Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.25%—Intel Driver & Support Assistant9/6/202117/6/2026
Insufficient control flow management in Intel(R) DSA before version 20.11.50.9 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)2.3%💥 PoCGnupg LibgcryptDebian LinuxFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+48/6/202117/6/2026
Libgcrypt before 1.8.8 and 1.9.x before 1.9.3 mishandles ElGamal encryption because it lacks exponent blinding to address a side-channel attack against mpi_powm, and the window size is not chosen appropriately. This, for example, affects use of ElGamal in OpenPGP.
ModificadaAlta (7.8)0.40%—Vmware Spring FrameworkOracle Commerce Guided SearchOracle Communications BRM - Elastic Charging EngineOracle Communications Cloud Native Core Binding Support Function+2827/5/202117/6/2026
In Spring Framework, versions 5.2.x prior to 5.2.15 and versions 5.3.x prior to 5.3.7, a WebFlux application is vulnerable to a privilege escalation: by (re)creating the temporary storage directory, a locally authenticated malicious user can read or modify files that have been uploaded to the WebFlux application, or…
ModificadaMedia (5.7)1.9%—PythonFedoraproject FedoraDebian LinuxRedhat Software Collections+620/5/202117/6/2026
There's a flaw in Python 3's pydoc. A local or adjacent attacker who discovers or is able to convince another local or adjacent user to start a pydoc server could access the server and use it to disclose sensitive information belonging to the other user that they would not normally be able to access. The highest risk…
ModificadaCrítica (9.8)6.9%—PythonOracle Communications Cloud Native Core Automated Test SuiteOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Slice Selection Function+26/5/202117/6/2026
In Python before 3,9,5, the ipaddress library mishandles leading zero characters in the octets of an IP address string. This (in some situations) allows attackers to bypass access control that is based on IP addresses.
ModificadaMedia (4.9)1.5%—Oracle OSS Support Tools22/4/202117/6/2026
Vulnerability in the OSS Support Tools product of Oracle Support Tools (component: Diagnostic Assistant). The supported version that is affected is Prior to 2.12.41. Easily exploitable vulnerability allows high privileged attacker with network access via HTTP to compromise OSS Support Tools. Successful attacks of this…
ModificadaCrítica (9.8)1.5%—Anysupport22/4/202117/6/2026
AnySupport (Remote support solution) before 2019.3.21.0 allows directory traversing because of swprintf function to copy file from a management PC to a client PC. This can be lead to arbitrary file execution.
ModificadaMedia (4.8)9.9%💥 PoCApache Commons IODebian LinuxOracle Access ManagerOracle Agile Engineering Data Management+5613/4/20217/10/2026
In Apache Commons IO before 2.7, When invoking the method FileNameUtils.normalize with an improper input string, like "//../foo", or "\\..\foo", the result would be the same value, thus possibly providing access to files in the parent directory, but not further above (thus "limited" path traversal), if the calling…
ModificadaAlta (7.8)0.35%—Dell Supportassist Client PromanageDell Supportassist FOR Business PCSDell Supportassist FOR Home PCS12/3/202117/6/2026
Dell SupportAssist Client for Consumer PCs versions 3.7.x, 3.6.x, 3.4.x, 3.3.x, Dell SupportAssist Client for Business PCs versions 2.0.x, 2.1.x, 2.2.x, and Dell SupportAssist Client ProManage 1.x contain a DLL injection vulnerability in the Costura Fody plugin. A local user with low privileges could potentially…
ModificadaMedia (5.3)1.2%—Jenkins Support Core24/2/202117/6/2026
Jenkins Support Core Plugin 2.72 and earlier provides the serialized user authentication as part of the "About user (basic authentication details only)" information, which can include the session ID of the user creating the support bundle in some configurations.
