Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
1217 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 5.8% | ⚠ Explotación activa | Veeam Backup & Replication | 17/3/2022 | 17/6/2026 | Improper limitation of path names in Veeam Backup & Replication 9.5U3, 9.5U4,10.x, and 11.x allows remote authenticated users access to internal API functions that allows attackers to upload and execute arbitrary code. | |
| Modificada | Media (6.1) | 1.2% | — | Wpvivid Migration, Backup, Staging | 28/2/2022 | 17/6/2026 | The Migration, Backup, Staging WordPress plugin before 0.9.69 does not have authorisation when adding remote storages, and does not sanitise as well as escape a parameter from such unauthenticated requests before outputting it in admin page, leading to a Stored Cross-Site Scripting issue | |
| Modificada | Alta (7.2) | 1.3% | — | Deliciousbrains Database Backup | 21/2/2022 | 17/6/2026 | The Database Backup for WordPress plugin before 2.5.1 does not properly sanitise and escape the fragment parameter before using it in a SQL statement in the admin dashboard, leading to a SQL injection issue | |
| Modificada | Media (6.5) | 0.84% | — | Intel Active Management Technology FirmwareNetapp Cloud Backup | 9/2/2022 | 17/6/2026 | Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access. | |
| Modificada | Alta (7.8) | 0.30% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+676 | 9/2/2022 | 17/6/2026 | Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.6) | 0.30% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+677 | 9/2/2022 | 17/6/2026 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (6.6) | 0.32% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+677 | 9/2/2022 | 17/6/2026 | Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (6.2) | 0.30% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+677 | 9/2/2022 | 17/6/2026 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (6.7) | 0.30% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+677 | 9/2/2022 | 17/6/2026 | Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.30% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+677 | 9/2/2022 | 17/6/2026 | Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.30% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+677 | 9/2/2022 | 17/6/2026 | Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.33% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.30% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.30% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.30% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.30% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.24% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Media (4.4) | 0.25% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Alta (7.8) | 0.33% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+677 | 9/2/2022 | 17/6/2026 | Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.6) | 0.32% | — | Intel C620a Series FirmwareIntel C620 Series FirmwareIntel C240 Series FirmwareIntel Atom P5000 Series Firmware+12 | 9/2/2022 | 17/6/2026 | Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0,… | |
| Modificada | Media (6.1) | 0.89% | — | Revmakx Backup AND Staging BY WP Time Capsule | 24/1/2022 | 17/6/2026 | The Backup and Staging by WP Time Capsule WordPress plugin before 1.22.7 does not sanitise and escape the error parameter before outputting it back in an admin page, leading to a Reflected Cross-Site Scripting | |
| Modificada | Alta (8.8) | 54% | — | Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+22 | 18/1/2022 | 17/6/2026 | CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists. | |
| Modificada | Crítica (9.8) | 67% | 💥 PoC | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+24 | 18/1/2022 | 17/6/2026 | By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or… | |
| Modificada | Alta (8.8) | 64% | — | Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+22 | 18/1/2022 | 17/6/2026 | JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink… | |
| Analizada | Crítica (9.8) | 97% | 💥 Exploit | Apache Http ServerFedoraproject FedoraDebian LinuxTenable.sc+10 | 20/12/2021 | 17/6/2026 | A carefully crafted request body can cause a buffer overflow in the mod_lua multipart parser (r:parsebody() called from Lua scripts). The Apache httpd team is not aware of an exploit for the vulnerabilty though it might be possible to craft one. This issue affects Apache HTTP Server 2.4.51 and earlier. |