Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

495 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)0.78%—Media Library Assistant Project Media Library Assistant27/2/202317/6/2026
The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin.
ModificadaMedia (5.3)0.15%—Intel Endpoint Management Assistant16/2/202317/6/2026
Improper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege via network access.
ModificadaAlta (7.3)0.18%—Intel Quickassist Technology16/2/202317/6/2026
Uncontrolled search path in some Intel(R) QAT drivers for Windows before version 1.6 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.23%—Intel Quickassist Technology16/2/202317/6/2026
Incorrect default permissions in the software installer for some Intel(R) QAT drivers for Linux before version 4.17 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7)0.13%—Intel Driver & Support Assistant16/2/202317/6/2026
Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.23%—Intel Driver & Support Assistant16/2/202317/6/2026
Protection mechanism failure in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.20%—Elecom Camera AssistantElecom Quickfiledealer15/2/202317/6/2026
Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (5.5)0.16%—Dell Supportassist FOR Home PCS11/2/202317/6/2026
SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information.
ModificadaMedia (5.3)0.44%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS11/2/202317/6/2026
Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician.
ModificadaAlta (7.1)0.16%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS11/2/202317/6/2026
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected…
ModificadaAlta (7.8)0.15%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS11/2/202317/6/2026
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system.
ModificadaMedia (5.5)0.17%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS11/2/202317/6/2026
Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.
ModificadaMedia (5.5)0.13%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS11/2/202317/6/2026
SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.
ModificadaAlta (7.8)0.23%—Dell Alienware UpdateDell Command UpdateDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS+111/2/202317/6/2026
Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may…
ModificadaMedia (6.5)0.52%—Dell Supportassist FOR Home PCS10/2/202317/6/2026
Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information.
ModificadaAlta (7.8)0.19%—HP Support Assistant1/2/202317/6/2026
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.
ModificadaAlta (7.8)0.19%—HP Support Assistant1/2/202317/6/2026
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.
ModificadaAlta (7.8)0.19%—HP Support Assistant1/2/202317/6/2026
Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files.
ModificadaCrítica (9.8)1.9%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager13/12/202217/6/2026
A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve administrative access to the system.
ModificadaAlta (7.8)2.8%—HP FusionHP Support Assistant12/12/202217/6/2026
HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up.
ModificadaMedia (5.3)0.58%—Davidlingren Media Library Assistant18/11/202217/6/2026
Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress.
ModificadaAlta (7.8)0.17%—Intel Endpoint Management Assistant11/11/202217/6/2026
Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)0.47%—Intel Active Management Technology Software Development KITIntel Endpoint Management AssistantIntel Manageability Commander11/11/202217/6/2026
Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access.
ModificadaCrítica (9.8)0.88%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Session fixation vulnerability. A malicious actor who obtains a valid session token may be able to authenticate to the application using that token.
ModificadaMedia (6.1)0.46%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Reflected cross-site scripting (XSS) vulnerability. Due to improper user input sanitization, a malicious actor with some user interaction may be able to inject javascript code in the target user's window.
Orbitaley — Vulnerabilidades