when incompletely uninstalled, allows attackers to execute arbitrary code as root (upon the next boot) by dragging a crafted Tunnelblick.app file into /Applications. | |
| Analizada | Media (6.5) | 1.2% | — | Apache Seatunnel | 19/6/2025 | 17/6/2026 | # Summary Unauthorized users can perform Arbitrary File Read and Deserialization attack by submit job using restful api-v1. # Details Unauthorized users can access `/hazelcast/rest/maps/submit-job` to submit job. An attacker can set extra params in mysql url to perform Arbitrary File Read and Deserialization attack.… | |
| Aplazada | Media (6.1) | 0.35% | — | Sonicwall Connect TunnelAI | 16/4/2025 | 17/6/2026 | A Improper Link Resolution vulnerability (CWE-59) in the SonicWall Connect Tunnel Windows (32 and 64 bit) client, this results in unauthorized file overwrite, potentially leading to denial of service or file corruption. | |
| Aplazada | Alta (7.8) | 0.26% | — | Sonicwall Connect TunnelAI | 11/10/2024 | 17/6/2026 | The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to delete arbitrary folders and files, potentially leading to local privilege escalation attack. | |
| Aplazada | Media (5.5) | 0.23% | — | Sonicwall Connect TunnelAI | 11/10/2024 | 17/6/2026 | The Improper link resolution before file access ('Link Following') vulnerability in SonicWall Connect Tunnel (version 12.4.3.271 and earlier of Windows client) allows users with standard privileges to create arbitrary folders and files, potentially leading to local Denial of Service (DoS) attack. | |
| Modificada | Alta (7.5) | 0.93% | — | Apache Seatunnel | 21/8/2024 | 17/6/2026 | Mysql security vulnerability in Apache SeaTunnel. Attackers can read files on the MySQL server by modifying the information in the MySQL URL allowLoadLocalInfile=true&allowUrlInLocalInfile=true&allowLoadLocalInfileInPath=/&maxAllowedPacket=655360 This issue affects Apache SeaTunnel: 1.0.0. Users are recommended to… | |
| Analizada | Crítica (9.1) | 0.72% | — | Apache Seatunnel | 30/7/2024 | 17/6/2026 | Web Authentication vulnerability in Apache SeaTunnel. Since the jwt key is hardcoded in the application, an attacker can forge any token to log in any user. Attacker can get secret key in /seatunnel-server/seatunnel-app/src/main/resources/application.yml and then create a token. This issue affects Apache SeaTunnel:… | |
| Modificada | Media (5.9) | 0.57% | — | GO Simple Tunnel Project GO Simple Tunnel | 30/5/2023 | 17/6/2026 | gost (GO Simple Tunnel) is a simple tunnel written in golang. Sensitive secrets such as passwords, token and API keys should be compared only using a constant-time comparison function. Untrusted input, sourced from a HTTP header, is compared directly with a secret. Since this comparison is not secure, an attacker can… | |
| Modificada | Media (5.5) | 0.18% | — | Linux Layer 2 Tunneling ProtocolFedoraproject Fedora | 28/11/2022 | 17/6/2026 | A flaw was found in the Linux kernel's Layer 2 Tunneling Protocol (L2TP). A missing lock when clearing sk_user_data can lead to a race condition and NULL pointer dereference. A local user could use this flaw to potentially crash the system causing a denial of service. | |
| Modificada | Alta (7.8) | 0.36% | — | Openvpn Private Tunnel | 26/5/2021 | 17/6/2026 | Private Tunnel installer for macOS version 3.0.1 and older versions may corrupt system critical files it should not have access via symlinks in /tmp. | |
| Modificada | Alta (7.5) | 1.2% | — | Stunnel | 23/2/2021 | 17/6/2026 | A flaw was found in stunnel before 5.57, where it improperly validates client certificates when it is configured to use both redirect and verifyChain options. This flaw allows an attacker with a certificate signed by a Certificate Authority, which is not the one accepted by the stunnel server, to access the tunneled… | |
| Modificada | Alta (7.5) | 1.5% | — | Honeywell OPC UA Tunneller | 26/1/2021 | 17/6/2026 | The affected product has uncontrolled resource consumption issues, which may allow an attacker to cause a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233). | |
| Modificada | Crítica (9.1) | 1.7% | — | Honeywell OPC UA Tunneller | 26/1/2021 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds read, which may allow an attacker to obtain and disclose sensitive data information or cause the device to crash on the OPC UA Tunneller (versions prior to 6.3.0.8233). | |
| Modificada | Crítica (9.8) | 2.4% | — | Honeywell OPC UA Tunneller | 26/1/2021 | 17/6/2026 | The affected product is vulnerable to a heap-based buffer overflow, which may allow an attacker to manipulate memory with controlled values and remotely execute code on the OPC UA Tunneller (versions prior to 6.3.0.8233). | |
| Modificada | Alta (7.5) | 1.1% | — | Honeywell OPC UA Tunneller | 26/1/2021 | 17/6/2026 | Some parsing functions in the affected product do not check the return value of malloc and the thread handling the message is forced to close, which may lead to a denial-of-service condition on the OPC UA Tunneller (versions prior to 6.3.0.8233). | |
| Modificada | Crítica (9.8) | 3.8% | — | Mcafee Tunnelbear | 26/4/2018 | 17/6/2026 | TunnelBear 3.2.0.6 for Windows suffers from a SYSTEM privilege escalation vulnerability through the "TunnelBearMaintenance" service. This service establishes a NetNamedPipe endpoint that allows arbitrary installed applications to connect and call publicly exposed methods. The "OpenVPNConnect" method accepts a server… | |
| Modificada | Alta (7.8) | 0.38% | — | Privatetunnel | 26/4/2017 | 17/6/2026 | Buffer overflow in PrivateTunnel 2.7 and 2.8 allows local attackers to cause a denial of service (SEH overwrite) or possibly have unspecified other impact via a long password. |