Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
728 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.64% | — | Londontrustmedia Private Internet Access VPN Client | 11/7/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, local attacker to overwrite arbitrary files. When the client initiates a connection, the XML /tmp/pia-watcher.plist file is created. If the file exists, it will be… | |
| Modificada | Alta (7.8) | 0.93% | — | Londontrustmedia Private Internet Access | 21/6/2019 | 17/6/2026 | A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. On startup, the PIA Windows service (pia-service.exe) loads the OpenSSL library from %PROGRAMFILES%\Private… | |
| Modificada | Media (6.7) | 0.46% | — | Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware | 13/6/2019 | 17/6/2026 | Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access. | |
| Modificada | Media (4.9) | 0.45% | — | Cloudera ManagerCloudera Navigator KEY Trustee KMS | 7/6/2019 | 17/6/2026 | In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete API calls on encryption zone keys. The Navigator Key Trustee KMS includes 2 API calls in addition to those in Apache Hadoop KMS: purge and undelete. The KMS ACL values for these commands are… | |
| Modificada | Media (6.8) | 0.47% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 17/5/2019 | 17/6/2026 | Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Alta (7.8) | 0.52% | — | Intel Converged Security AND Management EngineIntel Trusted Execution Technology | 17/5/2019 | 17/6/2026 | Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 17/5/2019 | 17/6/2026 | Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.1) | 2.2% | — | Rust-lang RustFedoraproject FedoraOpensuse Leap | 13/5/2019 | 17/6/2026 | The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities… | |
| Modificada | Alta (7.5) | 1.6% | — | Beyondtrust Avecto Defendpoint | 17/4/2019 | 17/6/2026 | Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch. | |
| Modificada | Media (6.5) | 1.6% | — | Trustsource ECS Publisher | 28/3/2019 | 17/6/2026 | A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to the Jenkins home directory to obtain the API token configured in this plugin's configuration. | |
| Modificada | Alta (7.6) | 0.51% | — | Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware | 14/3/2019 | 17/6/2026 | Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access. | |
| Modificada | Media (6.2) | 0.49% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 14/3/2019 | 17/6/2026 | Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access. | |
| Modificada | Alta (7.6) | 0.48% | — | Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware | 14/3/2019 | 17/6/2026 | Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via… | |
| Modificada | Media (6.7) | 0.38% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 14/3/2019 | 17/6/2026 | Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.29% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 14/3/2019 | 17/6/2026 | Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access. | |
| Modificada | Media (4.6) | 0.34% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 14/3/2019 | 17/6/2026 | Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access. | |
| Modificada | Media (5.3) | 1.4% | — | Trustedfirmware Trusted Firmware-a | 30/1/2019 | 17/6/2026 | ARM Trusted Firmware-A allows information disclosure. | |
| Analizada | Alta (7.5) | 1.9% | — | Trustedfirmware Trusted Firmware-a | 18/12/2018 | 17/6/2026 | In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information. | |
| Modificada | Media (5.5) | 1.3% | — | Virustotal Yara | 17/12/2018 | 17/6/2026 | In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine. | |
| Modificada | Media (5.5) | 1.4% | — | Virustotal Yara | 17/12/2018 | 17/6/2026 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_COUNT can read a DWORD. | |
| Modificada | Media (5.5) | 1.3% | — | Virustotal Yara | 17/12/2018 | 17/6/2026 | In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses in the real stack (not the YARA virtual stack). | |
| Modificada | Media (4.7) | 0.34% | — | ARM Mbed TLSTrustedfirmware Mbed TLS | 5/12/2018 | 17/6/2026 | Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites. | |
| Modificada | Crítica (9.8) | 3.0% | — | Rust-lang Rust | 8/10/2018 | 17/6/2026 | The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number,… | |
| Modificada | Media (6.8) | 0.43% | — | Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware | 12/9/2018 | 17/6/2026 | A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access. | |
| Modificada | Alta (7.3) | 0.46% | — | Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware | 12/9/2018 | 17/6/2026 | A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access. |