Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
482 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.37% | — | Performance MonitorAI | 21/3/2026 | 17/6/2026 | The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers… | |
| Analizada | Media (6.5) | 0.35% | — | Tanium Performance | 5/2/2026 | 17/6/2026 | Tanium addressed an incorrect default permissions vulnerability in Performance. | |
| Aplazada | Media (6.8) | 0.14% | — | Lenovo VantageAILenovo SmartperformanceaddinAI | 14/1/2026 | 17/6/2026 | An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges. | |
| Aplazada | Media (4.3) | 0.19% | — | Merlot Digital TNC Toolbox WEB PerformanceAI | 21/11/2025 | 17/6/2026 | Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4. | |
| Aplazada | Media (5.4) | 0.12% | — | Intel Killer Performance SuiteAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 28/10/2025 | 17/6/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to the incorrect calculation of the size of the data that is being pointed to. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 28/10/2025 | 17/6/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated… | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 30/9/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due an out of bounds write. | |
| Analizada | Media (6.5) | 0.31% | — | IBM DB2 High Performance Unload Load | 27/10/2025 | 30/9/2026 | IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack. | |
| Aplazada | Media (6.1) | 0.19% | — | HR Performance Solutions Performance PROAI | 21/10/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee Notes, title, or description parameters. The patched version is… | |
| Aplazada | Media (6.1) | 0.19% | — | HR Performance Solutions Performance PROAI | 21/10/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name, and… | |
| Aplazada | Media (6.1) | 0.19% | — | HR Performance Solutions Performance PROAI | 21/10/2025 | 17/6/2026 | Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name,… | |
| Aplazada | Media (5.5) | 0.33% | — | Storage Performance Development KIT SpdkAI | 1/10/2025 | 17/6/2026 | Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf. | |
| Aplazada | Media (6.5) | 0.17% | — | Pencidesign Penci Shortcodes AND PerformanceAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Shortcodes & Performance penci-shortcodes allows DOM-Based XSS.This issue affects Penci Shortcodes & Performance: from n/a through < 6.1. | |
| Aplazada | Alta (7) | 0.20% | — | Lenovo 510 FHD WEB CameraAILenovo Performance FHD WEB CameraAI | 18/8/2025 | 17/6/2026 | A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over a USB connection. | |
| Aplazada | Alta (7.3) | 0.13% | — | Intel Connectivity Performance SuiteAI | 12/8/2025 | 17/6/2026 | Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.4) | 0.19% | — | Solarwinds Database Performance Analyzer | 12/8/2025 | 17/6/2026 | SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level… | |
| Aplazada | Crítica (9.8) | 0.42% | — | HPE Performance Cluster ManagerAI | 22/4/2025 | 17/6/2026 | A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host. | |
| Analizada | Alta (8.1) | 0.41% | — | HPE Performance Cluster Manager | 21/4/2025 | 17/6/2026 | A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication. | |
| Aplazada | Media (4.3) | 0.21% | — | Bjoern WP Performance PackAI | 9/4/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Cross Site Request Forgery.This issue affects WP Performance Pack: from n/a through <= 2.5.4. | |
| Aplazada | Media (5.3) | 0.50% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 1/4/2025 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through… | |
| Aplazada | Crítica (9.8) | 0.54% | — | Mywebtonet PerformancestatsAI | 28/3/2025 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performancestats allows Object Injection.This issue affects PHP/MySQL CPU performance statistics: from n/a through <= 1.2.1. | |
| Aplazada | Media (4.3) | 0.28% | — | Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI | 27/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a… | |
| Aplazada | Media (4.3) | 0.40% | — | Bjoern WP Performance PackAI | 11/3/2025 | 17/6/2026 | Missing Authorization vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Performance Pack: from n/a through <= 2.5.3. | |
| Analizada | Alta (7.5) | 0.18% | — | Intel Integrated Performance Primitives Cryptography | 14/2/2025 | 17/6/2026 | Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access. |