Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

325 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.3%—Crypto CronosCrypto EthermintCrypto Evmos21/12/202117/6/2026
Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. This problem has been patched in Cronos v0.6.5. There are no tested workarounds.…
ModificadaAlta (7.5)0.99%—Acronis Agent29/11/202117/6/2026
Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147
ModificadaMedia (5.4)0.47%—Acronis Cyber Protect29/11/202117/6/2026
Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
ModificadaMedia (5.4)0.47%—Acronis Cyber Protect29/11/202117/6/2026
Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
ModificadaMedia (6.1)0.58%—Acronis Cyber Protect29/11/202117/6/2026
Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
ModificadaMedia (5.4)0.47%—Acronis Cyber Protect29/11/202117/6/2026
Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035
ModificadaMedia (5.5)0.23%—Acronis AgentAcronis Cyber ProtectAcronis Cyber Protect Home Office29/11/202117/6/2026
DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27305, Acronis Cyber Protect Home Office (Windows) before build 39612
ModificadaAlta (7.8)0.26%—Acronis Cyber Protect29/11/202117/6/2026
DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035
ModificadaAlta (8.3)3.0%—Samsung Ddr4 Sdram FirmwareSamsung Lddr4 FirmwareMicron Lddr4 FirmwareMicron Ddr4 Sdram Firmware+216/11/202117/6/2026
Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks. Novel non-uniform Rowhammer access patterns, consisting of aggressors with different frequencies, phases, and amplitudes allow triggering bit flips on affected memory…
ModificadaCrítica (9.8)4.3%💥 PoCCron-utils Project Cron-utils15/11/202117/6/2026
cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE)…
ModificadaAlta (7.8)0.56%—Micron Ballistix Memory Overview Display Utility4/10/202117/6/2026
Ballistix MOD Utility through 2.0.2.5 is vulnerable to privilege escalation in the MODAPI.sys driver component. The vulnerability is triggered by sending a specific IOCTL request that allows low-privileged users to directly interact with physical memory via the MmMapIoSpace function call (mapping physical memory into…
ModificadaAlta (7.8)0.23%—Acronis Cyber Protect12/8/202117/6/2026
Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking.
ModificadaMedia (6.1)0.58%—Acronis Cyber Protect12/8/202117/6/2026
Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009.
ModificadaAlta (7.8)0.26%—Acronis Cyber Protect12/8/202117/6/2026
Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking.
ModificadaAlta (8.1)0.73%—Acronis Cyber Protect CloudAcronis Cyber Protection AgentAcronis True Image5/8/202117/6/2026
Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 27009 did not implement SSL certificate validation.
ModificadaAlta (7.8)0.26%—Acronis True Image5/8/202117/6/2026
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking.
ModificadaAlta (7.8)0.24%—Acronis True Image5/8/202117/6/2026
Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service API.
ModificadaAlta (7.8)0.23%—Acronis True Image5/8/202117/6/2026
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 2 of 2).
ModificadaAlta (7.8)0.20%—Acronis True Image5/8/202117/6/2026
Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissions.
ModificadaAlta (7.8)0.23%—Acronis True Image5/8/202117/6/2026
Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2).
ModificadaAlta (7.5)1.1%—Acronis Agent30/7/202117/6/2026
A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Windows memory protection and access sensitive data.
ModificadaAlta (7.5)1.7%—Objectcomputing Micronaut16/7/202117/6/2026
Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file…
ModificadaAlta (7.8)2.2%💥 ExploitAcronis True Image15/7/202117/6/2026
Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration.
ModificadaMedia (6.7)0.25%—Acronis True Image15/7/202117/6/2026
Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions.
ModificadaAlta (7.8)0.26%—Acronis True Image15/7/202117/6/2026
Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration.
Orbitaley — Vulnerabilidades