Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

111 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.4)0.38%—Openvpn Connect26/5/202623/7/2026
Privilege escalation via background service of OpenVPN Connect 3.5.1 through 3.8.1 on macOS allows attackers to execute arbitrary commands with elevated privileges via local IPC channel
AplazadaCrítica (10)0.58%—Openvpn-auth-oauth2AI8/5/202617/6/2026
openvpn-auth-oauth2 is a plugin/management interface client for OpenVPN server to handle an OIDC based single sign-on (SSO) auth flows. From version 1.26.3 to before version 1.27.3, when openvpn-auth-oauth2 is deployed in the experimental plugin mode (shared library loaded by OpenVPN via the plugin directive), clients…
Pendiente de análisisMedia (6.5)0.19%—Mikrotik RouterosAIOpenvpnAIMikrotik CapsmanAI5/5/202630/9/2026
RouterOS provides various services that rely on correct verification of client and server certificates to secure confidentiality and integrity of communications. This includes OpenVPN, CAPsMAN, Dot1x (802.1X), among others. The vulnerability lies in shared certificate validation logic which uses the system certificate…
Pendiente de análisisAlta (7.2)0.73%—Wago PLCAIOpenvpnAI9/4/202617/6/2026
An authenticated remote attacker with high privileges can exploit the OpenVPN configuration via the web-based management interface of a WAGO PLC. If user-defined scripts are permitted, OpenVPN may allow the execution of arbitrary shell commands enabling the attacker to run arbitrary commands on the device.
AplazadaBaja (3.8)0.36%—OpenvpnAI30/1/202617/6/2026
Insufficient epoch key slot processing in OpenVPN 2.7_alpha1 through 2.7_rc5 allows remote authenticated users to trigger an assert resulting in a denial of service
AnalizadaMedia (4.6)0.64%—Openvpn3/12/202525/9/2026
Improper validation of source IP addresses in OpenVPN version 2.6.0 through 2.6.15 and 2.7_alpha1 through 2.7_rc1 allows an attacker to open a session from a different IP address which did not initiate the connection resulting in a denial of service for the originating client
AnalizadaBaja (1.3)0.17%—Openvpn3/12/202517/6/2026
Interactive service agent in OpenVPN version 2.5.0 through 2.6.16 and 2.7_alpha1 through 2.7_rc2 on Windows allows a local authenticated user to connect to the service and trigger an error causing a local denial of service.
AnalizadaCrítica (9.1)0.56%—Openvpn1/12/202525/9/2026
Insufficient argument validation in OpenVPN 2.7_alpha1 through 2.7_rc1 allows an attacker to trigger a heap buffer over-read when parsing IP addresses
AplazadaMedia (6.4)0.21%—Openvpn Access ServerAI27/10/202517/6/2026
Cross-site scripting (XSS) vulnerability in the SAML Authentication module in OpenVPN Access Server version 2.14.0 through 2.14.3 allows configured remote SAML Assertion Consumer Service (ACS) endpoint servers to inject arbitrary web script or HTML via the RelayState parameter
AplazadaAlta (8.8)7.3%—OpenvpnAI24/10/202517/6/2026
OpenVPN 2.7_alpha1 through 2.7_beta1 on POSIX based platforms allows a remote authenticated server to inject shell commands via DNS variables when --dns-updown is in use
AplazadaMedia (6.8)0.35%—OpenvpnAIL2tpAIUI Unifi NetworkAI29/6/202517/6/2026
A misconfigured query in UniFi Network (v9.1.120 and earlier) could allow users to authenticate to Enterprise WiFi or VPN Server (l2tp and OpenVPN) using a device’s MAC address from 802.1X or MAC Authentication, if both services are enabled and share the same RADIUS profile.
