Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1217 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)5.8%⚠ Explotación activaVeeam Backup & Replication17/3/202217/6/2026
Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code.
ModificadaMedia (6.1)1.2%—Wpvivid Migration, Backup, Staging28/2/202217/6/2026
The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue
ModificadaAlta (7.2)1.3%—Deliciousbrains Database Backup21/2/202217/6/2026
The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue
ModificadaMedia (6.5)0.84%—Intel Active Management Technology FirmwareNetapp Cloud Backup9/2/202217/6/2026
Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access.
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6769/2/202217/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.6)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.6)0.32%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.2)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.7)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.7)0.33%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.30%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.7)0.30%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.30%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaMedia (4.4)0.24%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
ModificadaMedia (4.4)0.25%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
ModificadaAlta (7.8)0.33%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.6)0.32%—Intel C620a Series FirmwareIntel C620 Series FirmwareIntel C240 Series FirmwareIntel Atom P5000 Series Firmware+129/2/202217/6/2026
Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0,…
ModificadaMedia (6.1)0.89%—Revmakx Backup AND Staging BY WP Time Capsule24/1/202217/6/2026
The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting
ModificadaAlta (8.8)54%—Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+2218/1/202217/6/2026
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
ModificadaCrítica (9.8)67%💥 PoCApache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+2418/1/202217/6/2026
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or…
ModificadaAlta (8.8)64%—Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+2218/1/202217/6/2026
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink…
AnalizadaCrítica (9.8)97%💥 ExploitApache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+1020/12/202117/6/2026
A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier.