Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2532▼ 361 respecto a la semana anterior
Críticas / altas1338▲ 69 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
210 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.19% | — | Tanium Endpoint Configuration Toolset SolutionTanium Patch Endpoint Tools | 10/2/2026 | 17/6/2026 | Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. | |
| Analizada | Alta (7.8) | 0.19% | — | Tanium Patch Endpoint Tools | 9/2/2026 | 17/6/2026 | Tanium addressed a local privilege escalation vulnerability in Patch Endpoint Tools. | |
| Analizada | Media (6.5) | 0.35% | — | Tanium Patch | 5/2/2026 | 17/6/2026 | Tanium addressed an incorrect default permissions vulnerability in Patch. | |
| Analizada | Media (4.3) | 0.27% | — | Tanium Patch | 5/2/2026 | 17/6/2026 | Tanium addressed an improper access controls vulnerability in Patch. | |
| Aplazada | Alta (8.5) | 0.15% | — | Hi-rez Studios HipatchserviceAI | 21/1/2026 | 17/6/2026 | Hi-Rez Studios 5.1.6.3 contains an unquoted service path vulnerability in the HiPatchService that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions. | |
| Aplazada | Alta (8.2) | 0.36% | — | SAP WEB DispatcherAISAP ICMAI | 9/12/2025 | 17/6/2026 | SAP Web Dispatcher and ICM may expose internal testing interfaces that are not intended for production. If enabled, unauthenticated attackers could exploit them to access diagnostics, send crafted requests, or disrupt services. This vulnerability has a high impact on confidentiality, availability and low impact on… | |
| Aplazada | Alta (7.5) | 0.54% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAISAP Content ServerAI | 9/12/2025 | 17/6/2026 | SAP Web Dispatcher, Internet Communication Manager (ICM), and SAP Content Server allow an unauthenticated user to exploit logical errors that lead to a memory corruption vulnerability. This results in high impact on the availability with no impact on confidentiality or integrity of the application. | |
| Analizada | Media (6.2) | 0.40% | — | Cnblogs Pdfpatcher | 17/11/2025 | 17/6/2026 | PDFPatcher executable does not validate user-supplied file paths, allowing directory traversal attacks allowing attackers to upload arbitrary files to arbitrary locations. | |
| Analizada | Alta (7.1) | 0.40% | — | Cnblogs Pdfpatcher | 17/11/2025 | 17/6/2026 | PDFPatcher thru 1.1.3.4663 executable's XML bookmark import functionality does not restrict XML external entity (XXE) references. The application uses .NET's XmlDocument class without disabling external entity resolution, enabling attackers to: Read arbitrary files from the victim's filesystem, exfiltrate sensitive… | |
| Aplazada | Alta (7.5) | 0.51% | — | WP DispatcherAI | 3/10/2025 | 17/6/2026 | The WP Dispatcher plugin for WordPress is vulnerable to arbitrary file uploads due to missing file type validation in the wp_dispatcher_process_upload() function in all versions up to, and including, 1.2.0. This makes it possible for authenticated attackers, with Subscriber-level access and above, to upload arbitrary… | |
| Aplazada | Alta (8.8) | 0.34% | — | WP DispatcherAI | 3/10/2025 | 17/6/2026 | The WP Dispatcher plugin for WordPress is vulnerable to SQL Injection via the ‘id’ parameter in all versions up to, and including, 1.2.0 due to insufficient escaping on the user supplied parameter and lack of sufficient preparation on the existing SQL query. This makes it possible for authenticated attackers, with… | |
| Aplazada | Alta (7.3) | 0.39% | — | Lenovo DispatcherAI | 11/9/2025 | 17/6/2026 | A potential insufficient access control vulnerability was reported in the Lenovo Dispatcher 3.0 and Dispatcher 3.1 drivers used by some Lenovo consumer notebooks that could allow an authenticated local user to execute code with elevated privileges. The Lenovo Dispatcher 3.2 driver is not affected. This vulnerability… | |
| Aplazada | Baja (1.3) | 0.30% | — | JsondiffpatchAI | 11/9/2025 | 17/6/2026 | Versions of the package jsondiffpatch before 0.7.2 are vulnerable to Cross-site Scripting (XSS) via HtmlFormatter::nodeBegin. An attacker can inject malicious scripts into HTML payloads that may lead to code execution if untrusted payloads were used as source for the diff, and the result renderer using the built-in… | |
| Aplazada | Media (6.4) | 0.11% | — | AMD CPU ROM Microcode Patch LoaderAI | 27/6/2025 | 17/6/2026 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious microcode, potentially resulting in loss of integrity of x86 instruction execution, loss of confidentiality and integrity of data in x86 CPU privileged context and compromise… | |
| Aplazada | Media (4.6) | 0.29% | — | Hexagon Hxgn Oncall Dispatch Advantage WEBAIHexagon Hxgn Oncall Dispatch Advantage MobileAI | 25/6/2025 | 17/6/2026 | Hexagon HxGN OnCall Dispatch Advantage (Web) v10.2309.03.00264 and Hexagon HxGN OnCall Dispatch Advantage (Mobile) v10.2402 are vulnerable to Cross Site Scripting (XSS) which allows a remote authenticated attacker with access to the Broadcast (Person) functionality to execute arbitrary code. | |
| Aplazada | Alta (7.3) | 0.27% | — | Patch MY PC Home UpdaterAI | 9/5/2025 | 17/6/2026 | A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects some unknown processing in the library… | |
| Analizada | Media (5.3) | 0.55% | — | Oracle Fleet Patching AND Provisioning | 15/4/2025 | 17/6/2026 | Vulnerability in the Fleet Patching and amp; Provisioning component of Oracle Database Server. Supported versions that are affected are 19.3-19.26. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Fleet Patching and amp; Provisioning. Successful attacks of… | |
| Aplazada | Media (4.9) | 0.38% | — | SAP WEB DispatcherAISAP Internet Communication ManagerAI | 11/3/2025 | 17/6/2026 | SAP Web Dispatcher and Internet Communication Manager allow an attacker with administrative privileges to enable debugging trace mode with a specific parameter value. This exposes unencrypted passwords in the logs, causing a high impact on the confidentiality of the application. There is no impact on integrity or… | |
| Aplazada | Alta (7.2) | 0.53% | — | AMD CPU ROM Microcode Patch LoaderAI | 3/2/2025 | 17/6/2026 | Improper signature verification in AMD CPU ROM microcode patch loader may allow an attacker with local administrator privilege to load malicious CPU microcode resulting in loss of confidentiality and integrity of a confidential guest running under AMD SEV-SNP. | |
| Aplazada | Media (5.3) | 0.16% | — | IBM Bigfix Patch Download Plug-insAI | 23/1/2025 | 17/6/2026 | BigFix Patch Download Plug-ins are affected by path traversal vulnerability. The application could allow operators to download files from a local repository which is vulnerable to path traversal attacks. | |
| Aplazada | Baja (2.8) | 0.08% | — | IBM Bigfix Patch Download Plug-insAI | 23/1/2025 | 17/6/2026 | BigFix Patch Download Plug-ins are affected by an insecure protocol support. The application can allow improper handling of SSL certificates validation. | |
| Aplazada | Baja (2.5) | 0.13% | — | IBM Bigfix Patch Download Plug-insAI | 23/1/2025 | 17/6/2026 | BigFix Patch Download Plug-ins are affected by an insecure package which is susceptible to XML injection attacks. This allows an attacker to exploit this vulnerability by injecting malicious XML content, which can lead to various issues including denial of service and unauthorized access. | |
| Aplazada | Baja (2.5) | 0.14% | — | IBM Bigfix Patch Download Plug-insAI | 23/1/2025 | 17/6/2026 | BigFix Patch Download Plug-ins are affected by insecure support for file URI scheme. It could allow a malicious operator to attempt to download files using the file:// URI scheme. | |
| Aplazada | Baja (2.5) | 0.09% | — | IBM Bigfix Patch Download Plug-insAI | 23/1/2025 | 17/6/2026 | BigFix Patch Download Plug-ins are affected by an arbitrary file download vulnerability. It could allow a malicious operator to download files from arbitrary URLs without any proper validation or allowlist controls. | |
| Aplazada | Baja (2.5) | 0.12% | — | IBM Bigfix Patch Download Plug-insAI | 23/1/2025 | 17/6/2026 | BigFix Patch Download Plug-ins are affected by Server-Side Request Forgery (SSRF) vulnerability. It may allow the application to download files from an internally hosted server on localhost. |