Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
538 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.24% | — | Parallels Access | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Access 6.5.4 (39316) Agent. An attacker must first obtain the ability to execute low-privileged code on the target host system in order to exploit this vulnerability. The specific flaw exists within the Parallels… | |
| Modificada | Alta (7.8) | 0.26% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update… | |
| Modificada | Alta (7.8) | 0.30% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop 17.1.1. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the update… | |
| Modificada | Alta (8.8) | 0.34% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the… | |
| Modificada | Alta (8.2) | 0.35% | — | Parallels Desktop | 18/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 17.1.1 (51537). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the ACPI virtual… | |
| Modificada | Alta (8.2) | 0.34% | — | Parallels Desktop | 15/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.1 (49187). An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the HDAudio… | |
| Modificada | Alta (7.8) | 0.27% | — | Parallels Desktop | 15/7/2022 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.5.0 (49183). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the Parallels Service. By… | |
| Modificada | Alta (7.8) | 1.0% | — | Siemens ParasolidSiemens Simcenter Femap | 12/7/2022 | 17/6/2026 | A vulnerability has been identified in Parasolid V33.1 (All versions < V33.1.264), Parasolid V34.0 (All versions < V34.0.250), Parasolid V34.1 (All versions < V34.1.233), Simcenter Femap V2022.1 (All versions < V2022.1.3), Simcenter Femap V2022.2 (All versions < V2022.2.2). The affected application contains an out of… | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Validating Email Parameter | 30/6/2022 | 17/6/2026 | Jenkins Validating Email Parameter Plugin 1.10 and earlier does not escape the name and description of its parameter type, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.75% | — | Jenkins Stash Branch Parameter | 23/6/2022 | 17/6/2026 | Jenkins Stash Branch Parameter Plugin 0.3.0 and earlier does not escape the name and description of Stash Branch parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.80% | — | Jenkins Rest List Parameter | 23/6/2022 | 17/6/2026 | Jenkins REST List Parameter Plugin 1.5.2 and earlier does not escape the name and description of REST list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Readonly Parameter | 23/6/2022 | 17/6/2026 | Jenkins Readonly Parameter Plugin 1.0.0 and earlier does not escape the name and description of Readonly String and Readonly Text parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Image TAG Parameter | 23/6/2022 | 17/6/2026 | Jenkins Image Tag Parameter Plugin 1.10 and earlier does not escape the name and description of Image Tag parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Hidden Parameter | 23/6/2022 | 17/6/2026 | Jenkins Hidden Parameter Plugin 0.0.4 and earlier does not escape the name and description of Hidden Parameter parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.78% | — | Jenkins Filesystem List Parameter | 23/6/2022 | 17/6/2026 | Jenkins Filesystem List Parameter Plugin 0.0.7 and earlier does not escape the name and description of File system objects list parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.80% | — | Jenkins Dynamic Extended Choice Parameter | 23/6/2022 | 17/6/2026 | Jenkins Dynamic Extended Choice Parameter Plugin 1.0.1 and earlier does not escape the name and description of Moded Extended Choice parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Date Parameter | 23/6/2022 | 17/6/2026 | Jenkins Date Parameter Plugin 0.0.4 and earlier does not escape the name and description of Date parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.64% | — | Jenkins Agent Server Parameter | 23/6/2022 | 17/6/2026 | Jenkins Agent Server Parameter Plugin 1.1 and earlier does not escape the name and description of Agent Server parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Alta (8.8) | 0.42% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Ciisafe FirmwareBD Pyxis Logistics FirmwareBD Pyxis Medbank Firmware+12 | 2/6/2022 | 17/6/2026 | Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product… | |
| Modificada | Media (5.3) | 1.0% | — | Erudika Para | 24/5/2022 | 17/6/2026 | Business Logic Errors in GitHub repository erudika/para prior to 1.45.11. | |
| Modificada | Media (6.1) | 0.97% | — | Erudika Para | 18/5/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Generic in GitHub repository erudika/para prior to v1.45.11. | |
| Modificada | Media (5.4) | 0.79% | — | Jenkins Autocomplete Parameter | 17/5/2022 | 17/6/2026 | Jenkins Autocomplete Parameter Plugin 1.1 and earlier references Dropdown Autocomplete parameter and Auto Complete String parameter names in an unsafe manner from Javascript embedded in view definitions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure… | |
| Modificada | Alta (8.8) | 0.89% | — | Jenkins Autocomplete Parameter | 17/5/2022 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Autocomplete Parameter Plugin 1.1 and earlier allows attackers to execute arbitrary code without sandbox protection if the victim is an administrator. | |
| Modificada | Media (5.4) | 0.76% | — | Jenkins Random String Parameter | 17/5/2022 | 17/6/2026 | Jenkins Random String Parameter Plugin 1.0 and earlier does not escape the name and description of Random String parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. | |
| Modificada | Media (5.4) | 0.76% | — | Jenkins Multiselect Parameter | 17/5/2022 | 17/6/2026 | Jenkins Multiselect parameter Plugin 1.3 and earlier does not escape the name and description of Multiselect parameters on views displaying parameters, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. |