Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2598▼ 321 respecto a la semana anterior
Críticas / altas1342▲ 74 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
–

538 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaBaja (3.2)0.49%—Parallels Desktop14/4/202117/6/2026
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.0.1-48919. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the…
ModificadaAlta (7.8)0.45%—Parallels Desktop14/4/202117/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate…
ModificadaMedia (5.4)8.8%—Jenkins Rest List Parameter30/3/202117/6/2026
Jenkins REST List Parameter Plugin 1.3.0 and earlier does not escape a parameter name reference in embedded JavaScript, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModificadaAlta (8.8)0.76%—Jenkins Build With Parameters30/3/202117/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Build With Parameters Plugin 1.5 and earlier allows attackers to build a project with attacker-specified parameters.
ModificadaMedia (5.4)81%—Jenkins Build With Parameters30/3/202117/6/2026
Jenkins Build With Parameters Plugin 1.5 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModificadaMedia (6.5)0.27%—Parallels Desktop29/3/202117/6/2026
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 16.0.1-48919. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the…
ModificadaAlta (8.8)0.28%—Parallels Desktop29/3/202117/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate…
ModificadaAlta (8.8)0.27%—Parallels Desktop29/3/202117/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 16.0.1-48919. An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the Toolgate…
ModificadaAlta (7.5)2.6%—Parall Jspdf9/3/202117/6/2026
This affects the package jspdf before 2.3.1. ReDoS is possible via the addImage function.
ModificadaMedia (5.4)9.4%—Jenkins Artifact Repository Parameter24/2/202117/6/2026
Jenkins Artifact Repository Parameter Plugin 1.0.0 and earlier does not escape parameter names and descriptions, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModificadaMedia (5.3)1.7%—Parallels Remote Application Server25/12/202017/6/2026
Parallels Remote Application Server (RAS) 18 allows remote attackers to discover an intranet IP address because submission of the login form (even with blank credentials) provides this address to the attacker's client for use as a "host" value. In other words, after an attacker's web browser sent a request to the…
ModificadaCrítica (9.8)2.6%—Paradox Ip150 Firmware21/11/202017/6/2026
The affected product is vulnerable to three stack-based buffer overflows, which may allow an unauthenticated attacker to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).
ModificadaAlta (8.8)2.2%—Paradox Ip150 Firmware21/11/202017/6/2026
The affected product is vulnerable to five post-authentication buffer overflows, which may allow a logged in user to remotely execute arbitrary code on the IP150 (firmware versions 5.02.09).
ModificadaAlta (7.5)1.6%—Cloudavid Pparam16/11/202017/6/2026
Memory leak in IPv6Param::setAddress in CloudAvid PParam 1.3.1.
ModificadaMedia (5.4)0.73%—Jenkins Validating String Parameter16/9/202017/6/2026
Jenkins Validating String Parameter Plugin 2.4 and earlier does not escape various user-controlled fields, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModificadaMedia (4.3)0.52%—Jenkins Parameterized Remote Trigger1/9/202017/6/2026
Jenkins Parameterized Remote Trigger Plugin 3.1.3 and earlier stores a secret unencrypted in its global configuration file on the Jenkins controller where it can be viewed by attackers with access to the Jenkins controller file system.
ModificadaMedia (5.4)0.75%—Jenkins GIT Parameter1/9/202017/6/2026
Jenkins Git Parameter Plugin 0.9.12 and earlier does not escape the repository field on the 'Build with Parameters' page, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Job/Configure permission.
ModificadaMedia (5.5)0.19%—Niscomed M1000 Multipara Patient Monitor Firmware26/8/202017/6/2026
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The onboard Flash memory stores data in cleartext, without integrity protection against tampering.
ModificadaMedia (6.8)0.42%—Niscomed M1000 Multipara Patient Monitor Firmware26/8/202017/6/2026
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The physical UART debug port provides a shell, without requiring a password, with complete access.
ModificadaAlta (7.8)0.20%—Niscomed M1000 Multipara Patient Monitor Firmware26/8/202017/6/2026
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The device enables an unencrypted TELNET service by default, with a blank password for the admin account. This allows an attacker to gain root access to the device over the local network.
ModificadaAlta (7.5)0.83%—Niscomed M1000 Multipara Patient Monitor Firmware26/8/202017/6/2026
An issue was discovered on Nescomed Multipara Monitor M1000 devices. The internal storage of the underlying Linux system stores data in cleartext, without integrity protection against tampering.
ModificadaMedia (6.5)0.47%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to disclose sensitive information on affected installations of Parallels Desktop 15.1.4 (47270). An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the…
ModificadaMedia (6)0.55%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to disclose sensitive informations on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute high-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists within the VGA…
ModificadaAlta (8.8)0.53%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor kext. The…
ModificadaAlta (8.8)0.53%—Parallels Desktop25/8/202017/6/2026
This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop 15.1.4. An attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this vulnerability. The specific flaw exists within the prl_hypervisor kext. The…