Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

482 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.2)0.37%—Performance MonitorAI21/3/202617/6/2026
The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers…
AnalizadaMedia (6.5)0.35%—Tanium Performance5/2/202617/6/2026
Tanium addressed an incorrect default permissions vulnerability in Performance.
AplazadaMedia (6.8)0.14%—Lenovo VantageAILenovo SmartperformanceaddinAI14/1/202617/6/2026
An improper link following vulnerability was reported in the SmartPerformanceAddin for Lenovo Vantage that could allow an authenticated local user to perform an arbitrary file deletion with elevated privileges.
AplazadaMedia (4.3)0.19%—Merlot Digital TNC Toolbox WEB PerformanceAI21/11/202517/6/2026
Missing Authorization vulnerability in Merlot Digital (by TNC) TNC Toolbox: Web Performance tnc-toolbox allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects TNC Toolbox: Web Performance: from n/a through <= 2.0.4.
AplazadaMedia (5.4)0.12%—Intel Killer Performance SuiteAI11/11/202517/6/2026
Uncontrolled search path for some Intel(R) Killer(TM) Performance Suite software before version killer 4.0 40.25.509.1465 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of…
AnalizadaMedia (6.5)0.31%—IBM DB2 High Performance Unload Load28/10/202517/6/2026
IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to the incorrect calculation of the size of the data that is being pointed to.
AnalizadaMedia (6.5)0.31%—IBM DB2 High Performance Unload Load28/10/202517/6/2026
IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, 5.1, 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated…
AnalizadaMedia (6.5)0.31%—IBM DB2 High Performance Unload Load27/10/202530/9/2026
IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due an out of bounds write.
AnalizadaMedia (6.5)0.31%—IBM DB2 High Performance Unload Load27/10/202530/9/2026
IBM DB2 High Performance Unload 6.1.0.3, 5.1.0.1, 6.1.0.2, 6.5, 6.5.0.0 IF1, 6.1.0.1, 6.1, and 5.1 could allow an authenticated user to cause the program to crash due to a buffer being overwritten when it is allocated on the stack.
AplazadaMedia (6.1)0.19%—HR Performance Solutions Performance PROAI21/10/202517/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the index.php component of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Employee Notes, title, or description parameters. The patched version is…
AplazadaMedia (6.1)0.19%—HR Performance Solutions Performance PROAI21/10/202517/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the Future Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name, and…
AplazadaMedia (6.1)0.19%—HR Performance Solutions Performance PROAI21/10/202517/6/2026
Multiple stored cross-site scripting (XSS) vulnerabilities in the Current Goals function of HR Performance Solutions Performance Pro v3.19.17 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Goal Name, Goal Notes, Action Step Name, Action Step Description, Note Name,…
AplazadaMedia (5.5)0.33%—Storage Performance Development KIT SpdkAI1/10/202517/6/2026
Storage Performance Development Kit (SPDK) 25.05 is vulnerable to Buffer Overflow in the NVMe-oF target component in SPDK - lib/nvmf.
AplazadaMedia (6.5)0.17%—Pencidesign Penci Shortcodes AND PerformanceAI22/9/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in PenciDesign Penci Shortcodes & Performance penci-shortcodes allows DOM-Based XSS.This issue affects Penci Shortcodes & Performance: from n/a through < 6.1.
AplazadaAlta (7)0.20%—Lenovo 510 FHD WEB CameraAILenovo Performance FHD WEB CameraAI18/8/202517/6/2026
A potential vulnerability was reported in the Lenovo 510 FHD and Performance FHD web cameras that could allow an attacker with physical access to write arbitrary firmware updates to the device over a USB connection.
AplazadaAlta (7.3)0.13%—Intel Connectivity Performance SuiteAI12/8/202517/6/2026
Time-of-check Time-of-use race condition for some Intel(R) Connectivity Performance Suite software installers before version 40.24.11210 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6.4)0.19%—Solarwinds Database Performance Analyzer12/8/202517/6/2026
SolarWinds Database Performance Analyzer was found to contain a hard-coded cryptographic key. If exploited, this vulnerability could lead to a machine-in-the-middle (MITM) attack against users. This vulnerability requires additional software not installed by default, local access to the server and administrator level…
AplazadaCrítica (9.8)0.42%—HPE Performance Cluster ManagerAI22/4/202517/6/2026
A vulnerability in the cmdb service of the HPE Performance Cluster Manager (HPCM) could allow an attacker to gain access to an arbitrary file on the server host.
AnalizadaAlta (8.1)0.41%—HPE Performance Cluster Manager21/4/202517/6/2026
A vulnerability in the HPE Performance Cluster Manager (HPCM) GUI could allow an attacker to bypass authentication.
AplazadaMedia (4.3)0.21%—Bjoern WP Performance PackAI9/4/202517/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Cross Site Request Forgery.This issue affects WP Performance Pack: from n/a through <= 2.5.4.
AplazadaMedia (5.3)0.50%—Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI1/4/202517/6/2026
Insertion of Sensitive Information into Log File vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Retrieve Embedded Sensitive Data.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a through…
AplazadaCrítica (9.8)0.54%—Mywebtonet PerformancestatsAI28/3/202517/6/2026
Deserialization of Untrusted Data vulnerability in mywebtonet PHP/MySQL CPU performance statistics mywebtonet-performancestats allows Object Injection.This issue affects PHP/MySQL CPU performance statistics: from n/a through <= 1.2.1.
AplazadaMedia (4.3)0.28%—Smackcoders INC AIO Performance Profiler Monitor Optimize Compress DebugAI27/3/202517/6/2026
Missing Authorization vulnerability in Smackcoders Inc., AIO Performance Profiler, Monitor, Optimize, Compress & Debug all-in-one-performance-accelerator allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects AIO Performance Profiler, Monitor, Optimize, Compress & Debug: from n/a…
AplazadaMedia (4.3)0.40%—Bjoern WP Performance PackAI11/3/202517/6/2026
Missing Authorization vulnerability in Bjoern WP Performance Pack wp-performance-pack allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Performance Pack: from n/a through <= 2.5.3.
AnalizadaAlta (7.5)0.18%—Intel Integrated Performance Primitives Cryptography14/2/202517/6/2026
Generation of weak initialization vector in an Intel(R) IPP Cryptography software library before version 2021.5 may allow an unauthenticated user to potentially enable information disclosure via local access.