Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
809 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.2) | 0.21% | — | Processwire | 19/7/2024 | 9/7/2026 | Cross Site Request Forgery vulnerability in ProcessWire v.3.0.229 allows a remote attacker to insert a comment. NOTE: this is disputed by the Supplier because the product intentionally accepts anonymous, unauthenticated comments and thus there are fewer situations in which CSRF would be a useful attack technique.… | |
| Analizada | Alta (8.1) | 0.39% | — | Oracle Process Manufacturing Product Development | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Management Specs). The supported version that is affected is 12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Analizada | Alta (8.1) | 0.40% | — | Oracle Process Manufacturing Financials | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Process Manufacturing Financials product of Oracle E-Business Suite (component: Allocation Rules). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Process… | |
| Modificada | Crítica (9.8) | 0.62% | — | HP 3par Service Processor Firmware | 16/7/2024 | 17/6/2026 | The vulnerability could be remotely exploited to bypass authentication. | |
| Modificada | Alta (7.8) | 0.15% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm Ar8035 Firmware+218 | 1/7/2024 | 17/6/2026 | Memory corruption when IOMMU unmap operation fails, the DMA and anon buffers are getting released. | |
| Modificada | Alta (7.8) | 0.10% | — | Qualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Ar9380 Firmware+339 | 1/7/2024 | 17/6/2026 | Memory corruption when allocating and accessing an entry in an SMEM partition. | |
| Aplazada | Alta (7.1) | 0.19% | — | NXP Data Co-processorAI | 28/6/2024 | 17/6/2026 | The NXP Data Co-Processor (DCP) is a built-in hardware module for specific NXP SoCs¹ that implements a dedicated AES cryptographic engine for encryption/decryption operations. The dcp_tool reference implementation included in the repository selected the test key, regardless of its `-t` argument. This issue has been… | |
| Aplazada | Alta (7.3) | 0.25% | — | W3C XML Signature Syntax AND ProcessingAI | 26/6/2024 | 17/6/2026 | The W3C XML Signature Syntax and Processing (XMLDsig) specification, starting with 1.0, was originally published with a "RetrievalMethod is a URI ... that may be used to obtain key and/or certificate information" statement and no accompanying information about SSRF risks, and this may have contributed to vulnerable… | |
| Analizada | Alta (7.8) | 0.19% | — | Intel Processor Diagnostic Tool | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Processor Diagnostic Tool software before version 4.1.9.41 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.7) | 0.19% | — | Intel Processor Identification UtilityAI | 16/5/2024 | 17/6/2026 | Uncontrolled search path in some Intel(R) Processor Identification Utility software before versions 6.10.34.1129, 7.1.6 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.7) | 0.28% | — | Intel Core Ultra ProcessorsAI | 16/5/2024 | 17/6/2026 | Sequence of processor instructions leads to unexpected behavior in Intel(R) Core(TM) Ultra Processors may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Baja (2.8) | 0.18% | — | Intel ProcessorsAI | 16/5/2024 | 17/6/2026 | Hardware logic contains race conditions in some Intel(R) Processors may allow an authenticated user to potentially enable partial information disclosure via local access. | |
| Aplazada | Media (4.2) | 0.27% | — | Sysinternals Process ExplorerAI | 7/5/2024 | 17/6/2026 | Process Explorer before 17.04 allows attackers to make it functionally unavailable (a denial of service for analysis) by renaming an executable file to a new extensionless 255-character name and launching it with NtCreateUserProcess. This can occur through an issue in wcscat_s error handling. | |
| Aplazada | Crítica (9.8) | 0.52% | — | Shenzhen Jf6000 Cloud Media Collaboration Processing PlatformAI | 30/4/2024 | 17/6/2026 | Shenzhen JF6000 Cloud Media Collaboration Processing Platform firmware version V1.2.0 and software version V2.0.0 build 6245 is vulnerable to Incorrect Access Control. | |
| Analizada | Alta (8.1) | 0.60% | — | Oracle Agile Product Lifecycle Management FOR Process | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Product Quality Management). The supported version that is affected is 6.2.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile… | |
| Analizada | Media (6.5) | 0.45% | — | Oracle Agile Product Lifecycle Management FOR Process | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Agile Product Lifecycle Management for Process product of Oracle Supply Chain (component: Data Import). The supported version that is affected is 6.2.4.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Agile Product… | |
| Analizada | Media (6.5) | 0.51% | — | Oracle Concurrent Processing | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Concurrent Processing product of Oracle E-Business Suite (component: Request Submission and Scheduling). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Concurrent… | |
| Analizada | Alta (7.5) | 0.64% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 Firmware+4 | 15/4/2024 | 17/6/2026 | A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will… | |
| Analizada | Crítica (9.8) | 6.9% | — | Haskell Process LibraryNodejs Node.jsPHPRust-lang Rust+1 | 10/4/2024 | 17/6/2026 | A command inject vulnerability allows an attacker to perform command injection on Windows applications that indirectly depend on the CreateProcess function when the specific conditions are satisfied. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au Firmware+226 | 1/4/2024 | 17/6/2026 | Memory corruption when there is failed unmap operation in GPU. | |
| Aplazada | Media (6.5) | 0.35% | — | ProcessmakerAI | 28/3/2024 | 17/6/2026 | Cross Site Scripting vulnerability in Process Maker, Inc ProcessMaker before 4.0 allows a remote attacker to run arbitrary code via control of the pm_sys_sys cookie. | |
| Aplazada | Media (6.5) | 0.75% | — | Intel ProcessorsAI | 14/3/2024 | 17/6/2026 | Protection mechanism failure of bus lock regulator for some Intel(R) Processors may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Aplazada | Media (5.5) | 0.27% | — | Intel ProcessorsAI | 14/3/2024 | 17/6/2026 | Non-transparent sharing of return predictor targets between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (7.2) | 0.15% | — | Intel Xeon ProcessorsAIIntel SGXAIIntel TDXAI | 14/3/2024 | 17/6/2026 | On-chip debug and test interface with improper access control in some 4th Generation Intel(R) Xeon(R) Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.5) | 0.55% | — | Intel Atom ProcessorsAI | 14/3/2024 | 17/6/2026 | Information exposure through microarchitectural state after transient execution from some register files for some Intel(R) Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. |