Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2610▼ 308 respecto a la semana anterior
Críticas / altas1345▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
43 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.4) | 0.23% | — | Daggerhartlab Openid Connect Generic ClientAI | 18/12/2025 | 17/6/2026 | The OpenID Connect Generic Client plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'openid_connect_generic_auth_url' shortcode in all versions up to, and including, 3.10.0 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers,… | |
| Aplazada | Media (6.9) | 0.16% | — | SAP Hana Jdbc ClientAI | 11/11/2025 | 17/6/2026 | Due to insufficient validation of connection property values, the SAP HANA JDBC Client allows a high-privilege locally authenticated user to supply crafted parameters that lead to unauthorized code loading, resulting in low impact on confidentiality and integrity and high impact on availability of the application. | |
| Aplazada | Media (6.8) | 0.31% | — | Kubernetes C ClientAI | 16/9/2025 | 17/6/2026 | A vulnerability exists in the Kubernetes C# client where the certificate validation logic accepts properly constructed certificates from any Certificate Authority (CA) without properly verifying the trust chain. This flaw allows a malicious actor to present a forged certificate and potentially intercept or manipulate… | |
| Aplazada | Baja (2) | 0.12% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.7.0 contains an issue with use of less trusted source, which may allow an attacker who can conduct a man-in-the-middle attack to eavesdrop upgrade requests and execute a malicious DLL with custom code. | |
| Aplazada | Crítica (9.3) | 0.88% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | Path traversal vulnerability exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is running by tampering with specific files used on the product. | |
| Aplazada | Media (6.9) | 0.42% | — | Ricoh Streamline NX V3 PC ClientAI | 13/6/2025 | 17/6/2026 | External control of file name or path issue exists in RICOH Streamline NX V3 PC Client versions 3.5.0 to 3.242.0. If an attacker sends a specially crafted request, arbitrary files in the file system can be overwritten with log data. | |
| Aplazada | Media (4.2) | 0.24% | — | Redhat Single Sign ONAIRedhat Jboss Enterprise Application PlatformAIRedhat Oidc ClientAI | 9/12/2024 | 4/8/2026 | A vulnerability was found in OIDC-Client. When using the RH SSO OIDC adapter with EAP 7.x or when using the elytron-oidc-client subsystem with EAP 8.x, authorization code injection attacks can occur, allowing an attacker to inject a stolen authorization code into the attacker's own session with the client with a… | |
| Aplazada | Media (4) | 0.16% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, files in the PC where the product is installed may be altered. | |
| Aplazada | Crítica (9.8) | 0.51% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of potentially dangerous function issue exists in Ricoh Streamline NX PC Client. If this vulnerability is exploited, an attacker may create an arbitrary file in the PC where the product is installed. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Use of hard-coded credentials issue exists in Ricoh Streamline NX PC Client ver.3.7.2 and earlier. If this vulnerability is exploited, an attacker may obtain LocalSystem Account of the PC where the product is installed. As a result, unintended operations may be performed on the PC. | |
| Aplazada | Media (6.3) | 0.22% | — | Ricoh Streamline NX PC ClientAI | 19/6/2024 | 17/6/2026 | Improper restriction of communication channel to intended endpoints issue exists in Ricoh Streamline NX PC Client ver.3.6.x and earlier. If this vulnerability is exploited, arbitrary code may be executed on the PC where the product is installed. | |
| Modificada | Crítica (9.9) | 0.95% | — | Vasion Printerlogic Client | 25/7/2023 | 17/6/2026 | An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.836. During client installation and repair, a PrinterLogic binary is called by the installer to configure the device. This window is not hidden, and is running with elevated privileges. A standard user can break out of this window,… | |
