Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
3834 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.22% | — | Intel Endpoint Management Assistant | 12/5/2026 | 21/7/2026 | Improper input validation for some Intel Endpoint Management Assistant (EMA) software before version 1.14.5 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an unauthenticated user combined with a low complexity attack may enable escalation of privilege. This… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Intel ProcessorsAI | 12/5/2026 | 17/6/2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Processors within VMX non-root (guest) operation may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a high complexity… | |
| Pendiente de análisis | Media (5.4) | 0.09% | — | Intel Server Firmware Update Utility SoftwareAI | 12/5/2026 | 17/6/2026 | Uncontrolled search path for some Intel(R) Server Firmware Update Utility Software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This result… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Intel Ethernet 800 SeriesAI | 12/5/2026 | 17/6/2026 | Use after free for some Linux kernel driver for the Intel(R) Ethernet 800 series before version 2.3.14 within Ring 0: Kernel may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur… | |
| Pendiente de análisis | Media (5.4) | 0.12% | — | SAP Businessobjects Business Intelligence PlatformAI | 12/5/2026 | 17/6/2026 | Due to insufficient CSRF protection in SAP BusinessObjects Business Intelligence Platform ,an authenticated user could be tricked by an attacker to send unintended requests to the web server. This has low impact on integrity and availability of the application. There is no impact on confidentiality of the data. | |
| Analizada | Media (6.1) | 0.27% | — | Naturalintelligence Fast-xml-parser | 7/5/2026 | 17/6/2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Prior to version 5.7.0, XMLBuilder does not escape the "-->" sequence in comment content or the "]]>" sequence in CDATA sections when building XML from JavaScript objects. This allows XML injection when… | |
| Analizada | Alta (7.5) | 0.44% | — | Jetbrains Intellij Idea | 30/4/2026 | 17/6/2026 | In JetBrains IntelliJ IDEA before 2024.3.7.1, 2025.1.7.1, 2025.2.6.2, 2025.3.4.1, 2026.1.1 reading arbitrary local files was possible via built-in web server | |
| Analizada | Crítica (9.9) | 0.32% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download… | |
| Analizada | Alta (7.1) | 0.23% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton… | |
| Analizada | Alta (7.4) | 0.17% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download… | |
| Analizada | Alta (7.5) | 0.32% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed in the latest version of Eaton IPP which is available on the Eaton download centre. | |
| Analizada | Alta (7.2) | 0.34% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious code resulting in arbitrary command execution. This security issue has been fixed in the latest version of Eaton IPP… | |
| Pendiente de análisis | Media (4.1) | 0.28% | — | SAP Businessobjects Business IntelligenceAI | 14/4/2026 | 17/6/2026 | SAP BusinessObjects Business Intelligence application allows an authenticated attacker to inject malicious JavaScript payloads through crafted URLs. When a victim accesses the URL, the script executes in the user�s browser, potentially exposing restricted information. This results in a low impact on confidentiality… | |
| Pendiente de análisis | Media (4.2) | 0.17% | — | SAP Business Objects Business Intelligence PlatformAI | 14/4/2026 | 17/6/2026 | Due to an Insecure session management vulnerability in SAP Business Objects Business Intelligence Platform, an unauthenticated attacker could obtain valid session tokens and reuse them to gain unauthorized access to a victim�s session. If the application continues to accept previously issued tokens after… | |
| Pendiente de análisis | Media (5.8) | 0.11% | — | Intel Pentium Processor Silver SeriesAIIntel Celeron Processor J SeriesAIIntel Celeron Processor N SeriesAI | 8/4/2026 | 25/7/2026 | Use of Default Cryptographic Key in the hardware for some Intel(R) Pentium(R) Processor Silver Series, Intel(R) Celeron(R) Processor J Series, Intel(R) Celeron(R) Processor N Series may allow an escalation of privilege. Hardware reverse engineer adversary with a privileged user combined with a high complexity attack… | |
| Analizada | Alta (7.5) | 0.39% | — | Artificial Intelligence Project Artificial Intelligence | 26/3/2026 | 17/6/2026 | Incorrect Authorization vulnerability in Drupal AI (Artificial Intelligence) allows Resource Injection.This issue affects AI (Artificial Intelligence): from 0.0.0 before 1.1.11, from 1.2.0 before 1.2.12. | |
| Analizada | Media (5.9) | 0.48% | — | Naturalintelligence Fast-xml-parser | 24/3/2026 | 17/6/2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. From version 4.0.0-beta.3 to before version 5.5.7, the DocTypeReader in fast-xml-parser uses JavaScript truthy checks to evaluate maxEntityCount and maxEntitySize configuration limits. When a developer explicitly… | |
| Analizada | Alta (7.5) | 0.73% | — | Naturalintelligence Fast-xml-parser | 20/3/2026 | 17/6/2026 | fast-xml-parser allows users to process XML from JS object without C/C++ based libraries or callbacks. Versions 4.0.0-beta.3 through 5.5.5 contain a bypass vulnerability where numeric character references (&#NNN;, &#xHH;) and standard XML entities completely evade the entity expansion limits (e.g., maxTotalExpansions,… | |
| Pendiente de análisis | Alta (8.7) | 0.30% | — | Intelbras Telefone IP Tip200AIIntelbras Telefone IP Tip200 LiteAI | 11/3/2026 | 17/6/2026 | IntelBras Telefone IP TIP200 and 200 LITE contain an unauthenticated arbitrary file read vulnerability in the dumpConfigFile function accessible via the cgiServer.exx endpoint. Attackers can send GET requests to /cgi-bin/cgiServer.exx with the command parameter containing dumpConfigFile() to read sensitive files… | |
| En análisis | Media (6.1) | 0.21% | — | Cisco FinesseAICisco Packaged Contact Center EnterpriseAICisco Unified Contact Center EnterpriseAICisco Unified Contact Center ExpressAI+1 | 11/3/2026 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Finesse, Cisco Packaged Contact Center Enterprise (Packaged CCE), Cisco Unified Contact Center Enterprise (Unified CCE), Cisco Unified Contact Center Express (Unified CCX), and Cisco Unified Intelligence Center could allow an unauthenticated, remote… | |
| Pendiente de análisis | Media (5.6) | 0.08% | — | Intel Uefi Pdasmm ModuleAI | 10/3/2026 | 17/6/2026 | Time-of-check time-of-use race condition in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.6) | 0.10% | — | Intel Uefi PdasmmAI | 10/3/2026 | 17/6/2026 | Exposure of resource to wrong sphere in the UEFI PdaSmm module for some Intel(R) reference platforms may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Alta (8.7) | 0.12% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper input validation in some UEFI firmware SMM module for the Intel(R) reference platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable local code execution. This result may potentially occur via local access when attack… | |
| Pendiente de análisis | Media (5.9) | 0.14% | — | Intel Uefi FirmwareAI | 10/3/2026 | 17/6/2026 | Improper input validation in the UEFI firmware for some Intel Reference Platforms may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable data manipulation. This result may potentially occur via local access when attack requirements are… | |
| Pendiente de análisis | Baja (1.8) | 0.10% | — | Intel Uefi DXEAI | 10/3/2026 | 17/6/2026 | Improper buffer restrictions in the UEFI DXE module for some Intel(R) Reference Platforms within UEFI may allow an information disclosure. System software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via local access when attack… |