Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.25% | — | Intel NUC Hdmi Firmware Update Tool | 17/11/2021 | 17/6/2026 | Improper access control in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC8i3BE, NUC8i5BE, NUC8i7BE before version 1.78.4.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.13% | — | ABB Update Manager | 28/10/2021 | 17/6/2026 | A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed. | |
| Modificada | Alta (8.7) | 1.5% | — | Linuxfoundation THE Update Framework | 19/10/2021 | 17/6/2026 | python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to `get_one_valid_targetinfo()`. It occurs… | |
| Analizada | Crítica (9) | 100% | ⚠ Explotación activa💥 Exploit | Resf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+35 | 16/9/2021 | 6/8/2026 | A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier. | |
| Analizada | Alta (7.5) | 1.2% | — | Vuelidate Project Vuelidate | 15/9/2021 | 17/6/2026 | vuelidate is vulnerable to Inefficient Regular Expression Complexity | |
| Analizada | Alta (7.8) | 2.9% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 11% | ⚠ Explotación activa💥 Exploit | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa💥 Exploit | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.2) | 0.67% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications. | |
| Modificada | Media (5.3) | 0.80% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data. | |
| Modificada | Media (6.1) | 0.59% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS. | |
| Modificada | Crítica (9.8) | 1.00% | — | Dated News Project Dated News | 13/8/2021 | 17/6/2026 | The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection. | |
| Modificada | Alta (7.8) | 1.9% | — | Microsoft Windows 10 Update Assistant | 12/8/2021 | 10/8/2026 | Windows 10 Update Assistant Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.17% | — | Dell Alienware Command Center ApplicationDell Command | UpdateDell Update/alienware Update | 9/8/2021 | 17/6/2026 | Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbitrary code on the system. | |
| Modificada | Media (6.5) | 0.92% | — | Oracle Peoplesoft Enterprise HCM Candidate Gateway | 21/7/2021 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HCM Candidate Gateway product of Oracle PeopleSoft (component: e-mail notification). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Candidate… | |
| Modificada | Media (6.5) | 1.2% | — | Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+9 | 27/5/2021 | 17/6/2026 | An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command. | |
| Modificada | Media (5.5) | 0.21% | — | Dell System Update | 2/4/2021 | 17/6/2026 | Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to cause the system to run out of memory by running multiple instances of the vulnerable application. | |
| Modificada | Media (6.1) | 6.2% | 💥 Exploit | Triconsole Datepicker Calendar | 25/2/2021 | 17/6/2026 | Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents. | |
| Modificada | Alta (7.5) | 2.2% | — | Date-and-time Project Date-and-time | 28/12/2020 | 17/6/2026 | date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2. | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Crítica (9.1) | 0.86% | — | Bitdefender Update Server | 9/11/2020 | 17/6/2026 | Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior… | |
| Modificada | Alta (7.5) | 3.5% | — | Npmjs Npm-user-validate | 27/10/2020 | 17/6/2026 | This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters. | |
| Modificada | Alta (7.8) | 0.71% | — | Samsung Update | 12/10/2020 | 17/6/2026 | Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication | |
| Modificada | Media (6.6) | 2.7% | — | Spice Project SpiceRedhat OpenstackCanonical Ubuntu LinuxDebian Linux+6 | 7/10/2020 | 17/6/2026 | Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when… |