| Modificada | Crítica (9.9) | 1.1% | — | Vasion Printerlogic Client | 25/7/2023 | 17/6/2026 | An issue was discovered in Vasion PrinterLogic Client for Windows before 25.0.0.818. During installation, binaries gets executed out of a subfolder in C:\Windows\Temp. A standard user can create the folder and path file ahead of time and obtain elevated code execution. | |
| Modificada | Alta (7.4) | 0.63% | — | Python-scciclient Project Python-scciclientDebian Linux | 1/9/2022 | 17/6/2026 | A flaw was found in the python-scciclient when making an HTTPS connection to a server where the server's certificate would not be verified. This issue opens up the connection to possible Man-in-the-middle (MITM) attacks. | |
| Modificada | Alta (7.8) | 0.58% | — | Druva Insync Client | 12/7/2022 | 9/7/2026 | URL injection in Driva inSync 6.9.0 for MacOS, allows attackers to force a visit to an arbitrary url via the port parameter to the Electron App. | |
| Modificada | Alta (7.8) | 2.7% | — | Druva Insync Client | 12/7/2022 | 9/7/2026 | Command injection vulnerability in Druva inSync 6.9.0 for MacOS, allows attackers to execute arbitrary commands via crafted payload to the local HTTP server due to un-sanitized call to the python os.system library. | |
| Modificada | Alta (7.8) | 0.46% | — | Druva Insync Client | 12/7/2022 | 9/7/2026 | An issue was discovered in Druva 6.9.0 for MacOS, allows attackers to gain escalated local privileges via the inSyncDecommission. | |
| Modificada | Alta (7.8) | 0.51% | — | Druva Insync Client | 12/7/2022 | 9/7/2026 | An issue was discovered in Druva 6.9.0 for macOS, allows attackers to gain escalated local privileges via the inSyncUpgradeDaemon. | |
| Modificada | Media (6.1) | 1.6% | — | Daggerhartlab Openid Connect Generic Client | 6/5/2021 | 17/6/2026 | The OpenID Connect Generic Client WordPress plugin 3.8.0 and 3.8.1 did not sanitise the login error when output back in the login form, leading to a reflected Cross-Site Scripting issue. This issue does not require authentication and can be exploited with the default configuration. | |
| Modificada | Alta (7.8) | 0.31% | — | Ricoh Streamline NX Client ToolRicoh Streamline NX PC Client | 4/8/2020 | 17/6/2026 | An issue was discovered in RICOH Streamline NX Client Tool and RICOH Streamline NX PC Client that allows attackers to escalate local privileges. | |
| Modificada | Alta (7.8) | 8.6% | — | Druva Insync Client | 21/5/2020 | 17/6/2026 | Relative path traversal in Druva inSync Windows Client 6.6.3 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges. | |
| Modificada | Alta (7.8) | 8.6% | — | Druva Insync Client | 25/2/2020 | 17/6/2026 | Improper neutralization of special elements used in an OS command in Druva inSync Windows Client 6.5.0 allows a local, unauthenticated attacker to execute arbitrary operating system commands with SYSTEM privileges. | |
| Modificada | Crítica (9.8) | 2.0% | — | Universityofcalifornia Boinc Client | 20/2/2020 | 16/6/2026 | Multiple SQL injection vulnerabilities in BOINC allow remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (8.1) | 0.61% | — | Ncp-e NCP Secure Entry ClientSophos Ipsec Client | 9/4/2019 | 17/6/2026 | The Sophos UTM VPN endpoint interacts with client software provided by NPC Engineering (www.ncp-e.com). The affected client software, "Sophos IPSec Client" 11.04 is a rebranded version of NCP "Secure Entry Client" 10.11 r32792. A vulnerability in the software update feature of the VPN client allows a man-in-the-middle… | |
| Modificada | Media (5) | 4.4% | — | Universityofcalifornia Boinc Client | 2/6/2014 | 17/6/2026 | Format string vulnerability in the PROJECT::write_account_file function in client/cs_account.cpp in BOINC, possibly 7.2.33, allows remote attackers to cause a denial of service (crash) or possibly execute arbitrary code via format string specifiers in the gui_urls item in an account file. |