Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
538 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Parallels | 21/1/2020 | 17/6/2026 | Parallels 13 uses cleartext HTTP as part of the update process, allowing man-in-the-middle attacks. Users of out-of-date versions are presented with a pop-up window for a parallels_updates.xml file on the http://update.parallels.com web site. | |
| Modificada | Alta (7.8) | 0.50% | — | Parallels Desktop | 7/1/2020 | 17/6/2026 | This vulnerability allows local attackers to escalate privileges on affected installations of Parallels Desktop Parallels Desktop version 14.1.3 (45485). An attacker must first obtain the ability to execute low-privileged code on the target guest system in order to exploit this vulnerability. The specific flaw exists… | |
| Modificada | Media (6.1) | 0.79% | — | Parallels Plesk Panel | 13/11/2019 | 17/6/2026 | Parallels Plesk Panel 9.5 allows XSS in target/locales/tr-TR/help/index.htm? via the "fileName" parameter. | |
| Modificada | Alta (7.5) | 3.1% | — | Accio Responsive Onepage Parallax Site Template Project Accio Responsive Onepage Parallax Site Template | 11/10/2019 | 17/6/2026 | The ThemeMakers Accio Responsive Parallax One Page Site Template component through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.1% | — | Accio ONE Page Parallax Responsive Theme Project Accio ONE Page Parallax Responsive Theme | 11/10/2019 | 17/6/2026 | The ThemeMakers Accio One Page Parallax Responsive theme through 2015-05-15 for WordPress allows remote attackers to obtain sensitive information (such as user_login, user_pass, and user_email values) via a direct request for the wp-content/uploads/tmm_db_migrate/wp_users.dat URI. | |
| Modificada | Alta (7.5) | 3.2% | — | Para Antioch | 20/9/2019 | 17/6/2026 | The Antioch theme through 2014-09-07 for WordPress allows arbitrary file downloads via the file parameter to lib/scripts/download.php. | |
| Modificada | Crítica (9.8) | 4.3% | — | Anjlab Paranoid2 | 14/7/2019 | 17/6/2026 | The paranoid2 gem 1.1.6 for Ruby, as distributed on RubyGems.org, included a code-execution backdoor inserted by a third party. The current version, without this backdoor, is 1.1.5. | |
| Modificada | Alta (7.1) | 1.2% | — | Medtronic Minimed 508 FirmwareMedtronic Minimed Paradigm 511 FirmwareMedtronic Minimed Paradigm 512 FirmwareMedtronic Minimed Paradigm 712 Firmware+15 | 28/6/2019 | 17/6/2026 | Medtronic MiniMed Insulin Pumps are designed to communicate using a wireless RF with other devices, such as blood glucose meters, glucose sensor transmitters, and CareLink USB devices. This wireless RF communication protocol does not properly implement authentication or authorization. An attacker with adjacent access… | |
| Modificada | Media (6.1) | 0.93% | — | Parallax Scroll Project Parallax Scroll | 5/2/2019 | 17/6/2026 | In the Parallax Scroll (aka adamrob-parallax-scroll) plugin before 2.1 for WordPress, includes/adamrob-parralax-shortcode.php allows XSS via the title text. ("parallax" has a spelling change within the PHP filename.) | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Parallel StudioIntel Parallel Studio XE | 14/12/2018 | 17/6/2026 | Improper directory permissions in the installer for the Intel Parallel Studio before 2019 Gold may allow authenticated users to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.38% | — | Intel Parallel Studio XE | 14/11/2018 | 17/6/2026 | Heap overflow in Intel Trace Analyzer 2018 in Intel Parallel Studio XE 2018 Update 3 may allow an authenticated user to potentially escalate privileges via local access. | |
| Modificada | Alta (8.8) | 4.4% | — | ParamikoRedhat Ansible TowerRedhat Virtualization HostRedhat Enterprise Linux Desktop+7 | 8/10/2018 | 17/6/2026 | Paramiko version 2.4.1, 2.3.2, 2.2.3, 2.1.5, 2.0.8, 1.18.5, 1.17.6 contains a Incorrect Access Control vulnerability in SSH server that can result in RCE. This attack appear to be exploitable via network connectivity. | |
