Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

728 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.64%—Londontrustmedia Private Internet Access VPN Client11/7/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client v0.9.8 beta (build 02099) for macOS could allow an authenticated, local attacker to overwrite arbitrary files. When the client initiates a connection, the XML /tmp/pia-watcher.plist file is created. If the file exists, it will be…
ModificadaAlta (7.8)0.93%—Londontrustmedia Private Internet Access21/6/201917/6/2026
A vulnerability in the London Trust Media Private Internet Access (PIA) VPN Client 1.0.2 (build 02363) for Windows could allow an authenticated, local attacker to run arbitrary code with elevated privileges. On startup, the PIA Windows service (pia-service.exe) loads the OpenSSL library from %PROGRAMFILES%\Private…
ModificadaMedia (6.7)0.46%—Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware13/6/201917/6/2026
Insufficient input validation in HECI subsystem in Intel(R) CSME before version 11.21.55, Intel® Server Platform Services before version 4.0 and Intel® Trusted Execution Engine Firmware before version 3.1.55 may allow a privileged user to potentially enable escalation of privileges via local access.
ModificadaMedia (4.9)0.45%—Cloudera ManagerCloudera Navigator KEY Trustee KMS7/6/201917/6/2026
In Cloudera Navigator Key Trustee KMS 5.12 and 5.13, incorrect default ACL values allow remote access to purge and undelete API calls on encryption zone keys. The Navigator Key Trustee KMS includes 2 API calls in addition to those in Apache Hadoop KMS: purge and undelete. The KMS ACL values for these commands are…
ModificadaMedia (6.8)0.47%—Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware17/5/201917/6/2026
Logic bug vulnerability in subsystem for Intel(R) CSME before version 12.0.35, Intel(R) TXE before 3.1.65, 4.0.15 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
ModificadaAlta (7.8)0.52%—Intel Converged Security AND Management EngineIntel Trusted Execution Technology17/5/201917/6/2026
Code injection vulnerability in installer for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.36%—Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware17/5/201917/6/2026
Insufficient access control vulnerability in Dynamic Application Loader software for Intel(R) CSME before versions 11.8.65, 11.11.65, 11.22.65, 12.0.35 and Intel(R) TXE 3.1.65, 4.0.15 may allow an unprivileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.1)2.2%—Rust-lang RustFedoraproject FedoraOpensuse Leap13/5/201917/6/2026
The Rust Programming Language Standard Library 1.34.x before 1.34.2 contains a stabilized method which, if overridden, can violate Rust's safety guarantees and cause memory unsafety. If the `Error::type_id` method is overridden then any type can be safely cast to any other type, causing memory safety vulnerabilities…
ModificadaAlta (7.5)1.6%—Beyondtrust Avecto Defendpoint17/4/201917/6/2026
Avecto Defendpoint 4 prior to 4.4 SR6 and 5 prior to 5.1 SR1 has an Untrusted Search Path vulnerability, exploitable by modifying environment variables to trigger automatic elevation of an attacker's process launch.
ModificadaMedia (6.5)1.6%—Trustsource ECS Publisher28/3/201917/6/2026
A vulnerability in Jenkins ECS Publisher Plugin 1.0.0 and earlier allows attackers with Item/Extended Read permission, or local file system access to the Jenkins home directory to obtain the API token configured in this plugin's configuration.
ModificadaAlta (7.6)0.51%—Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware14/3/201917/6/2026
Buffer overflow in HECI subsystem in Intel(R) CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel(R) TXE version before 3.1.60 or 4.0.10, or Intel(R) Server Platform Services before version 5.00.04.012 may allow an unauthenticated user to potentially execute arbitrary code via physical access.
ModificadaMedia (6.2)0.49%—Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware14/3/201917/6/2026
Buffer overflow in an OS component in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 and Intel TXE version before 3.1.60 or 4.0.10 may allow a privileged user to potentially execute arbitrary code via physical access.
