Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.37% | — | Intel Graphics Drivers | 13/8/2020 | 17/6/2026 | Out of bounds write in system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7) | 0.20% | — | Intel Graphics Drivers | 13/8/2020 | 17/6/2026 | Race condition in some Intel(R) Graphics Drivers before version 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.27% | — | Intel Graphics Drivers | 13/8/2020 | 17/6/2026 | Out-of-bounds write in Kernel Mode Driver for some Intel(R) Graphics Drivers before version 26.20.100.7755 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Graphics Drivers | 13/8/2020 | 17/6/2026 | Out of bounds write for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.30% | — | Intel Graphics Drivers | 13/8/2020 | 17/6/2026 | Uncaught exception in the system driver for some Intel(R) Graphics Drivers before version 15.33.50.5129 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Graphics Drivers | 13/8/2020 | 17/6/2026 | Out of bounds read in some Intel(R) Graphics Drivers before versions 15.45.31.5127 and 15.40.45.5126 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.30% | — | Teradici Graphics AgentTeradici Pcoip Standard Agent | 11/8/2020 | 17/6/2026 | Broker Protocol messages in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to 20.04.1 are not cleaned up in server memory, which may allow an attacker to read confidential information from a memory dump via forcing a crashing during the single sign-on procedure. | |
| Modificada | Media (6.7) | 0.24% | — | Teradici Graphics AgentTeradici Pcoip Standard Agent | 11/8/2020 | 17/6/2026 | A function in the Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows prior to version 20.04.1 does not properly validate the signature of an external binary, which could allow an attacker to gain elevated privileges via execution in the context of the PCoIP Agent process. | |
| Modificada | Alta (7.8) | 0.38% | — | Teradici Graphics AgentTeradici Pcoip Standard Agent | 11/8/2020 | 17/6/2026 | The support bundler in Teradici PCoIP Standard Agent for Windows and Graphics Agent for Windows versions prior to 20.04.1 and 20.07.0 does not use hard coded paths for certain Windows binaries, which allows an attacker to gain elevated privileges via execution of a malicious binary placed in the system path. | |
| Modificada | Media (5.4) | 0.73% | — | Jenkins Sonargraph Integration | 2/7/2020 | 17/6/2026 | Jenkins Sonargraph Integration Plugin 3.0.0 and earlier does not escape the file path for the Log file field form validation, resulting in a stored cross-site scripting vulnerability. | |
| Modificada | Alta (7.4) | 7.2% | — | Prisma Graphql-playground-htmlPrisma Graphql-playground-middleware-expressPrisma Graphql-playground-middleware-hapiPrisma Graphql-playground-middleware-koa+1 | 8/6/2020 | 17/6/2026 | GraphQL Playground (graphql-playground-html NPM package) before version 1.6.22 have a severe XSS Reflection attack vulnerability. All unsanitized user input passed into renderPlaygroundPage() method could trigger this vulnerability. This has been patched in graphql-playground-html version 1.6.22. Note that some of the… | |
| Modificada | Alta (7.8) | 0.23% | — | Teradici Pcoip Graphics AgentTeradici Pcoip Standard Agent | 28/5/2020 | 17/6/2026 | Initialization of the pcoip_credential_provider in Teradici PCoIP Standard Agent for Windows and PCoIP Graphics Agent for Windows versions 19.11.1 and earlier creates an insecure named pipe, which allows an attacker to intercept sensitive information or possibly elevate privileges via pre-installing an application… | |
| Modificada | Alta (7.5) | 2.9% | — | GraphicsmagickDebian LinuxOpensuse Backports SLEOpensuse Leap | 6/5/2020 | 17/6/2026 | GraphicsMagick through 1.3.35 has a heap-based buffer overflow in ReadMNGImage in coders/png.c. | |
| Modificada | Media (6.1) | 1.3% | — | Sourcegraph | 30/4/2020 | 17/6/2026 | Sourcegraph before 3.15.1 has a vulnerable authentication workflow because of improper validation in the SafeRedirectURL method in cmd/frontend/auth/redirect.go, such as for the //foo//example.com substring. | |
| Modificada | Baja (3.7) | 8.1% | 💥 PoC | Apache Log4jOracle Communications Application Session ControllerOracle Communications Billing AND Revenue ManagementOracle Communications Eagle FTP Table Base Retrieval+42 | 27/4/2020 | 17/6/2026 | Improper validation of certificate with host mismatch in Apache Log4j SMTP appender. This could allow an SMTPS connection to be intercepted by a man-in-the-middle attack which could leak any log messages sent through that appender. Fixed in Apache Log4j 2.12.3 and 2.13.1 | |
| Modificada | Crítica (9.8) | 2.6% | — | Microsoft Research Javascript Cryptography Library | 15/4/2020 | 17/6/2026 | A Security Feature Bypass vulnerability exists in the MSR JavaScript Cryptography Library that is caused by multiple bugs in the library’s Elliptic Curve Cryptography (ECC) implementation.An attacker could potentially abuse these bugs to learn information about a server’s private ECC key (a key leakage attack) or… | |
| Modificada | Crítica (9.8) | 5.4% | — | GraphicsmagickDebian LinuxOpensuse BackportsOpensuse Leap | 24/3/2020 | 17/6/2026 | GraphicsMagick before 1.3.35 has an integer overflow and resultant heap-based buffer overflow in HuffmanDecodeImage in magick/compress.c. | |
| Modificada | Alta (7.8) | 0.51% | — | Schneider-electric Interactive Graphical Scada System | 23/3/2020 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a local user to execute processes that otherwise require escalation privileges when sending local network commands to the IGSS Update Service. | |
| Modificada | Alta (7.5) | 4.1% | — | Schneider-electric Interactive Graphical Scada System | 23/3/2020 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory exists in IGSS (Versions 14 and prior using the service: IGSSupdate), which could allow a remote unauthenticated attacker to read arbitrary files from the IGSS server PC on an unrestricted or shared network when the IGSS Update Service is enabled. | |
| Modificada | Media (6.5) | 8.0% | — | GraphicsmagickDebian LinuxOpensuse Backports SLEOpensuse Leap | 18/3/2020 | 17/6/2026 | In GraphicsMagick before 1.3.32, the text filename component allows remote attackers to read arbitrary files via a crafted image because of TranslateTextEx for SVG. | |
| Modificada | Media (5.5) | 0.31% | — | Intel Graphics Driver | 12/3/2020 | 17/6/2026 | Improper input validation in Intel(R) Graphics Drivers before version 26.20.100.7212 may allow an authenticated user to enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.35% | — | Intel Graphics Driver | 12/3/2020 | 17/6/2026 | Uncontrolled search path in Intel(R) Graphics Drivers before version 26.20.100.7158 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.27% | — | Nvidia Virtual GPU Graphics Driver | 12/3/2020 | 17/6/2026 | NVIDIA vGPU graphics driver for guest OS contains a vulnerability in which an incorrect resource clean up on a failure path can impact the guest VM, leading to denial of service. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel Graphics Driver | 12/3/2020 | 17/6/2026 | Path traversal in igdkmd64.sys for Intel(R) Graphics Drivers before versions 15.45.30.5103, 15.40.44.5107, 15.36.38.5117 and 15.33.49.5100 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access. | |
| Modificada | Alta (7.8) | 0.35% | — | Intel Graphics Driver | 12/3/2020 | 17/6/2026 | Improper access control for Intel(R) Graphics Drivers before versions 15.33.49.5100 and 15.36.38.5117 may allow an authenticated user to potentially enable escalation of privilege or denial of service via local access. |