ModificadaMedia (5.9)2.9%💥 PoCJson-smart Project Json-smart-v1Json-smart Project Json-smart-v2Oracle Communications Cloud Native Core PolicyOracle OSS Support Tools+323/2/202117/6/2026
An issue was discovered in netplex json-smart-v1 through 2015-10-23 and json-smart-v2 through 2.4. An exception is thrown from a function, but it is not caught, as demonstrated by NumberFormatException. When it is not caught, it may cause programs using the library to crash or expose sensitive information.
ModificadaAlta (7.2)21%💥 ExploitLodashOracle Banking Corporate Lending Process ManagementOracle Banking Credit Facilities Process ManagementOracle Banking Extensibility Workbench+1915/2/202117/6/2026
Lodash versions prior to 4.17.21 are vulnerable to Command Injection via the template function.
ModificadaCrítica (9.8)1.2%—Webidsupport Webid27/1/202117/6/2026
WeBid 1.2.2 admin/newuser.php has an issue with password rechecking during registration because it uses a loose comparison to check the identicalness of two passwords. Two non-identical passwords can still bypass the check.
ModificadaAlta (8.2)1.2%—Oracle Isupport20/1/202117/6/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Profile). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks…
ModificadaAlta (8.2)1.2%—Oracle Isupport20/1/202117/6/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: User Responsibilities). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful…
ModificadaAlta (7.8)3.3%—Redhat Language Support FOR Java10/12/202017/6/2026
Visual Studio Code Java Extension Pack Remote Code Execution Vulnerability
ModificadaAlta (7.5)25%💥 PoCApache TomcatNetapp Element Plug-inNetapp Oncommand System ManagerDebian Linux+83/12/202017/6/2026
While investigating bug 64830 it was discovered that Apache Tomcat 10.0.0-M1 to 10.0.0-M9, 9.0.0-M1 to 9.0.39 and 8.5.0 to 8.5.59 could re-use an HTTP request header value from the previous stream received on an HTTP/2 connection for the request associated with the subsequent stream. While this would most likely lead…
ModificadaMedia (4.7)0.39%—IBM ViosIBM AIXFedoraproject FedoraOracle Communications Cloud Native Core Binding Support Function+220/11/202017/6/2026
IBM Power9 (AIX 7.1, 7.2, and VIOS 3.1) processors could allow a local user to obtain sensitive information from the data in the L1 cache under extenuating circumstances. IBM X-Force ID: 189296.
ModificadaMedia (5.5)0.25%—Intel Driver & Support Assistant12/11/202017/6/2026
Incorrect default permissions in the Intel(R) DSA before version 20.8.30.6 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaAlta (8.8)0.82%—Onwebchat Live Chat - Live Support15/10/202017/6/2026
Cross-site request forgery (CSRF) vulnerability in Live Chat - Live support version 3.1.0 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (7.8)0.28%—Intel Driver & Support Assistant5/10/202017/6/2026
Improper permissions in the Intel(R) Driver & Support Assistant before version 20.7.26.7 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.23%—Google AndroidOracle Communications Cloud Native Core Binding Support FunctionOracle Communications Cloud Native Core Network Exposure FunctionOracle Communications Cloud Native Core Policy17/9/202017/6/2026
In uvc_scan_chain_forward of uvc_driver.c, there is a possible linked list corruption due to an unusual root cause. This could lead to local escalation of privilege in the kernel with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android…
ModificadaMedia (5.4)1.9%💥 ExploitAppsbd Best Support System4/9/202017/6/2026
An Authenticated Persistent XSS vulnerability was discovered in the Best Support System, tested version v3.0.4.
ModificadaAlta (8)0.93%—Openmage Long Term SupportMagento20/8/202017/6/2026
OpenMage LTS before versions 19.4.6 and 20.0.2 allows attackers to circumvent the `fromkey protection` in the Admin Interface and increases the attack surface for Cross Site Request Forgery attacks. This issue is related to Adobe's CVE-2020-9690. It is patched in versions 19.4.6 and 20.0.2.
ModificadaAlta (8.2)1.3%—Oracle Isupport15/7/202017/6/2026
Vulnerability in the Oracle iSupport product of Oracle E-Business Suite (component: Others). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSupport. Successful attacks require…