Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

495 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaAlta (7.8)0.86%—HP Support Assistant16/2/202217/6/2026
Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software.
ModificadaMedia (5.5)0.23%—BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+2011/2/202217/6/2026
Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health…
ModificadaMedia (5.5)0.28%—HP Support Assistant28/1/202217/6/2026
Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software.
ModificadaMedia (5.3)0.78%—Samsung S Assistant10/1/202217/6/2026
Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information.
ModificadaCrítica (9.8)1.1%—Uipath Assistant14/12/202117/6/2026
An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an…
ModificadaCrítica (9.8)1.8%—Uipath Assistant14/12/202117/6/2026
UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path.
ModificadaAlta (7.1)0.85%—Microsoft Windows 10 Update Assistant24/11/202119/8/2026
Windows 10 Update Assistant Elevation of Privilege Vulnerability
ModificadaAlta (7.8)1.4%—Microsoft Windows 10 Update Assistant24/11/202119/8/2026
Windows 10 Update Assistant Elevation of Privilege Vulnerability
ModificadaAlta (7.5)0.97%—Intel Endpoint Management Assistant17/11/202117/6/2026
Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network access.
ModificadaMedia (4.8)0.62%—Wooassist Storefront Footer Text8/11/202117/6/2026
The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed.
ModificadaAlta (8.8)0.59%—IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Doors Next Generation+327/10/202117/6/2026
IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks.
ModificadaAlta (7.8)0.46%—Dell Supportassist FOR Home PCS28/9/202117/6/2026
SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's,
ModificadaAlta (7.1)0.26%—Dell Supportassist Client Consumer28/9/202117/6/2026
Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user under some object directories, but by…
ModificadaAlta (7.8)1.9%—Microsoft Windows 10 Update Assistant12/8/202110/8/2026
Windows 10 Update Assistant Elevation of Privilege Vulnerability
ModificadaMedia (5.4)0.50%—IBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test ManagementIBM Engineering Workflow Management+528/7/202117/6/2026
IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192957.
ModificadaMedia (6.3)0.60%—IBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test ManagementIBM Engineering Workflow Management+528/7/202117/6/2026
IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434.
ModificadaAlta (7.8)0.29%—Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS22/7/202117/6/2026
Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 contain an uncontrolled search path…
ModificadaMedia (5.4)0.50%—IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Collaborative Lifecycle Management+319/7/202117/6/2026
IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235.
ModificadaMedia (6.1)1.1%—Greenbone Security AssistantGreenbone OS21/6/202117/6/2026
Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad.
ModificadaCrítica (9.8)1.3%—Greenbone Security AssistantGreenbone OS21/6/202117/6/2026
Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection.
ModificadaAlta (7.8)0.28%—Intel Driver & Support Assistant9/6/202117/6/2026
Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.3)0.29%—Intel Driver & Support Assistant9/6/202117/6/2026
Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.25%—Intel Driver & Support Assistant9/6/202117/6/2026
Insufficient control flow management in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.98%—Avaya Callback Assist23/4/202117/6/2026
An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7.
Orbitaley — Vulnerabilidades