Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

495 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.73%—HP Support Assistant25/6/201917/6/2026
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.
ModificadaAlta (7.8)0.26%—Dell Supportassist FOR Home PCSDell Supportassist FOR Business PCS20/6/201917/6/2026
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread…
ModificadaMedia (4.4)0.33%—Intel Driver & Support Assistant17/5/201917/6/2026
Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (4.4)0.38%—Intel Driver & Support Assistant17/5/201917/6/2026
Insufficient access control in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (6.1)87%💥 ExploitJqueryDebian LinuxDrupalBackdropcms Backdrop+10120/4/201917/6/2026
jQuery before 3.4.0, as used in Drupal, Backdrop CMS, and other products, mishandles jQuery.extend(true, {}, ...) because of Object.prototype pollution. If an unsanitized source object contained an enumerable __proto__ property, it could extend the native Object.prototype.
ModificadaAlta (8)16%💥 PoCDell Supportassist18/4/201917/6/2026
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via…
ModificadaAlta (8.8)0.67%—Dell Supportassist18/4/201917/6/2026
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.
ModificadaAlta (7.3)0.38%—HP Support Assistant27/3/201917/6/2026
HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.
ModificadaMedia (5.5)0.28%—Intel Quickassist Technology FOR Linux14/12/201817/6/2026
Improper memory handling in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaMedia (5.5)0.28%—Intel Quickassist Technology FOR Linux14/12/201817/6/2026
Improper configuration of hardware access in Intel QuickAssist Technology for Linux (all versions) may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaMedia (6.1)0.68%—I4 AI SI Assistant29/11/201817/6/2026
i4 assistant 7.85 allows XSS via a crafted machine name field within iOS settings.
ModificadaMedia (6.5)0.50%—Intel Driver&support Assistant14/11/201817/6/2026
Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.
ModificadaMedia (5.5)0.36%—Intel Quickassist Technology10/10/201817/6/2026
Insufficient access control in driver stack for Intel QuickAssist Technology for Linux before version 4.2 may allow an unprivileged user to potentially disclose information via local access.
ModificadaAlta (7.8)0.35%—Intel Driver & Support Assistant12/9/201817/6/2026
Privilege escalation in file permissions in Intel Driver and Support Assistant before 3.5.0.1 may allow an authenticated user to potentially execute code as administrator via local access.
ModificadaAlta (7.8)0.91%—Portrait Display SDKFujitsu Displayview ClickFujitsu Displayview Click SuiteHP Display Assistant+224/7/201817/6/2026
Applications developed using the Portrait Display SDK, versions 2.30 through 2.34, default to insecure configurations which allow arbitrary code execution. A number of applications developed using the Portrait Displays SDK do not use secure permissions when running. These applications run the component pdiservice.exe…
ModificadaMedia (6.4)0.29%—Lenovo Smart Assistant13/7/201817/6/2026
For the Lenovo Smart Assistant Android app versions earlier than 12.1.82, an attacker with physical access to the smart speaker can, by pressing a specific button sequence, enter factory test mode and enable a web service intended for testing the device. As with most test modes, this provides extra privileges,…
ModificadaAlta (7.8)0.71%—Myswisscomassistant27/3/201817/6/2026
Swisscom MySwisscomAssistant 2.17.1.1065 contains a vulnerability that could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system. This vulnerability exists due to the way .dll files are loaded. It allows an attacker to load a .dll of the attacker's choosing that could execute…
ModificadaAlta (7)0.76%—Dell EMC Supportassist Enterprise12/2/201817/6/2026
Dell EMC SupportAssist Enterprise version 1.1 creates a local Windows user account named "OMEAdapterUser" with a default password as part of the installation process. This unnecessary user account also remains even after an upgrade from v1.1 to v1.2. Access to the management console can be achieved by someone with…
ModificadaMedia (5.5)0.47%—HP Support Assistant23/1/201817/6/2026
The vulnerability allows attacker to extract binaries into protected file system locations in HP Support Assistant before 12.7.26.1.
ModificadaAlta (8.8)0.83%—Jenkins Translation Assistance23/1/201817/6/2026
Jenkins Translation Assistance Plugin 1.15 and earlier did not require form submissions to be submitted via POST, resulting in a CSRF vulnerability allowing attackers to override localized strings displayed to all users on the current Jenkins instance if the victim is a Jenkins administrator.
ModificadaMedia (6)0.31%—Intel Driver & Support Assistant9/1/201817/6/2026
SEMA driver in Intel Driver and Support Assistant before version 3.1.1 allows a local attacker the ability to read and writing to Memory Status registers potentially allowing information disclosure or a denial of service condition.
ModificadaAlta (7.8)0.86%—Sony Content Manager Assistant27/12/201717/6/2026
Untrusted search path vulnerability in Content Manager Assistant for PlayStation version 3.55.7671.0901 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (6.1)0.77%—Home-assistant10/11/201717/6/2026
In Home Assistant before 0.57, it is possible to inject JavaScript code into a persistent notification via crafted Markdown text, aka XSS.
ModificadaMedia (5.5)2.2%💥 ExploitBlackwave Dive Assistant12/9/201717/6/2026
XXE in Dive Assistant - Template Builder in Blackwave Dive Assistant - Desktop Edition 8.0 allows attackers to remotely view local files via a crafted template.xml file.
ModificadaAlta (7.8)0.43%—Synology Assistant18/8/201717/6/2026
Multiple untrusted search path vulnerabilities in installer in Synology Assistant before 6.1-15163 on Windows allows local attackers to execute arbitrary code and conduct DLL hijacking attack via a Trojan horse (1) shfolder.dll, (2) ntmarta.dll, (3) secur32.dll or (4) dwmapi.dll file in the current working directory.