Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.23% | — | Intel Driver & Support Assistant | 16/2/2023 | 17/6/2026 | Protection mechanism failure in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.17% | — | Opensuse Supportutils | 15/2/2023 | 17/6/2026 | A Cleartext Storage of Sensitive Information vulnerability in suppportutils of SUSE Linux Enterprise Server 12, SUSE Linux Enterprise Server 15, SUSE Linux Enterprise Server 15 SP3 allows attackers that get access to the support logs to gain knowledge of the stored credentials This issue affects: SUSE Linux Enterprise… | |
| Modificada | Media (5.5) | 0.16% | — | Dell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | SupportAssist for Home PCs (versions 3.11.4 and prior) contain an insufficient session expiration Vulnerability. An authenticated non-admin user can be able to obtain the refresh token and that leads to reuse the access token and fetch sensitive information. | |
| Modificada | Media (5.3) | 0.44% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist contains a rate limit bypass issues in screenmeet API third party component. An unauthenticated attacker could potentially exploit this vulnerability and impersonate a legitimate dell customer to a dell support technician. | |
| Modificada | Alta (7.1) | 0.16% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain information disclosure vulnerability. A local malicious user with low privileges could exploit this vulnerability to view and modify sensitive information in the database of the affected… | |
| Modificada | Alta (7.8) | 0.15% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain a privilege escalation vulnerability. A local authenticated malicious user could potentially exploit this vulnerability to elevate privileges and gain total control of the system. | |
| Modificada | Media (5.5) | 0.17% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | |
| Modificada | Media (5.5) | 0.13% | — | Dell Supportassist FOR Business PCSDell Supportassist FOR Home PCS | 11/2/2023 | 17/6/2026 | SupportAssist for Home PCs (version 3.11.4 and prior) and SupportAssist for Business PCs (version 3.2.0 and prior) contain cryptographic weakness vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | |
| Modificada | Alta (7.8) | 0.23% | — | Dell Alienware UpdateDell Command UpdateDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS+1 | 11/2/2023 | 17/6/2026 | Dell SupportAssist Client Consumer (version 3.11.1 and prior), SupportAssist Client Commercial (version 3.2 and prior), Dell Command | Update, Dell Update, and Alienware Update versions before 4.5 contain a Local Privilege Escalation Vulnerability in the Advanced Driver Restore component. A local malicious user may… | |
| Modificada | Media (6.5) | 0.52% | — | Dell Supportassist FOR Home PCS | 10/2/2023 | 17/6/2026 | Dell SupportAssist for Home PCs (version 3.11.2 and prior) contain Overly Permissive Cross-domain Whitelist vulnerability. An authenticated non-admin user could potentially exploit the issue and obtain sensitive information. | |
| Modificada | Alta (7.5) | 1.7% | — | Activesupport Project Activesupport | 9/2/2023 | 17/6/2026 | A regular expression based DoS vulnerability in Active Support <6.1.7.1 and <7.0.4.1. A specially crafted string passed to the underscore method can cause the regular expression engine to enter a state of catastrophic backtracking. This can cause the process to use large amounts of CPU and memory, leading to a… | |
| Modificada | Crítica (9.8) | 74% | — | Zohocorp Manageengine Supportcenter Plus | 1/2/2023 | 17/6/2026 | OS Command injection vulnerability in Support Center Plus 11 via Executor in Action when creating new schedules. | |
| Modificada | Alta (7.8) | 0.19% | — | HP Support Assistant | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files. | |
| Modificada | Alta (7.8) | 0.19% | — | HP Support Assistant | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files. | |
| Modificada | Alta (7.8) | 0.19% | — | HP Support Assistant | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files. | |
| Modificada | Crítica (9.8) | 1.2% | — | Jenkins Testcomplete Support | 26/1/2023 | 17/6/2026 | Jenkins TestComplete support Plugin 2.8.1 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Zohocorp Manageengine Access Manager PlusZohocorp Manageengine Ad360Zohocorp Manageengine Adaudit PlusZohocorp Manageengine Admanager Plus+18 | 18/1/2023 | 31/7/2026 | Multiple Zoho ManageEngine on-premise products, such as ServiceDesk Plus through 14003, allow remote code execution due to use of Apache Santuario xmlsec (aka XML Security for Java) 1.4.1, because the xmlsec XSLT features, by design in that version, make the application responsible for certain security protections,… | |
| Modificada | Media (4.4) | 0.21% | — | Oracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Policy | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle Communications BRM - Elastic Charging Engine product of Oracle Communications Applications (component: Customer, Config, Pricing Manager). Supported versions that are affected are 12.0.0.3.0-12.0.0.7.0. Easily exploitable vulnerability allows high privileged attacker with logon to the… | |
| Modificada | Alta (7.5) | 1.0% | — | Opensuse Travel Support Program | 10/1/2023 | 17/6/2026 | Travel support program is a rails app to support the travel support program of openSUSE (TSP). Sensitive user data (bank account details, password Hash) can be extracted via Ransack query injection. Every deployment of travel-support-program below the patched version is affected. The travel-support-program uses the… | |
| Modificada | Alta (7.8) | 2.8% | — | HP FusionHP Support Assistant | 12/12/2022 | 17/6/2026 | HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up. | |
| Modificada | Media (6.5) | 0.75% | — | Getawesomesupport Awesome Support | 28/11/2022 | 17/6/2026 | The Awesome Support WordPress plugin before 6.1.2 does not ensure that the exported tickets archive to be downloaded belongs to the user making the request, allowing a low privileged user, such as subscriber to download arbitrary exported tickets via an IDOR vector | |
| Modificada | Media (6.5) | 3.2% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer | 23/11/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to a validation bypass that allows users to access sensitive data via the report module. | |
| Modificada | Media (4.9) | 3.7% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter PlusZohocorp Manageengine Assetexplorer | 23/11/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to an XML External Entity attack that leads to Information Disclosure. | |
| Modificada | Alta (7.2) | 81% | — | Zohocorp Manageengine Servicedesk PlusZohocorp Manageengine Servicedesk Plus MSPZohocorp Manageengine Supportcenter Plus | 23/11/2022 | 17/6/2026 | Zoho ManageEngine ServiceDesk Plus versions 13010 and prior are vulnerable to authenticated command injection. This can be exploited by high-privileged users. | |
| Modificada | Baja (3.3) | 0.51% | — | Zohocorp Manageengine Supportcenter Plus | 17/11/2022 | 17/6/2026 | Zoho ManageEngine SupportCenter Plus through 11024 allows low-privileged users to view the organization users list. |