Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3021▲ 414 respecto a la semana anterior
Críticas / altas1420▲ 180 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 169 respecto a la semana anterior
124 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 20% | ⚠ Explotación activa | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/9/2026 | 23/9/2026 | A directory traversal and file upload vulnerability allows an unauthenticated attacker to upload and execute arbitrary scripts on Check Point Management Server. | |
| Pendiente de análisis | Crítica (9.8) | 3.7% | — | Checkpoint Quantum Security ManagementAICheckpoint Quantum Security GatewayAI | 9/9/2026 | 10/9/2026 | A heap-based buffer overflow in VPN certificate ASN.1 decoding may allow an unauthenticated remote attacker to execute arbitrary code on Check Point Quantum Security Management and Quantum Security Gateway systems. | |
| Aplazada | Media (5.5) | 2.7% | — | Sangfor Operation AND Maintenance Security Management SystemAI | 3/8/2026 | 12/8/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.13. Affected by this vulnerability is the function com.sbr.fort.foreignDP.DpLoginController of the file /fort/portal_login of the component Login Endpoint. This manipulation causes os command injection. The attack… | |
| Pendiente de análisis | Crítica (9.3) | 0.89% | — | Checkpoint Security Management ServerAICheckpoint Multi Domain Security Management ServerAI | 3/8/2026 | 5/8/2026 | An authentication bypass vulnerability in Check Point Security Management Server and Multi-Domain Security Management Server (MDS) could allow an unauthenticated remote attacker with network access to Management services to execute arbitrary commands on the Security Management Server. Successful exploitation could… | |
| Pendiente de análisis | Crítica (9.1) | 1.0% | — | Checkpoint Security ManagementAICheckpoint Multi-domain Security ManagementAI | 22/7/2026 | 24/7/2026 | An authentication bypass vulnerability in Check Point Security Management and Multi-Domain Security Management allows an unauthenticated remote attacker to execute administrative commands on the Management Server. Successful exploitation may also allow command execution on managed Security Gateways. Exploitation… | |
| Analizada | Crítica (9.3) | 78% | ⚠ Explotación activa | Checkpoint Multi-domain Security ManagementCheckpoint Quantum Security Management | 22/7/2026 | 10/8/2026 | An authentication bypass vulnerability in the Check Point SmartConsole login process allows an unauthenticated remote attacker to obtain an application login token and use it to authenticate with full administrative privileges. Successful exploitation allows the attacker to modify security policies and security… | |
| Analizada | Baja (2.1) | 4.9% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This impacts the function getInformation of the file /equipment/get_Information of the component HTTP POST Request Handler. Executing a manipulation of the argument fortEquipmentIp can lead to command… | |
| Analizada | Baja (2.1) | 3.1% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability was found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function portValidate of the file /fort/ip_and_port/port_validate of the component HTTP POST Request Handler. Performing a manipulation of the argument port results in command injection. The attack… | |
| Analizada | Media (5.5) | 4.3% | — | Sangfor Operation AND Maintenance Security Management System | 26/1/2026 | 17/6/2026 | A vulnerability has been found in Sangfor Operation and Maintenance Security Management System up to 3.0.12. The impacted element is an unknown function of the file /fort/audit/get_clip_img of the component HTTP POST Request Handler. Such manipulation of the argument frame/dirno leads to command injection. It is… | |
| Analizada | Media (5.5) | 0.58% | — | Sangfor Operation AND Maintenance Security Management System | 22/1/2026 | 17/6/2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Security Management System up to 3.0.12. This affects the function edit_pwd_mall of the file /fort/login/edit_pwd_mall. The manipulation of the argument flag results in weak password recovery. It is possible to launch the attack remotely. The… | |
| Analizada | Alta (7.4) | 7.1% | — | Sangfor Operation AND Maintenance Security Management System | 22/1/2026 | 17/6/2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.12. Affected by this issue is the function SessionController of the file /isomp-protocol/protocol/session of the component SSH Protocol Handler. The manipulation of the argument keypassword leads to os command injection. It… | |
| Analizada | Media (5.5) | 2.1% | — | Sangfor Operation AND Maintenance Security Management System | 10/1/2026 | 17/6/2026 | A security flaw has been discovered in Sangfor Operation and Maintenance Management System up to 3.0.8. The impacted element is an unknown function of the file /fort/trust/version/common/common.jsp. Performing a manipulation of the argument File results in unrestricted upload. The attack is possible to be carried out… | |
