Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.38% | — | Intel Driver & Support Assistant | 17/5/2019 | 17/6/2026 | Insufficient access control in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.1) | 87% | 💥 Exploit | JqueryDebian LinuxDrupalBackdropcms Backdrop+101 | 20/4/2019 | 17/6/2026 | jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype. | |
| Modificada | Alta (7.3) | 0.38% | — | HP Support Assistant | 27/3/2019 | 17/6/2026 | HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code. | |
| Modificada | Media (6.1) | 0.68% | — | I4 AI SI Assistant | 29/11/2018 | 17/6/2026 | i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings. | |
| Modificada | Media (6.5) | 0.50% | — | Intel Driver&support Assistant | 14/11/2018 | 17/6/2026 | Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access. | |
| Modificada | Alta (7.8) | 0.35% | — | Intel Driver & Support Assistant | 12/9/2018 | 17/6/2026 | Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access. | |
| Modificada | Alta (7.8) | 0.91% | — | Portrait Display SDKFujitsu Displayview ClickFujitsu Displayview Click SuiteHP Display Assistant+2 | 24/7/2018 | 17/6/2026 | Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe… | |
| Modificada | Media (6.4) | 0.29% | — | Lenovo Smart Assistant | 13/7/2018 | 17/6/2026 | For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges,… | |
| Modificada | Alta (7.8) | 0.71% | — | Myswisscomassistant | 27/3/2018 | 17/6/2026 | Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's choosing that could execute… | |
| Modificada | Media (5.5) | 0.47% | — | HP Support Assistant | 23/1/2018 | 17/6/2026 | The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1. | |
| Modificada | Media (6) | 0.31% | — | Intel Driver & Support Assistant | 9/1/2018 | 17/6/2026 | SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and writing to Memory Status registers potentially allowing information disclosure or a denial of service condition. | |
| Modificada | Alta (7.8) | 0.86% | — | Sony Content Manager Assistant | 27/12/2017 | 17/6/2026 | Untrusted search path vulnerability in Content Manager Assistant for PlayStation version 3.55.7671.0901 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.1) | 0.77% | — | Home-assistant | 10/11/2017 | 17/6/2026 | In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS. | |
| Modificada | Media (5.5) | 2.2% | 💥 Exploit | Blackwave Dive Assistant | 12/9/2017 | 17/6/2026 | XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file. | |
| Modificada | Alta (7.8) | 0.43% | — | Synology Assistant | 18/8/2017 | 17/6/2026 | Multiple untrusted search path vulnerabilities in installer in Synology Assistant before 6.1-15163 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory. | |
| Modificada | Crítica (9.8) | 5.9% | — | HP Support Assistant | 19/3/2016 | 17/6/2026 | HP Support Assistant before 8.1.52.1 allows remote attackers to bypass authentication via unspecified vectors. | |
| Modificada | Media (6.1) | 1.6% | — | Greenbone Security AssistantGreenbone OSFedoraproject Fedora | 26/1/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the charts module in Greenbone Security Assistant (GSA) 6.x before 6.0.8 allows remote attackers to inject arbitrary web script or HTML via the aggregate_type parameter in a get_aggregate command to omp. | |
| Modificada | Media (5.4) | 0.27% | — | Skydrive Assistant Project Skydrive Assistant | 22/9/2014 | 17/6/2026 | The SkyDrive Assistant (aka com.dhh.sky) application 2.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Wargaming World OF Tanks Assistant | 9/9/2014 | 17/6/2026 | The World of Tanks Assistant (aka ru.worldoftanks.mobile) application 1.7.5 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Registeredassistant Project Registeredassistant | 9/9/2014 | 17/6/2026 | The RegisteredAssistant (aka Icr.RegisteredAssistant) application 0.2.3 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 2.1% | — | Cisco Telepresence VX Clinical Assistant | 8/11/2013 | 16/6/2026 | The WIL-A module in Cisco TelePresence VX Clinical Assistant 1.2 before 1.21 changes the admin password to an empty password upon a reboot, which makes it easier for remote attackers to obtain access via the administrative interface, aka Bug ID CSCuj17238. | |
| Modificada | Media (6.8) | 1.1% | — | Greenbone Security Assistant | 28/1/2011 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in Greenbone Security Assistant (GSA) before 2.0+rc3 allows remote attackers to hijack the authentication of users for requests that send email via an OMP request to OpenVAS Manager. NOTE: this issue can be leveraged to bypass authentication requirements for exploiting… | |
| Modificada | Alta (9.3) | 4.8% | — | Assistanttools MP3 TAG Assistance Professional | 4/12/2009 | 16/6/2026 | Multiple stack-based buffer overflows in Mp3 Tag Assistant Professional 2.92 build 300 allow remote attackers to execute arbitrary code via an MP3 file with a long string in the (1) ID3v1, (2) ID3v2, or (3) APEv2 metadata field. | |
| Modificada | Alta (9.3) | 5.8% | 💥 Exploit | Assistanttools Music TAG Editor | 27/10/2009 | 16/6/2026 | Stack-based buffer overflow in Music Tag Editor 1.61 build 212 allows remote attackers to execute arbitrary code via an MP3 file with a long ID3 tag. NOTE: some of these details are obtained from third party information. | |
| Modificada | Media (5) | 7.4% | 💥 Exploit | Dotnetindex Professional Download Assistant | 15/12/2008 | 16/6/2026 | Professional Download Assistant 0.1 stores sensitive information under the web root with insufficient access control, which allows remote attackers to download the database file via a direct request for database/downloads.mdb. |