Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

325 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.22%—Acronis True Image15/7/202117/6/2026
Acronis True Image for Mac before 2021 Update 4 allowed local privilege escalation due to insecure folder permissions.
ModificadaAlta (7.8)0.48%—Acronis True Image 202025/5/202117/6/2026
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe includes functionality to quarantine files by copying a suspected ransomware file from one directory to another using SYSTEM privileges. Because unprivileged users have write permissions in the quarantine folder, it is possible…
ModificadaMedia (5.5)0.38%—Acronis True Image 202025/5/202117/6/2026
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe keeps a log in a folder where unprivileged users have write permissions. The logs are generated in a predictable pattern, allowing an unprivileged user to create a hardlink from a (not yet created) log file to…
ModificadaAlta (7.8)0.40%—Acronis True Image 202025/5/202117/6/2026
An issue was discovered in Acronis True Image 2020 24.5.22510. anti_ransomware_service.exe exposes a REST API that can be used by everyone, even unprivileged users. This API is used to communicate from the GUI to anti_ransomware_service.exe. This can be exploited to add an arbitrary malicious executable to the…
ModificadaAlta (7.5)1.2%—Omicronenergy Stationguard20/4/202117/6/2026
OMICRON StationGuard before 1.10 allows remote attackers to cause a denial of service (connectivity outage) via crafted tcp/20499 packets to the CTRL Ethernet port.
ModificadaMedia (6.1)0.70%—Acronis Cyber Protect22/2/202117/6/2026
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. There is cross-site scripting (XSS) in the console.
ModificadaAlta (7.5)1.1%—Acronis Cyber Protect22/2/202117/6/2026
An issue was discovered in Acronis Cyber Protect before 15 Update 1 build 26172. Because the local notification service misconfigures CORS, information disclosure can occur.
ModificadaAlta (7.8)0.57%—Acronis True Image29/1/202117/6/2026
Acronis True Image for Windows prior to 2021 Update 3 allowed local privilege escalation due to a DLL hijacking vulnerability in multiple components, aka an Untrusted Search Path issue.
ModificadaAlta (8.1)4.2%—Cron-utils Project Cron-utils25/11/202017/6/2026
Cron-utils is a Java library to parse, validate, migrate crons as well as get human readable descriptions for them. In cron-utils before version 9.1.3, a template Injection vulnerability is present. This enables attackers to inject arbitrary Java EL expressions, leading to unauthenticated Remote Code Execution (RCE)…
ModificadaAlta (7.3)0.38%—Acronis True Image21/10/202017/6/2026
Acronis True Image 2021 fails to properly set ACLs of the C:\ProgramData\Acronis directory. Because some privileged processes are executed from the C:\ProgramData\Acronis, an unprivileged user can achieve arbitrary code execution with SYSTEM privileges by placing a DLL in one of several paths within…
ModificadaAlta (7.8)0.43%—Acronis True Image21/10/202017/6/2026
Acronis True Image 2021 includes an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis True Image contains a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create subdirectories off of the system root, a user can…
ModificadaAlta (7.8)0.53%—Acronis Cyber BackupAcronis Cyber Protect21/10/202017/6/2026
Acronis Cyber Backup 12.5 and Cyber Protect 15 include an OpenSSL component that specifies an OPENSSLDIR variable as a subdirectory within C:\jenkins_agent\. Acronis Cyber Backup and Cyber Protect contain a privileged service that uses this OpenSSL component. Because unprivileged Windows users can create…
ModificadaMedia (6.5)5.5%💥 ExploitAcronis Cyber Backup21/9/202017/6/2026
An issue was discovered in Acronis Cyber Backup before 12.5 Build 16342. Some API endpoints on port 9877 under /api/ams/ accept an additional custom Shard header. The value of this header is afterwards used in a separate web request issued by the application itself. This can be abused to conduct SSRF attacks against…
ModificadaCrítica (9.8)1.2%—Z-cron15/4/202017/6/2026
Z-Cron 5.6 Build 04 allows an unprivileged attacker to elevate privileges by modifying a privileged user's task. This can also affect all users who are signed in on the system if a shell is placed in a location that other unprivileged users have access to.
