Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.5% | — | Microsoft Windows Upgrade Assistant | 15/4/2022 | 17/6/2026 | Windows Upgrade Assistant Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Media (6.5) | 1.1% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/3/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of service. IBM X-Force ID: 207413. | |
| Modificada | Alta (7.5) | 2.9% | — | Home-assistant | 10/3/2022 | 17/6/2026 | An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Media (5.5) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Media (5.5) | 0.28% | — | HP Support Assistant | 28/1/2022 | 17/6/2026 | Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software. | |
| Modificada | Media (5.3) | 0.78% | — | Samsung S Assistant | 10/1/2022 | 17/6/2026 | Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information. | |
| Modificada | Crítica (9.8) | 1.1% | — | Uipath Assistant | 14/12/2021 | 17/6/2026 | An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an… | |
| Modificada | Crítica (9.8) | 1.8% | — | Uipath Assistant | 14/12/2021 | 17/6/2026 | UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path. | |
| Modificada | Alta (7.1) | 0.85% | — | Microsoft Windows 10 Update Assistant | 24/11/2021 | 19/8/2026 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 1.4% | — | Microsoft Windows 10 Update Assistant | 24/11/2021 | 19/8/2026 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 0.97% | — | Intel Endpoint Management Assistant | 17/11/2021 | 17/6/2026 | Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Alta (8.8) | 0.59% | — | IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Doors Next Generation+3 | 27/10/2021 | 17/6/2026 | IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Modificada | Alta (7.8) | 1.9% | — | Microsoft Windows 10 Update Assistant | 12/8/2021 | 10/8/2026 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test ManagementIBM Engineering Workflow Management+5 | 28/7/2021 | 17/6/2026 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192957. | |
| Modificada | Media (6.3) | 0.60% | — | IBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test ManagementIBM Engineering Workflow Management+5 | 28/7/2021 | 17/6/2026 | IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Collaborative Lifecycle Management+3 | 19/7/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235. | |
| Modificada | Media (6.1) | 1.1% | — | Greenbone Security AssistantGreenbone OS | 21/6/2021 | 17/6/2026 | Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad. | |
| Modificada | Crítica (9.8) | 1.3% | — | Greenbone Security AssistantGreenbone OS | 21/6/2021 | 17/6/2026 | Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection. | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Driver & Support Assistant | 9/6/2021 | 17/6/2026 | Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access. |