Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.88% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Access Control vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 0.99% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains a Broken Authentication Method vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Crítica (9.8) | 1.0% | — | Vmware Workspace ONE Assist | 9/11/2022 | 17/6/2026 | VMware Workspace ONE Assist prior to 22.10 contains an Authentication Bypass vulnerability. A malicious actor with network access to Workspace ONE Assist may be able to obtain administrative access without the need to authenticate to the application. | |
| Modificada | Alta (8) | 0.39% | — | Intel Driver & Support Assistant | 18/8/2022 | 17/6/2026 | Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Media (6.5) | 0.37% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310. | |
| Modificada | Media (6.5) | 0.86% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to improper client side validation. IBM X-Force ID: 203738. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Crítica (9.3) | 1.3% | — | Barry Voice Assistant Project Barry Voice Assistant | 11/7/2022 | 17/6/2026 | The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Crítica (9.6) | 1.2% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 10/6/2022 | 17/6/2026 | Dell SupportAssist Client Consumer versions (3.10.4 and prior) and Dell SupportAssist Client Commercial versions (3.1.1 and prior) contain a cross-site scripting vulnerability. A remote unauthenticated malicious user could potentially exploit this vulnerability under specific conditions leading to execution of… | |
| Modificada | Alta (7.1) | 0.24% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 10/6/2022 | 17/6/2026 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion/overwrite vulnerability. Authenticated non-admin user could exploit the issue and delete or overwrite arbitrary files on the system. | |
| Modificada | Alta (7.1) | 0.24% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 10/6/2022 | 17/6/2026 | Dell SupportAssist Client Consumer versions (3.10.4 and versions prior) and Dell SupportAssist Client Commercial versions (3.1.1 and versions prior) contain an arbitrary file deletion vulnerability. Authenticated non-admin user could exploit the issue and delete arbitrary files on the system. | |
| Modificada | Alta (7.8) | 0.35% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 10/6/2022 | 17/6/2026 | Dell SupportAssist Client Consumer versions (3.11.0 and versions prior) and Dell SupportAssist Client Commercial versions (3.2.0 and versions prior) contain a privilege escalation vulnerability. A non-admin user can exploit the vulnerability and gain admin access to the system. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Contributor License Agreement Assistant | 6/6/2022 | 17/6/2026 | Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application. | |
| Modificada | Alta (8.8) | 0.42% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Ciisafe FirmwareBD Pyxis Logistics FirmwareBD Pyxis Medbank Firmware+12 | 2/6/2022 | 17/6/2026 | Specific BD Pyxis™ products were installed with default credentials and may presently still operate with these credentials. There may be scenarios where BD Pyxis™ products are installed with the same default local operating system credentials or domain-joined server(s) credentials that may be shared across product… | |
| Modificada | Media (6.8) | 0.30% | — | Dell Supportassist OS Recovery | 26/5/2022 | 17/6/2026 | Dell Support Assist OS Recovery versions before 5.5.2 contain an Authentication Bypass vulnerability. An unauthenticated attacker with physical access to the system may exploit this vulnerability by bypassing OS Recovery authentication in order to run arbitrary code on the system as Administrator. | |
| Modificada | Alta (7.8) | 2.5% | — | Microsoft Windows Upgrade Assistant | 15/4/2022 | 17/6/2026 | Windows Upgrade Assistant Remote Code Execution Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Vmware Spring FrameworkCisco CX Cloud AgentOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Console+34 | 1/4/2022 | 17/6/2026 | A Spring MVC or Spring WebFlux application running on JDK 9+ may be vulnerable to remote code execution (RCE) via data binding. The specific exploit requires the application to run on Tomcat as a WAR deployment. If the application is deployed as a Spring Boot executable jar, i.e. the default, it is not vulnerable to… | |
| Modificada | Alta (7.5) | 52% | 💥 PoC | NokogiriPythonZlibDebian Linux+23 | 25/3/2022 | 14/7/2026 | zlib before 1.2.12 allows memory corruption when deflating (i.e., when compressing) if the input has many distant matches. | |
| Modificada | Media (6.5) | 1.1% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/3/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant prior to 3.1.3 could allow an authenticated user to cause a denial of service. IBM X-Force ID: 207413. | |
| Modificada | Alta (7.5) | 2.9% | — | Home-assistant | 10/3/2022 | 17/6/2026 | An information leak in Nabu Casa Home Assistant Operating System and Home Assistant Supervised 2022.03 allows a DNS operator to gain knowledge about internal network resources via the hardcoded DNS resolver configuration. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Media (5.5) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. |