Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
3834 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.12% | — | Intel Killer Performance SuiteAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Aplazada | Media (5.4) | 0.11% | — | Intel Rapid Storage Technology ApplicationAI | 11/11/2025 | 17/6/2026 | Insecure inherited permissions for some Intel(R) Rapid Storage Technology Application before version 20.0.1021 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This… | |
| Analizada | Baja (2.1) | 0.25% | — | Intel Computing Improvement Program | 11/11/2025 | 17/6/2026 | Improper access control for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with a privileged user combined with a high complexity attack may enable data exposure. This result may potentially occur via… | |
| Analizada | Baja (2.3) | 0.19% | — | Intel Computing Improvement Program | 11/11/2025 | 17/6/2026 | Improper privilege management for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable data manipulation. This result may… | |
| Analizada | Alta (8.7) | 0.32% | — | Intel Computing Improvement Program | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Baja (2) | 0.13% | — | Intel NPU DriversAI | 11/11/2025 | 17/6/2026 | Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before version 32.0.100.4023 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable… | |
| Analizada | Media (5.7) | 0.14% | — | Intel Computing Improvement Program | 11/11/2025 | 17/6/2026 | External control of file name or path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may… | |
| Aplazada | Media (4.8) | 0.12% | — | Intel Vtune ProfilerAI | 11/11/2025 | 17/6/2026 | Improper input validation for some Intel VTune Profiler before version 2025.1 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable data manipulation. This result may potentially occur via local… | |
| Analizada | Media (5.4) | 0.14% | — | Intel Computing Improvement Program | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) CIP software before version WIN_DCA_2.4.0.11001 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable local code execution. This result may… | |
| Aplazada | Alta (8.5) | 0.24% | — | Intel Processor Identification UtilityAI | 11/11/2025 | 17/6/2026 | Use of unmaintained third party components for some Intel(R) Processor Identification Utility before version 8.0.43 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user combined with a low complexity attack may enable escalation of privilege. This… | |
| Aplazada | Media (4.3) | 0.27% | — | Cisco Unified Intelligence CenterAI | 5/11/2025 | 17/6/2026 | A vulnerability in the API subsystem of Cisco Unified Intelligence Center could allow an authenticated, remote attacker to obtain sensitive information from an affected system. This vulnerability is due to improper validation of requests to certain API endpoints. An attacker could exploit this vulnerability by sending… | |
| Analizada | Alta (8.4) | 0.36% | — | Oracle Business Intelligence | 21/10/2025 | 17/6/2026 | Vulnerability in the Oracle Business Intelligence Enterprise Edition product of Oracle Analytics (component: Analytics Web Administration). Supported versions that are affected are 7.6.0.0.0 and 8.2.0.0.0. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise… | |
| Aplazada | Crítica (9.3) | 1.9% | — | Bytevalue Intelligent Flow Control RouterAI | 15/10/2025 | 17/6/2026 | BYTEVALUE Intelligent Flow Control Router contains a command injection vulnerability via the /goform/webRead/open endpoint. The `path` parameter is not properly validated and is echoed into a shell context, allowing an attacker to inject and execute arbitrary shell commands on the device. Successful exploitation can… | |
| Aplazada | Alta (7.6) | 0.26% | — | Intel Uefi FirmwareAI | 14/10/2025 | 17/6/2026 | Clevo’s UEFI firmware update packages, including B10717.exe, inadvertently contained private signing keys used for Boot Guard and Boot Policy Manifest verification. The exposure of these keys could allow attackers to sign malicious firmware that appears trusted by affected systems, undermining the integrity of the… | |
| Analizada | Alta (7.8) | 0.09% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm Mdm9650 FirmwareQualcomm Msm8996au Firmware+315 | 9/10/2025 | 17/6/2026 | Memory corruption during PlayReady APP usecase while processing TA commands. | |
| Aplazada | Alta (7.2) | 0.22% | — | HP Sure StartAIHP BiosAIIntel Flash DescriptorAI | 7/10/2025 | 17/6/2026 | A potential security vulnerability has been identified in HP Sure Start’s protection of the Intel Flash Descriptor in certain HP PC products, which might allow security bypass, arbitrary code execution, loss of integrity or confidentiality, or denial of service. HP is releasing BIOS updates to mitigate the potential… | |
| Aplazada | Media (6.4) | 0.20% | — | Fintelligence CalculatorAI | 3/10/2025 | 17/6/2026 | The Fintelligence Calculator plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'fintelligence-calculator' shortcode in all versions up to, and including, 1.0.3 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for… | |
| Analizada | Alta (7.8) | 0.08% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+188 | 24/9/2025 | 17/6/2026 | memory corruption while loading a PIL authenticated VM, when authenticated VM image is loaded without maintaining cache coherency. | |
| Analizada | Crítica (9.8) | 0.40% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 17/6/2026 | Memory corruption when the UE receives an RTP packet from the network, during the reassembly of NALUs. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+223 | 24/9/2025 | 25/9/2026 | Information disclosure while decoding RTP packet received by UE from the network, when payload length mentioned is greater than the available buffer length. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Sm8750 FirmwareQualcomm Sm8750p FirmwareQualcomm Sm8850 FirmwareQualcomm Sm8850p Firmware+169 | 24/9/2025 | 25/9/2026 | Information disclosure when UE receives the RTP packet from the network, while decoding and reassembling the fragments from RTP packet. | |
| Analizada | Alta (7.1) | 0.08% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+283 | 24/9/2025 | 25/9/2026 | Cryptographic issue while performing RSA PKCS padding decoding. | |
| Modificada | Baja (3.8) | 0.20% | — | Intelliants Subrion CMS | 11/9/2025 | 17/6/2026 | An issue was discovered in Subrion CMS 4.2.1, allowing authenticated adminitrators or moderators with access to the built-in Run SQL Query feature under the SQL Tool admin panel - to gain escalated privileges in the context of the SQL query tool. | |
| Analizada | Alta (8.4) | 3.3% | — | Intelbras IWR 3000n Firmware | 10/9/2025 | 17/6/2026 | Intelbras IWR 3000N 1.9.8 exposes the Wi-Fi password in plaintext via the /api/wireless endpoint. Any unauthenticated user on the local network can directly obtain the Wi-Fi network password by querying this endpoint. | |
| Aplazada | Baja (3.2) | 0.15% | — | Intel RdrandAIAMD SEV SNPAI | 5/9/2025 | 17/6/2026 | Incomplete cleanup after loading a CPU microcode patch may allow a privileged attacker to degrade the entropy of the RDRAND instruction, potentially resulting in loss of integrity for SEV-SNP guests. |