Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

40 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.7)0.21%—Intel Integrated Performance Primitives CryptographyIntel SGX DcapIntel SGX PSWIntel SGX SDK9/6/202117/6/2026
Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.
ModificadaMedia (6.5)0.59%—Intel Software Guard Extensions Data Center Attestation Primitives12/11/202017/6/2026
Improper conditions check in the Intel(R) SGX DCAP software before version 1.6 may allow an unauthenticated user to potentially enable denial of service via adjacent access.
ModificadaMedia (5.5)0.39%—Intel Software Guard ExtensionsIntel Software Guard Extensions Data Center Attestation Primitives13/6/201917/6/2026
Insufficient input validation in the Intel(R) SGX driver for Linux may allow an authenticated user to potentially enable a denial of service via local access.
ModificadaMedia (5.5)0.33%—Intel Integrated Performance Primitives5/12/201817/6/2026
Data leakage in cryptographic libraries for Intel IPP before 2019 update1 release may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (4.7)0.29%—Intel Integrated Performance Primitives Cryptography5/6/201817/6/2026
Some implementations in Intel Integrated Performance Primitives Cryptography Library before version 2018 U3.1 do not properly ensure constant execution time.
ModificadaAlta (7.3)0.97%—Intel AdvisorCryptography FOR Intel Integrated Performance PrimitivesIntel Data Analytics Acceleration LibraryIntel Inspector+828/2/201717/6/2026
Intel PSET Application Install wrapper of Intel Parallel Studio XE, Intel System Studio, Intel VTune Amplifier, Intel Inspector, Intel Advisor, Intel MPI Library, Intel Trace Analyzer and Collector, Intel Integrated Performance Primitives, Cryptography for Intel Integrated Performance Primitives, Intel Math Kernel…
ModificadaMedia (5.5)0.31%—Intel Integrated Performance Primitives10/10/201617/6/2026
Intel Integrated Performance Primitives (aka IPP) Cryptography before 9.0.4 makes it easier for local users to discover RSA private keys via a side-channel attack.
ModificadaMedia (4.3)4.6%—Microsoft Enhanced Mitigation Experience Toolkit29/11/201317/6/2026
Microsoft Enhanced Mitigation Experience Toolkit (EMET) before 4.0 uses predictable addresses for hooked functions, which makes it easier for context-dependent attackers to defeat the ASLR protection mechanism via a return-oriented programming (ROP) attack.
ModificadaAlta (7.5)2.3%—Bouzouste Primitive CMS22/9/201016/6/2026
cms_write.php in Primitive CMS 1.0.9 does not properly restrict access, which allows remote attackers to gain administrative privileges via a direct request. NOTE: this vulnerability can be leveraged to conduct cross-site scripting attacks, as demonstrated using the (1) title, (2) content, and (3) menutitle parameters.
ModificadaMedia (6.5)0.90%—Bouzouste Primitive CMS22/9/201016/6/2026
Multiple SQL injection vulnerabilities in cms_write.php in Primitive CMS 1.0.9 allow remote authenticated administrators to execute arbitrary SQL commands via the (1) title and (2) menutitle parameters. NOTE: this can be leveraged with CVE-2010-3483 to conduct attacks without authentication.
ModificadaAlta (7.5)0.95%—Miticdjd Apoll25/2/200916/6/2026
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the pass parameter.
ModificadaAlta (7.5)0.99%—Miticdjd Apoll25/2/200916/6/2026
SQL injection vulnerability in admin/index.php in Dragan Mitic Apoll 0.7 beta and 0.7.5 allows remote attackers to execute arbitrary SQL command via the user parameter.
ModificadaAlta (7.5)1.4%—Mitisoft9/1/200716/6/2026
MitiSoft stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for access_MS/MitiSoft.mdb.
ModificadaBaja (2.6)2.0%—Cisco Guard Ddos Mitigation Appliance21/9/200616/6/2026
Cross-site scripting (XSS) vulnerability in Cisco Guard DDoS Mitigation Appliance before 5.1(6), when anti-spoofing is enabled, allows remote attackers to inject arbitrary web script or HTML via certain character sequences in a URL that are not properly handled when the appliance sends a meta-refresh.
ModificadaMedia (5)1.6%—Toplayer Attack Mitigator22/7/200416/6/2026
Attack Mitigator IPS 5500 3.11.008, and possibly other versions, when configured in a one-armed routing configuration, allows remote attackers to cause a denial of service (CPU consumption) via a large number of HTTP requests.