Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

495 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.88%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaCrítica (9.8)0.99%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaCrítica (9.8)1.0%—Vmware Workspace ONE Assist9/11/202217/6/2026
VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application.
ModificadaAlta (8)0.39%—Intel Driver & Support Assistant18/8/202217/6/2026
Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access.
ModificadaMedia (6.5)0.37%—IBM Engineering Requirements Quality Assistant On-premises18/7/202217/6/2026
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310.
ModificadaMedia (6.5)0.86%—IBM Engineering Requirements Quality Assistant On-premises18/7/202217/6/2026
IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to improper client side validation. IBM X-Force ID: 203738.
ModificadaMedia (5.4)0.50%—IBM Engineering Requirements Quality Assistant On-premises18/7/202217/6/2026
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…
ModificadaMedia (5.4)0.50%—IBM Engineering Requirements Quality Assistant On-premises18/7/202217/6/2026
IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force…
ModificadaCrítica (9.3)1.3%—Barry Voice Assistant Project Barry Voice Assistant11/7/202217/6/2026
The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
ModificadaCrítica (9.6)1.2%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS10/6/202217/6/2026
Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of…
ModificadaAlta (7.1)0.24%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS10/6/202217/6/2026
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system.
ModificadaAlta (7.1)0.24%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS10/6/202217/6/2026
Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system.
ModificadaAlta (7.8)0.35%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS10/6/202217/6/2026
Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system.
ModificadaMedia (6.5)0.85%—SAP Contributor License Agreement Assistant6/6/202217/6/2026
Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application.
ModificadaAlta (8.8)0.42%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Ciisafe FirmwareBD Pyxis Logistics FirmwareBD Pyxis Medbank Firmware+122/6/202217/6/2026
Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product…
ModificadaMedia (6.8)0.30%—Dell Supportassist OS Recovery26/5/202217/6/2026
Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the system as Administrator.
ModificadaAlta (7.8)2.5%—Microsoft Windows Upgrade Assistant15/4/202217/6/2026
Windows Upgrade Assistant Remote Code Execution Vulnerability
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitVmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+341/4/202217/6/2026
A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to…
ModificadaAlta (7.5)52%💥 PoCNokogiriPythonZlibDebian Linux+2325/3/202214/7/2026
zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches.
ModificadaMedia (6.5)1.1%—IBM Engineering Requirements Quality Assistant On-premises18/3/202217/6/2026
IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of service. IBM X-Force ID: 207413.
ModificadaAlta (7.5)2.9%—Home-assistant10/3/202217/6/2026
An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration.
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaMedia (5.5)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.