ModificadaCrítica (9.8)1.8%—Objectcomputing Micronaut30/3/202017/6/2026
All versions of io.micronaut:micronaut-http-client before 1.2.11 and all versions from 1.3.0 before 1.3.2 are vulnerable to HTTP Request Header Injection due to not validating request headers passed to the client.
ModificadaCrítica (9)2.7%—Micron Ddr4 SdramMicron Lpddr4Samsung Ddr4Samsung Lpddr4+210/3/202017/6/2026
Modern DRAM chips (DDR4 and LPDDR4 after 2015) are affected by a vulnerability in deployment of internal mitigations against RowHammer attacks known as Target Row Refresh (TRR), aka the TRRespass issue. To exploit this vulnerability, the attacker needs to create certain access patterns to trigger bit flips on affected…
ModificadaMedia (5.5)0.46%—Debian CronDebian Linux12/3/201917/6/2026
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (use-after-free and daemon crash) because of a force_rescan_user error.
ModificadaMedia (5.5)0.37%—Cron Project CronDebian LinuxFedoraproject Fedora12/3/201917/6/2026
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (memory consumption) via a large crontab file because an unlimited number of lines is accepted.
ModificadaMedia (5.5)0.36%—Cron Project CronFedoraproject FedoraDebian Linux12/3/201917/6/2026
Vixie Cron before the 3.0pl1-133 Debian package allows local users to cause a denial of service (daemon crash) via a large crontab file because the calloc return value is not checked.
ModificadaAlta (7.2)2.4%—Jiacrontab Project Jiacrontab3/12/201817/6/2026
jiacrontab 1.4.5 allows remote attackers to execute arbitrary commands via the crontab/task/edit?addr=localhost%3a20001 command and args parameters, as demonstrated by command=cat&args=/etc/passwd in the POST data.
ModificadaMedia (4)0.23%—Samsung 840 EVO FirmwareSamsung 850 EVO FirmwareSamsung T3 FirmwareSamsung T5 Firmware+320/11/201817/6/2026
An issue was discovered on Samsung 840 EVO and 850 EVO devices (only in "ATA high" mode, not vulnerable in "TCG" or "ATA max" mode), Samsung T3 and T5 portable drives, and Crucial MX100, MX200 and MX300 devices. Absence of a cryptographic link between the password and the Disk Encryption Key allows attackers with…
ModificadaAlta (8)0.66%—Crony Cronjob Manager Project Crony Cronjob Manager18/9/201717/6/2026
WP_Admin_UI in the Crony Cronjob Manager plugin before 0.4.7 for WordPress has CSRF via the name parameter in an action=manage&do=create operation, as demonstrated by inserting XSS sequences.
ModificadaAlta (8.8)0.47%—Acronis True Image21/6/201717/6/2026
Acronis True Image up to and including version 2017 Build 8053 performs software updates using HTTP. Downloaded updates are only verified using a server-provided MD5 hash.
ModificadaMedia (6.7)0.55%—Cron Project CronDebian Linux9/6/201717/6/2026
In the cron package through 3.0pl1-128 on Debian, and through 3.0pl1-128ubuntu2 on Ubuntu, the postinst maintainer script allows for group-crontab-to-root privilege escalation via symlink attacks against unsafe usage of the chown and chmod programs.
ModificadaMedia (6.2)0.35%—Cronic Project CronicDebian LinuxOpensuse LeapOpensuse26/7/201617/6/2026
cronic before 3 allows local users to write to arbitrary files via a symlink attack on a (1) cronic.out.$$, (2) cronic.err.$$, or (3) cronic.trace.$$ file in /tmp.
Orbitaley — Vulnerabilidades