ModificadaAlta (7.6)0.48%—Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware14/3/201917/6/2026
Bounds check in Kernel subsystem in Intel CSME before version 11.8.60, 11.11.60, 11.22.60 or 12.0.20, or Intel(R) Server Platform Services before versions 4.00.04.383 or SPS 4.01.02.174, or Intel(R) TXE before versions 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially execute arbitrary code via…
ModificadaMedia (6.7)0.38%—Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware14/3/201917/6/2026
Insufficient input validation in Intel(r) CSME subsystem before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel(r) TXE before 3.1.60 or 4.0.10 may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaMedia (4.4)0.29%—Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware14/3/201917/6/2026
Unhandled exception in Content Protection subsystem in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before 3.1.60 or 4.0.10 may allow privileged user to potentially modify data via local access.
ModificadaMedia (4.6)0.34%—Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware14/3/201917/6/2026
Insufficient input validation in Intel CSME before versions 11.8.60, 11.11.60, 11.22.60 or 12.0.20 or Intel TXE before version 3.1.60 or 4.0.10 may allow an unauthenticated user to potentially modify data via physical access.
ModificadaMedia (5.3)1.4%—Trustedfirmware Trusted Firmware-a30/1/201917/6/2026
ARM Trusted Firmware-A allows information disclosure.
AnalizadaAlta (7.5)1.9%—Trustedfirmware Trusted Firmware-a18/12/201817/6/2026
In all versions of ARM Trusted Firmware up to and including v1.4, not initializing or saving/restoring the PMCR_EL0 register can leak secure world timing information.
ModificadaMedia (5.5)1.3%—Virustotal Yara17/12/201817/6/2026
In YARA 3.8.1, bytecode in a specially crafted compiled rule is exposed to information about its environment, in libyara/exec.c. This is a consequence of the design of the YARA virtual machine.
ModificadaMedia (5.5)1.4%—Virustotal Yara17/12/201817/6/2026
In YARA 3.8.1, bytecode in a specially crafted compiled rule can read data from any arbitrary address in memory, in libyara/exec.c. Specifically, OP_COUNT can read a DWORD.
ModificadaMedia (5.5)1.3%—Virustotal Yara17/12/201817/6/2026
In YARA 3.8.1, bytecode in a specially crafted compiled rule can read uninitialized data from VM scratch memory in libyara/exec.c. This can allow attackers to discover addresses in the real stack (not the YARA virtual stack).
ModificadaMedia (4.7)0.34%—ARM Mbed TLSTrustedfirmware Mbed TLS5/12/201817/6/2026
Arm Mbed TLS before 2.14.1, before 2.7.8, and before 2.1.17 allows a local unprivileged attacker to recover the plaintext of RSA decryption, which is used in RSA-without-(EC)DH(E) cipher suites.
ModificadaCrítica (9.8)3.0%—Rust-lang Rust8/10/201817/6/2026
The Rust Programming Language Standard Library version 1.29.0, 1.28.0, 1.27.2, 1.27.1, 127.0, 126.2, 126.1, 126.0 contains a CWE-680: Integer Overflow to Buffer Overflow vulnerability in standard library that can result in buffer overflow. This attack appear to be exploitable via str::repeat, passed a large number,…
ModificadaMedia (6.8)0.43%—Intel Converged Security Management Engine FirmwareIntel Trusted Execution Engine Firmware12/9/201817/6/2026
A vulnerability in Intel PTT module in Intel CSME firmware before version 12.0.5 and Intel TXE firmware before version 4.0 may allow an unauthenticated user to potentially disclose information via physical access.
ModificadaAlta (7.3)0.46%—Intel Converged Security Management Engine FirmwareIntel Server Platform Services FirmwareIntel Trusted Execution Engine Firmware12/9/201817/6/2026
A vulnerability in a subsystem in Intel CSME before version 11.21.55, Intel Server Platform Services before version 4.0 and Intel Trusted Execution Engine Firmware before version 3.1.55 may allow an unauthenticated user to potentially modify or disclose information via physical access.
Orbitaley — Vulnerabilidades