Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.25%—Intel NUC Hdmi Firmware Update Tool17/11/202117/6/2026
Improper access control in the software installer for the Intel(R) NUC HDMI Firmware Update Tool for NUC8i3BE, NUC8i5BE, NUC8i7BE before version 1.78.4.0.4 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.13%—ABB Update Manager28/10/202117/6/2026
A certificate validation vulnerability in PCM600 Update Manager allows attacker to get unwanted software packages to be installed on computer which has PCM600 installed.
ModificadaAlta (8.7)1.5%—Linuxfoundation THE Update Framework19/10/202117/6/2026
python-tuf is a Python reference implementation of The Update Framework (TUF). In both clients (`tuf/client` and `tuf/ngclient`), there is a path traversal vulnerability that in the worst case can overwrite files ending in `.json` anywhere on the client system on a call to `get_one_valid_targetinfo()`. It occurs…
AnalizadaCrítica (9)100%⚠ Explotación activa💥 ExploitResf Rocky LinuxRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR ARM 64+3516/9/20216/8/2026
A crafted request uri-path can cause mod_proxy to forward the request to an origin server choosen by the remote user. This issue affects Apache HTTP Server 2.4.48 and earlier.
AnalizadaAlta (7.5)1.2%—Vuelidate Project Vuelidate15/9/202117/6/2026
vuelidate is vulnerable to Inefficient Regular Expression Complexity
AnalizadaAlta (7.8)2.9%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)11%⚠ Explotación activa💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+615/9/202110/8/2026
Open Management Infrastructure (OMI) Remote Code Execution Vulnerability
AnalizadaAlta (7.8)2.7%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+615/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
ModificadaAlta (7.2)0.67%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 has incorrect Access Control for confirming various applications.
ModificadaMedia (5.3)0.80%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows Information Disclosure of application registration data.
ModificadaMedia (6.1)0.59%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows XSS.
ModificadaCrítica (9.8)1.00%—Dated News Project Dated News13/8/202117/6/2026
The dated_news (aka Dated News) extension through 5.1.1 for TYPO3 allows SQL Injection.
ModificadaAlta (7.8)1.9%—Microsoft Windows 10 Update Assistant12/8/202110/8/2026
Windows 10 Update Assistant Elevation of Privilege Vulnerability
ModificadaAlta (7.8)0.17%—Dell Alienware Command Center ApplicationDell Command | UpdateDell Update/alienware Update9/8/202117/6/2026
Dell Command | Update, Dell Update, and Alienware Update versions before 4.3 contains an Improper Verification of Cryptographic Signature Vulnerability. A local authenticated malicious user may exploit this vulnerability by executing arbitrary code on the system.
ModificadaMedia (6.5)0.92%—Oracle Peoplesoft Enterprise HCM Candidate Gateway21/7/202117/6/2026
Vulnerability in the PeopleSoft Enterprise HCM Candidate Gateway product of Oracle PeopleSoft (component: e-mail notification). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HCM Candidate…
ModificadaMedia (6.5)1.2%—Redhat LibvirtRedhat Enterprise LinuxRedhat Enterprise Linux EUSRedhat Enterprise Linux FOR IBM Z Systems+927/5/202117/6/2026
An information disclosure vulnerability was found in libvirt in versions before 6.3.0. HTTP cookies used to access network-based disks were saved in the XML dump of the guest domain. This flaw allows an attacker to access potentially sensitive information in the domain configuration via the `dumpxml` command.
ModificadaMedia (5.5)0.21%—Dell System Update2/4/202117/6/2026
Dell System Update (DSU) 1.9 and earlier versions contain a denial of service vulnerability. A local authenticated malicious user with low privileges may potentially exploit this vulnerability to cause the system to run out of memory by running multiple instances of the vulnerable application.
ModificadaMedia (6.1)6.2%💥 ExploitTriconsole Datepicker Calendar25/2/202117/6/2026
Triconsole Datepicker Calendar <3.77 is affected by cross-site scripting (XSS) in calendar_form.php. Attackers can read authentication cookies that are still active, which can be used to perform further attacks such as reading browser history, directory listings, and file contents.
ModificadaAlta (7.5)2.2%—Date-and-time Project Date-and-time28/12/202017/6/2026
date-and-time is an npm package for manipulating date and time. In date-and-time before version 0.14.2, there a regular expression involved in parsing which can be exploited to to cause a denial of service. This is fixed in version 0.14.2.
ModificadaAlta (7.8)0.34%—Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+2924/11/202017/6/2026
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaCrítica (9.1)0.86%—Bitdefender Update Server9/11/202017/6/2026
Insufficient validation in the Bitdefender Update Server and BEST Relay components of Bitdefender Endpoint Security Tools versions prior to 6.6.20.294 allows an unprivileged attacker to bypass the in-place mitigations and interact with hosts on the network. This issue affects: Bitdefender Update Server versions prior…
ModificadaAlta (7.5)3.5%—Npmjs Npm-user-validate27/10/202017/6/2026
This affects the package npm-user-validate before 1.0.1. The regex that validates user emails took exponentially longer to process long input strings beginning with @ characters.
ModificadaAlta (7.8)0.71%—Samsung Update12/10/202017/6/2026
Samsung Update 3.0.2.0 ~ 3.0.32.0 has a vulnerability that allows privilege escalation as commands crafted by attacker are executed while the engine deserializes the data received during inter-process communication
ModificadaMedia (6.6)2.7%—Spice Project SpiceRedhat OpenstackCanonical Ubuntu LinuxDebian Linux+67/10/202017/6/2026
Multiple buffer overflow vulnerabilities were found in the QUIC image decoding process of the SPICE remote display system, before spice-0.14.2-1. Both the SPICE client (spice-gtk) and server are affected by these flaws. These flaws allow a malicious client or server to send specially crafted messages that, when…
Orbitaley — Vulnerabilidades