| Modificada | Media (5.3) | 0.71% | — | Medtronicdiabetes 508 Minimed Insulin Pump FirmwareMedtronicdiabetes 522 Paradigm Real-time FirmwareMedtronicdiabetes 722 Paradigm Real-time FirmwareMedtronicdiabetes 523 Paradigm Revel Firmware+5 | 13/8/2018 | 17/6/2026 | Medtronic MiniMed MMT devices when paired with a remote controller and having the “easy bolus” and “remote bolus” options enabled (non-default), are vulnerable to a capture-replay attack. An attacker can capture the wireless transmissions between the remote controller and the pump and replay them to cause an insulin… | |
| Modificada | Media (4.8) | 0.47% | — | Medtronic Minimed Paradigm Revel Mmt-523k FirmwareMedtronic Minimed Paradigm Revel Mmt-723k FirmwareMedtronic Minimed Paradigm Revel Mmt-723 FirmwareMedtronic Minimed 530g Mmt-551 Firmware+5 | 13/8/2018 | 17/6/2026 | Communications between Medtronic MiniMed MMT pumps and wireless accessories are transmitted in cleartext. A sufficiently skilled attacker could capture these transmissions and extract sensitive information, such as device serial numbers. | |
| Modificada | Alta (7.5) | 1.1% | — | Nexpara Project Nexpara | 9/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for NEXPARA, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.8) | 0.38% | — | IBM General Parallel File SystemIBM Spectrum Scale | 13/6/2018 | 17/6/2026 | A vulnerability in GSKit affects IBM Spectrum Scale 4.1.1, 4.2.0, 4.2.1, 4.2.3, and 5.0.0 that could allow a local attacker to obtain control of the Spectrum Scale daemon and to access and modify files in the Spectrum Scale file system, and possibly to obtain administrator privileges on the node. IBM X-Force ID:… | |
| Modificada | Crítica (9.8) | 27% | — | ParamikoRedhat Ansible EngineRedhat CloudformsRedhat Virtualization+7 | 13/3/2018 | 17/6/2026 | transport.py in the SSH server implementation of Paramiko before 1.17.6, 1.18.x before 1.18.5, 2.0.x before 2.0.8, 2.1.x before 2.1.5, 2.2.x before 2.2.3, 2.3.x before 2.3.2, and 2.4.x before 2.4.1 does not properly check whether authentication is completed before processing other requests, as demonstrated by… | |
| Modificada | Baja (3.3) | 0.38% | — | IBM Spectrum ScaleIBM General Parallel File System | 2/3/2018 | 17/6/2026 | IBM Spectrum Scale 4.1.1 and 4.2.0 - 4.2.3 could allow a local unprivileged user access to information located in dump files. User data could be sent to IBM during service engagements. IBM X-Force ID: 133378. | |
| Modificada | Alta (7.5) | 2.0% | — | Parallels Remote Application Server | 28/2/2018 | 17/6/2026 | In the web interface of Parallels Remote Application Server (RAS) 15.5 Build 16140, a vulnerability exists due to improper validation of the file path when requesting a resource under the "RASHTML5Gateway" directory. A remote, unauthenticated attacker could exploit this weakness to read arbitrary files from the… | |
| Modificada | Media (5.4) | 0.60% | — | Parallelus Salutation | 17/11/2017 | 17/6/2026 | Stored XSS in Salutation Responsive WordPress + BuddyPress Theme version 3.0.15 could allow logged-in users to do almost anything an admin can | |
| Modificada | Media (6.5) | 0.78% | — | Jenkins Parameterized Trigger | 5/10/2017 | 17/6/2026 | Parameterized Trigger Plugin fails to check Item/Build permission: The Parameterized Trigger Plugin did not check the build authentication it was running as and allowed triggering any other project in Jenkins. | |
| Modificada | Media (5.5) | 0.79% | — | Eparaksts Edoc-librariesEparaksts Eparakstitajs 3 | 10/4/2017 | 17/6/2026 | LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to read arbitrary files via crafted EDOC files. | |
| Modificada | Media (5.5) | 0.62% | — | Eparaksts Edoc-librariesEparaksts Eparakstitajs 3 | 10/4/2017 | 17/6/2026 | LVRTC eParakstitajs 3.0 (1.3.0) and edoc-libraries-2.5.4_01 allow attackers to write to arbitrary files via crafted EDOC files. | |
| Analizada | Alta (8.1) | 99% | ⚠ Explotación activa | Microsoft Server Message BlockSiemens Acuson P300 FirmwareSiemens Acuson P500 FirmwareSiemens Acuson Sc2000 Firmware+5 | 17/3/2017 | 17/6/2026 | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote… | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa | Microsoft Windows 10 1507Microsoft Windows 10 1511Microsoft Windows 10 1607Microsoft Windows 7+14 | 17/3/2017 | 17/6/2026 | The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted… |