Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.36% | — | Davidlingren Media Library Assistant | 5/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in submodule of David Lingren Media Library Assistant plugin <= 3.0.7 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Wpindeed Debug Assistant | 16/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions. | |
| Modificada | Crítica (9.8) | 0.89% | — | HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware | 12/6/2023 | 17/6/2026 | Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23557. | |
| Modificada | Crítica (9.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23556. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command injection by authenticated users, aka OSFOURK-23554. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-24036. | |
| Modificada | Alta (7.1) | 0.31% | — | Ubuntukylin Youker-assistant | 5/6/2023 | 17/6/2026 | A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function delete_file in the library dbus.SystemBus of the component Arbitrary File Handler. The manipulation leads to improper access controls. It is possible to launch the attack on the… | |
| Modificada | Alta (7.8) | 0.68% | — | Ubuntukylin Youker-assistant | 5/6/2023 | 17/6/2026 | A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function restore_all_sound_file. The manipulation leads to path traversal: '../filedir'. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to version… | |
| Modificada | Media (6.1) | 0.54% | — | Pushassist Push Notifications | 15/5/2023 | 17/6/2026 | The Push Notifications for WordPress by PushAssist WordPress plugin through 3.0.8 does not sanitise and escape various parameters before outputting them back in pages, leading to Reflected Cross-Site Scripting which could be used against high privilege users such as admin. | |
| Modificada | Media (5.5) | 0.16% | — | Intel Endpoint Management Assistant | 10/5/2023 | 17/6/2026 | Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (8.8) | 0.61% | — | Intel Quickassist Technology Engine | 10/5/2023 | 17/6/2026 | Improper buffer restrictions in the Intel(R) QAT Engine for OpenSSL before version 0.6.16 may allow a privileged user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper buffer restriction in software for the Intel QAT Driver for Linux before version 1.7.l.4.12 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Incorrect permission assignment for critical resource in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.17% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.16% | — | Intel Endpoint Management Assistant Configuration ToolIntel Manageability Commander | 10/5/2023 | 17/6/2026 | Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Improper access control in some Intel(R) QAT drivers for Windows before version 1.9.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.19% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Out-of-bounds write in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Quickassist Technology | 10/5/2023 | 17/6/2026 | Out-of-bounds read in software for the Intel QAT Driver for Windows before version 1.9.0-0008 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 0.64% | — | Vegayazilim Mobile Assistant | 17/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection. This issue affects Mobile Assistant: before 21.S.2343. | |
| Modificada | Alta (7.8) | 1.5% | — | Kylinos Youker-assistant | 15/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function adjust_cpufreq_scaling_governer. The manipulation leads to os command injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public… | |
| Modificada | Media (5.5) | 0.25% | — | Redhat Openshift Assisted InstallerRedhat Openshift Container Platform | 24/3/2023 | 17/6/2026 | A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user. | |
| Modificada | Crítica (10) | 72% | 💥 Exploit | Home-assistantHome-assistant Supervisor | 8/3/2023 | 17/6/2026 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home… |