Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
325 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Crypto CronosCrypto EthermintCrypto Evmos | 21/12/2021 | 17/6/2026 | Cronos is a commercial implementation of a blockchain. In Cronos nodes running versions before v0.6.5, it is possible to take transaction fees from Cosmos SDK's FeeCollector for the current block by sending a custom crafted MsgEthereumTx. This problem has been patched in Cronos v0.6.5. There are no tested workarounds.… | |
| Modificada | Alta (7.5) | 0.99% | — | Acronis Agent | 29/11/2021 | 17/6/2026 | Sensitive information could be logged. The following products are affected: Acronis Agent (Windows, Linux, macOS) before build 27147 | |
| Modificada | Media (5.4) | 0.47% | — | Acronis Cyber Protect | 29/11/2021 | 17/6/2026 | Stored cross-site scripting (XSS) was possible in protection plan details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035 | |
| Modificada | Media (5.4) | 0.47% | — | Acronis Cyber Protect | 29/11/2021 | 17/6/2026 | Stored cross-site scripting (XSS) was possible in activity details. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035 | |
| Modificada | Media (6.1) | 0.58% | — | Acronis Cyber Protect | 29/11/2021 | 17/6/2026 | Cross-site scripting (XSS) was possible in notification pop-ups. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035 | |
| Modificada | Media (5.4) | 0.47% | — | Acronis Cyber Protect | 29/11/2021 | 17/6/2026 | Self cross-site scripting (XSS) was possible on devices page. The following products are affected: Acronis Cyber Protect 15 (Windows, Linux) before build 28035 | |
| Modificada | Media (5.5) | 0.23% | — | Acronis AgentAcronis Cyber ProtectAcronis Cyber Protect Home Office | 29/11/2021 | 17/6/2026 | DLL hijacking could lead to denial of service. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27305, Acronis Cyber Protect Home Office (Windows) before build 39612 | |
| Modificada | Alta (7.8) | 0.26% | — | Acronis Cyber Protect | 29/11/2021 | 17/6/2026 | DLL hijacking could lead to local privilege escalation. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035 | |
| Modificada | Alta (8.3) | 3.0% | — | Samsung Ddr4 Sdram FirmwareSamsung Lddr4 FirmwareMicron Lddr4 FirmwareMicron Ddr4 Sdram Firmware+2 | 16/11/2021 | 17/6/2026 | Modern DRAM devices (PC-DDR4, LPDDR4X) are affected by a vulnerability in their internal Target Row Refresh (TRR) mitigation against Rowhammer attacks. Novel non-uniform Rowhammer access patterns, consisting of aggressors with different frequencies, phases, and amplitudes allow triggering bit flips on affected memory… | |
| Modificada | Crítica (9.8) | 4.3% | 💥 PoC | Cron-utils Project Cron-utils | 15/11/2021 | 17/6/2026 | cron-utils is a Java library to define, parse, validate, migrate crons as well as get human readable descriptions for them. In affected versions A template Injection was identified in cron-utils enabling attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE)… | |
| Modificada | Alta (7.8) | 0.56% | — | Micron Ballistix Memory Overview Display Utility | 4/10/2021 | 17/6/2026 | Ballistix MOD Utility through 2.0.2.5 is vulnerable to privilege escalation in the MODAPI.sys driver component. The vulnerability is triggered by sending a specific IOCTL request that allows low-privileged users to directly interact with physical memory via the MmMapIoSpace function call (mapping physical memory into… | |
| Modificada | Alta (7.8) | 0.23% | — | Acronis Cyber Protect | 12/8/2021 | 17/6/2026 | Acronis Cyber Protect 15 for Windows prior to build 27009 allowed local privilege escalation via binary hijacking. | |
| Modificada | Media (6.1) | 0.58% | — | Acronis Cyber Protect | 12/8/2021 | 17/6/2026 | Reflected cross-site scripting (XSS) was possible on the login page in Acronis Cyber Protect 15 prior to build 27009. | |
| Modificada | Alta (7.8) | 0.26% | — | Acronis Cyber Protect | 12/8/2021 | 17/6/2026 | Acronis Cyber Protect 15 for Windows prior to build 27009 and Acronis Agent for Windows prior to build 26226 allowed local privilege escalation via DLL hijacking. | |
| Modificada | Alta (8.1) | 0.73% | — | Acronis Cyber Protect CloudAcronis Cyber Protection AgentAcronis True Image | 5/8/2021 | 17/6/2026 | Acronis True Image prior to 2021 Update 4 for Windows, Acronis True Image prior to 2021 Update 5 for Mac, Acronis Agent prior to build 26653, Acronis Cyber Protect prior to build 27009 did not implement SSL certificate validation. | |
| Modificada | Alta (7.8) | 0.26% | — | Acronis True Image | 5/8/2021 | 17/6/2026 | Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to DLL hijacking. | |
| Modificada | Alta (7.8) | 0.24% | — | Acronis True Image | 5/8/2021 | 17/6/2026 | Acronis True Image prior to 2021 Update 4 for Windows and Acronis True Image prior to 2021 Update 5 for macOS allowed an unauthenticated attacker (who has a local code execution ability) to tamper with the micro-service API. | |
| Modificada | Alta (7.8) | 0.23% | — | Acronis True Image | 5/8/2021 | 17/6/2026 | Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 2 of 2). | |
| Modificada | Alta (7.8) | 0.20% | — | Acronis True Image | 5/8/2021 | 17/6/2026 | Acronis True Image prior to 2021 Update 5 for Windows allowed local privilege escalation due to insecure folder permissions. | |
| Modificada | Alta (7.8) | 0.23% | — | Acronis True Image | 5/8/2021 | 17/6/2026 | Acronis True Image prior to 2021 Update 4 for Windows allowed local privilege escalation due to improper soft link handling (issue 1 of 2). | |
| Modificada | Alta (7.5) | 1.1% | — | Acronis Agent | 30/7/2021 | 17/6/2026 | A logic bug in system monitoring driver of Acronis Agent after 12.5.21540 and before 12.5.23094 allowed to bypass Windows memory protection and access sensitive data. | |
| Modificada | Alta (7.5) | 1.7% | — | Objectcomputing Micronaut | 16/7/2021 | 17/6/2026 | Micronaut is a JVM-based, full stack Java framework designed for building JVM applications. A path traversal vulnerability exists in versions prior to 2.5.9. With a basic configuration, it is possible to access any file from a filesystem, using "/../../" in the URL. This occurs because Micronaut does not restrict file… | |
| Modificada | Alta (7.8) | 2.2% | 💥 Exploit | Acronis True Image | 15/7/2021 | 17/6/2026 | Acronis True Image 2019 update 1 through 2021 update 1 on macOS allows local privilege escalation due to an insecure XPC service configuration. | |
| Modificada | Media (6.7) | 0.25% | — | Acronis True Image | 15/7/2021 | 17/6/2026 | Acronis True Image through 2021 on macOS allows local privilege escalation from admin to root due to insecure folder permissions. | |
| Modificada | Alta (7.8) | 0.26% | — | Acronis True Image | 15/7/2021 | 17/6/2026 | Acronis True Image 2019 update 1 through 2020 on macOS allows local privilege escalation due to an insecure XPC service configuration. |