Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▲ 36 respecto a la semana anterior
Críticas / altas1474▲ 366 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 464 respecto a la semana anterior
38 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.21% | — | ASR CraneAICrowdstrike FalconAI | 23/9/2026 | 23/9/2026 | NULL pointer dereference vulnerability in ASR Crane,Falcon on Linux (as_rrc module) allows Pointer Manipulation. This vulnerability is associated with program file 3g.mod/lib/src/urrsir.c. | |
| Pendiente de análisis | Alta (8.8) | 0.08% | — | Crowdstrike Falcon SensorAICrowdstrike Laroux Malware Cleanup ToolAIMicrosoft OfficeAI | 15/9/2026 | 18/9/2026 | CrowdStrike released a security update to address a vulnerability in the Falcon sensor for Windows. The vulnerability only exists when the Microsoft Office File Malicious Macro Removal Windows policy setting is enabled and customers remain protected through the Cloud Anti-malware for Microsoft Office Files settings.… | |
| Aplazada | Alta (7.5) | 0.46% | — | FalconAI | 27/7/2026 | 27/7/2026 | Unauthenticated Unknown in Falcon – WordPress Optimizations & Tweaks <= 2.10.0 versions. | |
| Aplazada | Media (6.5) | 0.17% | — | Crowdstrike Falcon Sensor FOR WindowsAI | 8/10/2025 | 17/6/2026 | A logic error exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There is… | |
| Aplazada | Media (5.6) | 0.12% | — | Crowdstrike Falcon SensorAI | 8/10/2025 | 17/6/2026 | A race condition exists in the Falcon sensor for Windows that could allow an attacker, with the prior ability to execute code on a host, to delete arbitrary files. CrowdStrike released a security fix for this issue in Falcon sensor for Windows versions 7.24 and above and all Long Term Visibility (LTV) sensors. There… | |
| Analizada | Media (5.4) | 0.29% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure. This vulnerability is associated with program files tr069/tr069_uci.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Analizada | Media (5.4) | 0.29% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in tr069 modules allows Resource Leak Exposure. This vulnerability is associated with program files tr069/tr098.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Analizada | Media (5.3) | 0.28% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router modules allows Resource Leak Exposure. This vulnerability is associated with program files router/phonebook/pbwork-queue.C. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Analizada | Crítica (9.1) | 0.29% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Out-of-bounds access in ASR180x 、ASR190x in lte-telephony, This vulnerability is associated with program files apps/lzma/src/LzmaEnc.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Analizada | Crítica (9.8) | 0.30% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Out-of-bounds write in ASR180x in lte-telephony, May cause a buffer underrun. This vulnerability is associated with program files apps/atcmd_server/src/dev_api.C. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Analizada | Media (5.3) | 0.28% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Improper Resource Shutdown or Release vulnerability in ASR Falcon_Linux、Kestrel、Lapwing_Linux on Linux (traffic_stat modules) allows Resource Leak Exposure. This vulnerability is associated with program files traffic_stat/traffic_service/traffic_service.C. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before… | |
| Analizada | Media (5.3) | 0.28% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Improper Resource Shutdown or Release vulnerability in ASR180x 、ASR190x in router components allows Resource Leak Exposure. This vulnerability is associated with program files router/phonebook/pb.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Analizada | Media (5.3) | 0.28% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Resource leak vulnerability in ASR180x in router allows Resource Leak Exposure. This vulnerability is associated with program files router/sms/sms.c. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Analizada | Media (5.3) | 0.28% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Improper Resource Shutdown or Release vulnerability in ASR Falcon_Linux、Kestrel、Lapwing_Linux on Linux (con_mgr components) allows Resource Leak Exposure. This vulnerability is associated with program files con_mgr/dialer_task.C. This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Analizada | Media (5.3) | 0.28% | — | Asrmicro Falcon LinuxAsrmicro KestrelAsrmicro Lapwing Linux | 1/7/2025 | 17/6/2026 | Resource leak vulnerability in ASR180x、ASR190x in con_mgr allows Resource Leak Exposure.This issue affects Falcon_Linux、Kestrel、Lapwing_Linux: before v1536. | |
| Aplazada | Media (5.9) | 0.23% | — | Falcon Solutions Duplicate Page AND PostAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Falcon Solutions Duplicate Page and Post duplicate-post-and-page allows Stored XSS.This issue affects Duplicate Page and Post: from n/a through <= 1.0. | |
| Aplazada | Alta (8.5) | 0.34% | — | Falcon Solutions Duplicate Page AND PostAI | 28/3/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Falcon Solutions Duplicate Page and Post duplicate-post-and-page allows Blind SQL Injection.This issue affects Duplicate Page and Post: from n/a through <= 1.0. | |
| Aplazada | Alta (8.1) | 0.26% | — | Crowdstrike Falcon Sensor FOR LinuxAICrowdstrike Falcon Kubernetes Admission ControllerAICrowdstrike Falcon Container SensorAI | 12/2/2025 | 17/6/2026 | CrowdStrike uses industry-standard TLS (transport layer security) to secure communications from the Falcon sensor to the CrowdStrike cloud. CrowdStrike has identified a validation logic error in the Falcon sensor for Linux, Falcon Kubernetes Admission Controller, and Falcon Container Sensor where our TLS connection… | |
| Aplazada | Alta (7.1) | 0.30% | — | Falcontheme Team WP Block PackAI | 22/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in FalconTheme Team WP Block Pack wp-block-pack allows Reflected XSS.This issue affects WP Block Pack: from n/a through <= 1.1.6. | |
| Aplazada | Media (4.3) | 0.43% | — | ANH Tran Falcon Wordpress Optimizations TweaksAI | 16/12/2024 | 17/6/2026 | Missing Authorization vulnerability in Anh Tran Falcon – WordPress Optimizations & Tweaks falcon allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Falcon – WordPress Optimizations & Tweaks: from n/a through <= 2.8.3. | |
| Modificada | Crítica (9.8) | 1.2% | — | Open-falcon Dashboard | 11/8/2023 | 17/6/2026 | An issue was discovered in open-falcon dashboard version 0.2.0, allows remote attackers to gain, modify, and delete sensitive information via crafted POST request to register interface. | |
| Modificada | Baja (2.7) | 4.9% | — | Crowdstrike Falcon | 22/8/2022 | 17/6/2026 | A vulnerability was found in CrowdStrike Falcon 6.31.14505.0/6.42.15610/6.44.15806. It has been classified as problematic. Affected is an unknown function of the component Uninstallation Handler. The manipulation leads to missing authorization. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Crítica (9.8) | 15% | — | Open-falcon Falcon-plus | 27/3/2022 | 17/6/2026 | Falcon-plus v0.3 was discovered to contain a SQL injection vulnerability via the parameter grpName in /config/service/host.go. | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Falcon 8+ UAS Asctec Thermal Viewer Firmware | 12/11/2020 | 17/6/2026 | Improper permissions in the installer for the Intel(R) Falcon 8+ UAS AscTec Thermal Viewer, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 1.6% | — | Falconpl | 19/11/2019 | 16/6/2026 | Falconpl before 0.9.6.9-git20120606 misuses the libcurl API which may allow remote attackers to interfere with security checks. |