Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
495 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Alta (7.8) | 0.86% | — | HP Support Assistant | 16/2/2022 | 17/6/2026 | Potential security vulnerabilities including compromise of integrity, and allowed communication with untrusted clients has been identified in HP Support Assistant software. | |
| Modificada | Media (5.5) | 0.23% | — | BD Pyxis Anesthesia Station ES FirmwareBD Pyxis Anesthesia Station 4000 FirmwareBD Pyxis Cato FirmwareBD Pyxis Ciisafe Firmware+20 | 11/2/2022 | 17/6/2026 | Hardcoded credentials are used in specific BD Pyxis products. If exploited, threat actors may be able to gain access to the underlying file system and could potentially exploit application files for information that could be used to decrypt application credentials or gain access to electronic protected health… | |
| Modificada | Media (5.5) | 0.28% | — | HP Support Assistant | 28/1/2022 | 17/6/2026 | Potential arbitrary file deletion vulnerability has been identified in HP Support Assistant software. | |
| Modificada | Media (5.3) | 0.78% | — | Samsung S Assistant | 10/1/2022 | 17/6/2026 | Improper access control vulnerability in S Assistant prior to version 7.5 allows attacker to remotely get senstive information. | |
| Modificada | Crítica (9.8) | 1.1% | — | Uipath Assistant | 14/12/2021 | 17/6/2026 | An issue was discovered in UiPath Assistant 21.4.4. User-controlled data supplied to the --process-start argument of the URI handler for uipath-assistant:// is not correctly encoded, resulting in attacker-controlled content being injected into the error message displayed (when the injected content does not match an… | |
| Modificada | Crítica (9.8) | 1.8% | — | Uipath Assistant | 14/12/2021 | 17/6/2026 | UiPath Assistant 21.4.4 will load and execute attacker controlled data from the file path supplied to the --dev-widget argument of the URI handler for uipath-assistant://. This allows an attacker to execute code on a victim's machine or capture NTLM credentials by supplying a networked or WebDAV file path. | |
| Modificada | Alta (7.1) | 0.85% | — | Microsoft Windows 10 Update Assistant | 24/11/2021 | 19/8/2026 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 1.4% | — | Microsoft Windows 10 Update Assistant | 24/11/2021 | 19/8/2026 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 0.97% | — | Intel Endpoint Management Assistant | 17/11/2021 | 17/6/2026 | Improper input validation for Intel(R) EMA before version 1.5.0 may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Modificada | Media (4.8) | 0.62% | — | Wooassist Storefront Footer Text | 8/11/2021 | 17/6/2026 | The Storefront Footer Text WordPress plugin through 1.0.1 does not sanitize and escape the "Footer Credit Text" added to pages, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered-html capability is disallowed. | |
| Modificada | Alta (8.8) | 0.59% | — | IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Doors Next Generation+3 | 27/10/2021 | 17/6/2026 | IBM Jazz Team Server products is vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. | |
| Modificada | Alta (7.8) | 0.46% | — | Dell Supportassist FOR Home PCS | 28/9/2021 | 17/6/2026 | SupportAssist Client version 3.8 and 3.9 contains an Untrusted search path vulnerability that allows attackers to load an arbitrary .dll file via .dll planting/hijacking, only by a separate administrative action that is not a default part of the SOSInstallerTool.exe installation for executing arbitrary dll's, | |
| Modificada | Alta (7.1) | 0.26% | — | Dell Supportassist Client Consumer | 28/9/2021 | 17/6/2026 | Dell SupportAssist Client Consumer versions 3.9.13.0 and any versions prior to 3.9.13.0 contain an arbitrary file deletion vulnerability that can be exploited by using the Windows feature of NTFS called Symbolic links. Symbolic links can be created by any(non-privileged) user under some object directories, but by… | |
| Modificada | Alta (7.8) | 1.9% | — | Microsoft Windows 10 Update Assistant | 12/8/2021 | 10/8/2026 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test ManagementIBM Engineering Workflow Management+5 | 28/7/2021 | 17/6/2026 | IBM Jazz Foundation products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 192957. | |
| Modificada | Media (6.3) | 0.60% | — | IBM Engineering Lifecycle Optimization - Engineering InsightsIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Test ManagementIBM Engineering Workflow Management+5 | 28/7/2021 | 17/6/2026 | IBM Jazz Foundation products are vulnerable to server side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially leading to network enumeration or facilitating other attacks. IBM X-Force ID: 192434. | |
| Modificada | Alta (7.8) | 0.29% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 22/7/2021 | 17/6/2026 | Dell SupportAssist for Business PCs versions 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3 and Dell SupportAssist for Home PCs version 2.0, 2.0.1, 2.0.2, 2.1, 2.1.1, 2.1.2, 2.1.3, 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, 3.2.1, 3.2.2, 3.3, 3.3.1, 3.3.2, 3.3.3, 3.4 contain an uncontrolled search path… | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Lifecycle OptimizationIBM Engineering Requirements Quality Assistant On-premisesIBM Engineering Workflow ManagementIBM Rational Collaborative Lifecycle Management+3 | 19/7/2021 | 17/6/2026 | IBM Jazz Foundation and IBM Engineering products are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 198235. | |
| Modificada | Media (6.1) | 1.1% | — | Greenbone Security AssistantGreenbone OS | 21/6/2021 | 17/6/2026 | Greenbone Security Assistant (GSA) before 8.0.2 and Greenbone OS (GOS) before 5.0.10 allow XSS during 404 URL handling in gsad. | |
| Modificada | Crítica (9.8) | 1.3% | — | Greenbone Security AssistantGreenbone OS | 21/6/2021 | 17/6/2026 | Greenbone Security Assistant (GSA) before 7.0.3 and Greenbone OS (GOS) before 5.0.0 allow Host Header Injection. | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Driver & Support Assistant | 9/6/2021 | 17/6/2026 | Improper link resolution before file access in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.29% | — | Intel Driver & Support Assistant | 9/6/2021 | 17/6/2026 | Uncontrolled search path element in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.25% | — | Intel Driver & Support Assistant | 9/6/2021 | 17/6/2026 | Insufficient control flow management in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.5) | 0.98% | — | Avaya Callback Assist | 23/4/2021 | 17/6/2026 | An XML External Entities (XXE)vulnerability in Callback Assist could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Callback Assist includes all 4.0.x versions before 4.7.1.1 Patch 7. |