Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.33% | — | Intel Atom C3000Intel Atom C3308Intel Atom C3336Intel Atom C3338+1060 | 14/7/2021 | 17/6/2026 | Insecure default variable initialization for the Intel BSSA DFT feature may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.35% | — | Intel Atom X5-e3930Intel Atom X5-e3940Intel Atom X7-e3950Intel Celeron J1750+210 | 9/6/2021 | 17/6/2026 | Incomplete cleanup in some Intel(R) VT-d products may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.47% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+64 | 9/6/2021 | 17/6/2026 | Domain-bypass transient execution vulnerability in some Intel Atom(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.9) | 0.49% | — | Atomtech Smart Life | 9/6/2021 | 17/6/2026 | The ATOM (ATOM - Smart life App for Android versions prior to 1.8.1 and ATOM - Smart life App for iOS versions prior to 1.8.2) does not verify server certificate properly, which allows man-in-the-middle attackers to eavesdrop on encrypted communication via a crafted certificate. | |
| Modificada | Crítica (9.8) | 3.5% | — | Atomisystems Activepresenter | 15/2/2021 | 17/6/2026 | ActivePresenter 6.1.6 is affected by a memory corruption vulnerability that may result in a denial of service (DoS) or arbitrary code execution. | |
| Modificada | Media (5.9) | 1.1% | — | Atomic-option Project Atomic-option | 26/1/2021 | 17/6/2026 | An issue was discovered in the atomic-option crate through 2020-10-31 for Rust. Because AtomicOption<T> implements Sync unconditionally, a data race can occur. | |
| Modificada | Media (4.7) | 0.20% | — | Atom Project Atom | 31/12/2020 | 17/6/2026 | An issue was discovered in the atom crate before 0.3.6 for Rust. An unsafe Send implementation allows a cross-thread data race. | |
| Modificada | Crítica (9.8) | 2.3% | — | Matomo Piwik Fpm-alpine Docker Image | 8/12/2020 | 17/6/2026 | The official piwik Docker images before fpm-alpine (Alpine specific) contain a blank password for a root user. Systems using the Piwik Docker container deployed by affected versions of the Docker image may allow an remote attacker to achieve root access. | |
| Modificada | Media (6.7) | 0.33% | — | Intel Pentium J6425 FirmwareIntel Pentium J4205 FirmwareIntel Pentium J3710 FirmwareIntel Pentium J2900 Firmware+57 | 13/11/2020 | 17/6/2026 | Improper access control in the PMC for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 1.0% | — | Atomxcms | 22/10/2020 | 17/6/2026 | AtomXCMS 2.0 is affected by Arbitrary File Read via admin/dump.php | |
| Modificada | Alta (8.1) | 0.75% | — | Atomxcms 2 | 22/10/2020 | 17/6/2026 | AtomXCMS 2.0 is affected by Incorrect Access Control via admin/dump.php | |
| Modificada | Alta (7.8) | 0.29% | — | Intel AC 3165 FirmwareIntel AC 3168 FirmwareIntel AC 7265 FirmwareIntel AC 8260 Firmware+72 | 13/8/2020 | 17/6/2026 | Insecure inherited permissions in some Intel(R) PROSet/Wireless WiFi products on Windows* 7 and 8.1 before version 21.40.5.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.4) | 1.6% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformRedhat Enterprise Linux+11 | 29/7/2020 | 17/6/2026 | Integer overflows were discovered in the functions grub_cmd_initrd and grub_initrd_init in the efilinux component of GRUB2, as shipped in Debian, Red Hat, and Ubuntu (the functionality is not included in GRUB2 upstream), leading to a heap-based buffer overflow. These could be triggered by an extremely large number of… | |
| Modificada | Media (6.4) | 0.98% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 contains a race condition in grub_script_function_create() leading to a use-after-free vulnerability which can be triggered by redefining a function whilst the same function is already executing, leading to arbitrary code execution and secure boot restriction bypass. This issue affects GRUB2 version 2.04 and… | |
| Modificada | Media (6.4) | 1.4% | — | GNU Grub2Redhat Enterprise Linux Atomic HostRedhat Openshift Container PlatformCanonical Ubuntu Linux+10 | 29/7/2020 | 17/6/2026 | GRUB2 fails to validate kernel signature when booted directly without shim, allowing secure boot to be bypassed. This only affects systems where the kernel signing certificate has been imported directly into the secure boot database and the GRUB image is booted directly without the use of shim. This issue affects… | |
| Modificada | Alta (7.8) | 0.90% | — | Projectatomic BubblewrapDebian LinuxArchlinux Arch LinuxCentos | 31/3/2020 | 17/6/2026 | Bubblewrap (bwrap) before version 0.4.1, if installed in setuid mode and the kernel supports unprivileged user namespaces, then the `bwrap --userns2` option can be used to make the setuid process keep running as root while being traceable. This can in turn be used to gain root permissions. Note that this only affects… | |
| Modificada | Media (5.6) | 1.1% | 💥 PoC | Intel Atom C2308Intel Atom C2316Intel Atom C2338Intel Atom C2350+1317 | 12/3/2020 | 17/6/2026 | Load value injection in some Intel(R) Processors utilizing speculative execution may allow an authenticated user to potentially enable information disclosure via a side channel with local access. The list of affected products is provided in intel-sa-00334:… | |
| Modificada | Media (5.5) | 1.4% | 💥 PoC | Canonical Ubuntu LinuxIntel Atom E3805Intel Atom E3815Intel Atom E3825+441 | 17/1/2020 | 17/6/2026 | Insufficient control flow in certain data structures for some Intel(R) Processors with Intel(R) Processor Graphics may allow an unauthenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.1) | 1.2% | — | Matomo | 20/11/2019 | 16/6/2026 | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0194. | |
| Modificada | Media (6.1) | 1.2% | — | Matomo | 20/11/2019 | 16/6/2026 | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0193 and CVE-2013-0195. | |
| Modificada | Media (6.1) | 1.2% | — | Matomo | 20/11/2019 | 16/6/2026 | Cross-site Scripting (XSS) in Piwik before 1.10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: This is a different vulnerability than CVE-2013-0194 and CVE-2013-0195. | |
| Modificada | Alta (7.8) | 0.67% | — | Redhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUSRedhat Enterprise Linux Server TUSIntel Graphics Driver+353 | 14/11/2019 | 17/6/2026 | Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series;… | |
| Modificada | Media (5.5) | 0.65% | — | Canonical Ubuntu LinuxIntel Pentium J4205 FirmwareIntel Pentium N4200 FirmwareIntel Celeron J3355 Firmware+144 | 14/11/2019 | 17/6/2026 | Insufficient access control in subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series;… | |
| Modificada | Alta (8.2) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of… | |
| Modificada | Media (6.7) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local… |