AnalizadaMedia (5.5)0.73%—Xiaoyunjie Openvpn-cms-flask27/6/202517/6/2026
A vulnerability classified as critical was found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This vulnerability affects the function Upload of the file app/plugins/oss/app/controller.py of the component File Upload. The manipulation of the argument image leads to path traversal. The attack can be initiated remotely.…
AnalizadaBaja (2.1)3.1%—Xiaoyunjie Openvpn-cms-flask27/6/202517/6/2026
A vulnerability classified as critical has been found in xiaoyunjie openvpn-cms-flask up to 1.2.7. This affects the function create_user of the file /app/api/v1/openvpn.py of the component User Creation Endpoint. The manipulation of the argument Username leads to command injection. It is possible to initiate the…
AnalizadaMedia (5.5)0.24%—Openvpn Ovpn-dco-win20/6/202517/6/2026
Buffer overflow in OpenVPN ovpn-dco-win version 1.3.0 and earlier and version 2.5.8 and earlier allows a local user process to send a too large control message buffer to the kernel driver resulting in a system crash
AnalizadaMedia (6.2)0.21%—Openvpn3linux19/5/202517/6/2026
The configuration initialization tool in OpenVPN 3 Linux v20 through v24 on Linux allows a local attacker to use symlinks pointing at an arbitrary directory which will change the ownership and permissions of that destination directory.
AnalizadaAlta (8.8)0.43%—Openvpn3/4/202517/6/2026
OpenVPN version 2.4.0 through 2.6.10 on Windows allows an external, lesser privileged process to create a named pipe which the OpenVPN GUI component would connect to allowing it to escalate its privileges
ModificadaAlta (7.5)0.83%—Openvpn2/4/202517/6/2026
OpenVPN version 2.6.1 through 2.6.13 in server mode using TLS-crypt-v2 allows remote attackers to trigger a denial of service by corrupting and replaying network packets in the early handshake phase
AnalizadaMedia (5.3)0.08%—Openvpn Easy-rsa20/1/202517/6/2026
Weak encryption algorithm in Easy-RSA version 3.0.5 through 3.1.7 allows a local attacker to more easily bruteforce the private CA key when created using OpenSSL 3
AnalizadaBaja (3.3)0.14%—Openvpn Ovpn-dco-win15/1/202517/6/2026
OpenVPN ovpn-dco for Windows version 1.1.1 allows an unprivileged local attacker to send I/O control messages with invalid data to the driver resulting in a NULL pointer dereference leading to a system halt.
AnalizadaAlta (7.5)0.55%—Openvpn Connect6/1/202517/6/2026
OpenVPN Connect before version 3.5.0 can contain the configuration profile's clear-text private key which is logged in the application log, which an unauthorized actor can use to decrypt the VPN traffic
ModificadaCrítica (9.1)0.83%—Openvpn6/1/202517/6/2026
OpenVPN before 2.6.11 does not santize PUSH_REPLY messages properly which an attacker controlling the server can use to inject unexpected arbitrary data ending up in client logs.
AnalizadaMedia (4.3)0.66%—Openvpn8/7/202417/6/2026
OpenVPN from 2.6.0 through 2.6.10 in a server role accepts multiple exit notifications from authenticated clients which will extend the validity of a closing session
AnalizadaCrítica (9.8)15%—Openvpn Tap-windows68/7/202417/6/2026
tap-windows6 driver version 9.26 and earlier does not properly check the size data of incomming write operations which an attacker can use to overflow memory buffers, resulting in a bug check and potentially arbitrary code execution in kernel space
ModificadaCrítica (9.8)8.9%—Openvpn8/7/202417/6/2026
OpenVPN plug-ins on Windows with OpenVPN 2.6.9 and earlier could be loaded from any directory, which allows an attacker to load an arbitrary plug-in which can be used to interact with the privileged OpenVPN interactive service.
ModificadaAlta (7.8)8.3%—Openvpn8/7/202417/6/2026
The interactive service in OpenVPN 2.6.9 and earlier allows an attacker to send data causing a stack overflow which can be used to execute arbitrary code with more privileges.