| Analizada | Media (5.5) | 6.1% | — | Sangfor Operation AND Maintenance Security Management System | 10/1/2026 | 17/6/2026 | A vulnerability was identified in Sangfor Operation and Maintenance Management System up to 3.0.8. The affected element is the function SessionController of the file /isomp-protocol/protocol/session. Such manipulation of the argument Hostname leads to os command injection. The attack can be executed remotely. The… | |
| Analizada | Alta (8.9) | 7.0% | — | Sangfor Operation AND Maintenance Security Management System | 9/1/2026 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Management System up to 3.0.8. Impacted is the function WriterHandle.getCmd of the file /isomp-protocol/protocol/getCmd. This manipulation of the argument sessionPath causes os command injection. Remote exploitation of the attack is possible. The… | |
| Analizada | Baja (2.1) | 5.1% | — | Sangfor Operation AND Maintenance Security Management System | 9/11/2025 | 17/6/2026 | A vulnerability was determined in Sangfor Operation and Maintenance Security Management System 3.0. Impacted is an unknown function of the file /fort/portal_login of the component Frontend. This manipulation of the argument loginUrl causes command injection. The attack may be initiated remotely. The exploit has been… | |
| Analizada | Alta (7.8) | 0.14% | — | Dell EncryptionDell Security Management Server | 30/7/2025 | 17/6/2026 | Dell Encryption and Dell Security Management Server, versions prior to 11.11.0, contain an Improper Link Resolution Before File Access ('Link Following') Vulnerability. A local malicious user could potentially exploit this vulnerability, leading to privilege escalation. | |
| Aplazada | Crítica (10) | 19% | — | Hikvision Integrated Security Management PlatformAIAlibaba FastjsonAI | 2/7/2025 | 17/6/2026 | An unauthenticated remote command execution vulnerability exists in the applyCT component of the Hikvision Integrated Security Management Platform due to the use of a vulnerable version of the Fastjson library. The endpoint /bic/ssoService/v1/applyCT deserializes untrusted user input, allowing an attacker to trigger… | |
| Analizada | Alta (8.8) | 0.57% | — | Qianxin Tianqing Endpoint Security Management System | 21/4/2025 | 17/6/2026 | The quarantine - restore function in Qi-ANXIN Tianqing Endpoint Security Management System v10.0 allows user to restore a malicious file to an arbitrary file path. Attackers can write malicious DLL to system path and perform privilege escalation by leveraging Windows DLL hijacking vulnerabilities. | |
| Aplazada | Media (6.1) | 0.31% | — | Forcepoint Next Generation Firewall Security Management CenterAI | 4/3/2024 | 17/6/2026 | Forcepoint NGFW Security Management Center Management Server has SMC Downloads optional feature to offer standalone Management Client downloads and ECA configuration downloads. Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Forcepoint Next Generation Firewall… | |
| Modificada | Alta (7.8) | 0.09% | — | Dell EncryptionDell Endpoint Security Suite EnterpriseDell Security Management Server | 6/2/2024 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server versions prior to 11.9.0 contain privilege escalation vulnerability due to improper ACL of the non-default installation directory. A local malicious user could potentially exploit this vulnerability by replacing binaries in… | |
| Modificada | Alta (7.3) | 0.15% | — | Dell Endpoint Security Suite EnterpriseDell EncryptionDell Security Management Server | 16/11/2023 | 17/6/2026 | Dell Encryption, Dell Endpoint Security Suite Enterprise, and Dell Security Management Server version prior to 11.8.1 contain an Insecure Operation on Windows Junction Vulnerability during installation. A local malicious user could potentially exploit this vulnerability to create an arbitrary folder inside a… | |
| Modificada | Media (4.4) | 0.20% | — | Intel Converged Security Management Engine Firmware | 11/8/2023 | 17/6/2026 | Improper Input validation in firmware for some Intel(R) Converged Security and Management Engine before versions 15.0.45, and 16.1.27 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.5) | 0.66% | — | Intel Converged Security Management Engine Firmware | 11/8/2023 | 17/6/2026 | Improper input validation in some firmware for Intel(R) AMT and Intel(R) Standard Manageability before versions 11.8.94, 11.12.94, 11.22.94, 12.0.93, 14.1.70, 15.0.45, and 16.1.27 in Intel (R) CSME may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Converged Security Management Engine Firmware | 11/8/2023 | 17/6/2026 | Improper access control in the Intel(R) CSME software installer before version 2239.3.7.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.25% | — | Microfocus Zenworks Configuration ManagementMicrofocus Zenworks Endpoint Security Management | 30/7/2021 | 17/6/2026 | A privileged escalation vulnerability has been identified in Micro Focus ZENworks Configuration Management, affecting version 2020 Update 1 and all prior versions. The vulnerability could be exploited to gain unauthorized system privileges. |