Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

495 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.24%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS14/2/202417/6/2026
In Dell SupportAssist for Home PCs (between v3.0 and v3.14.1) and SupportAssist for Business PCs (between v3.0 and v3.4.1), a security concern has been identified, impacting locally authenticated users on their respective PCs. This issue may potentially enable privilege escalation and the execution of arbitrary code,…
ModificadaMedia (5.3)0.32%—Dell Supportassist FOR Home PCS14/2/202417/6/2026
Dell SupportAssist for Business PCs version 3.4.0 contains a local Authentication Bypass vulnerability that allows locally authenticated non-admin users to gain temporary privilege within the SupportAssist User Interface on their respective PC. The Run as Admin temporary privilege feature enables IT/System…
ModificadaMedia (6.5)0.20%—Dell Supportassist FOR Home PCS14/2/202417/6/2026
Dell SupportAssist for Home PCs Installer Executable file version prior to 3.13.2.19 used for initial installation has a high vulnerability that can result in local privilege escalation (LPE). This vulnerability only affects first-time installations done prior to 8th March 2023
ModificadaCrítica (9.8)0.70%—Mitel Unify Openscape Xpressions Webassistant8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
ModificadaAlta (8.8)0.92%—Mitel Unify Openscape Xpressions Webassistant8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
ModificadaAlta (8.8)1.4%💥 PoC10web AI Assistant5/2/202417/6/2026
The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin AJAX action in all versions up to, and including, 1.0.18. This makes it possible for authenticated attackers, with subscriber-level…
ModificadaAlta (8.8)1.1%💥 PoCBarassistant BAR Assistant10/1/202417/6/2026
Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code.
ModificadaMedia (4.8)0.33%—Bitapps BIT Assist29/12/202317/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Bit Assist Chat Widget: WhatsApp Chat, Facebook Messenger Chat, Telegram Chat Bubble, Line Messenger, Live Chat Support Chat Button, WeChat, SMS, Call Button, Customer Support Button with floating Chat Widget allows…
ModificadaAlta (7.8)0.24%—Dell Supportassist FOR Home PCS22/12/202317/6/2026
Dell SupportAssist for Home PCs version 3.14.1 and prior versions contain a privilege escalation vulnerability in the installer. A local low privileged authenticated attacker may potentially exploit this vulnerability, leading to the execution of arbitrary executable on the operating system with elevated privileges.
ModificadaMedia (5.9)0.56%—Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+1018/12/202317/6/2026
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
ModificadaMedia (4.3)0.91%—Home-assistant15/12/202317/6/2026
Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch for this issue. When starting the Home Assistant 2023.12 release, the…
ModificadaMedia (6.5)1.0%—Gladysassistant Gladys Assistant7/12/202317/6/2026
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
ModificadaAlta (8.8)0.31%—Intel Quickassist Technology14/11/202317/6/2026
Improper input validation in firmware for Intel(R) QAT before version QAT20.L.1.0.40-00004 may allow escalation of privilege and denial of service via adjacent access.
ModificadaAlta (7.8)0.21%—Intel Quickassist Technology LibraryIntel Quickassist Technology14/11/202317/6/2026
Buffer overflow in some Intel(R) QAT drivers for Windows - HW Version 1.0 before version 1.10 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel Quickassist Technology LibraryIntel Quickassist Technology14/11/202317/6/2026
Uncontrolled search path element in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.20%—Intel Quickassist Technology LibraryIntel Quickassist Technology Firmware14/11/202317/6/2026
Improper authorization in some Intel(R) QAT drivers for Windows - HW Version 2.0 before version 2.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaBaja (2.3)0.21%—Intel Quickassist Technology LibraryIntel Quickassist Technology Driver FirmwareIntel QAT Driver Firmware14/11/202317/6/2026
Improper buffer restrictions in some Intel(R) QAT Library software before version 22.07.1 may allow a privileged user to potentially enable information disclosure via local access.
ModificadaAlta (8.8)0.39%—Wpindeed Debug Assistant13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
ModificadaAlta (8.8)0.33%—Ifeelweb Affiliate Super Assistent12/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Timo Reith Affiliate Super Assistent plugin <= 1.5.1 versions.
ModificadaAlta (7.8)0.17%—HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware31/10/202317/6/2026
Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.
ModificadaAlta (8.8)0.69%—Fastlinemedia Assistant26/10/202317/6/2026
The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to perform SSRF attacks
ModificadaMedia (5.3)0.42%—Home-assistant20/10/202317/6/2026
Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessible from the local network. This issue is facilitated by the SniTun proxy, which…
ModificadaMedia (5.4)0.40%—Home-assistant20/10/202317/6/2026
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication will be sent to the URL specified in the aforementioned parameters.…
ModificadaAlta (8.8)0.28%—Home-assistant Home Assistant Companion19/10/202317/6/2026
The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when visited, will make the victim to call arbitrary services in their Home Assistant installation. Combined with this security advisory, may…
ModificadaAlta (7.2)0.46%—Home-assistant19/10/202317/6/2026
Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able to invoke any Supervisor REST API endpoints with a POST request. An…
Orbitaley — Vulnerabilidades