Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
927 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.4) | 0.35% | — | Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+1 | 14/11/2019 | 17/6/2026 | Buffer overflow in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6618 (DCH) or 21.20.x.5077 (aka15.45.5077) may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.35% | — | Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+1 | 14/11/2019 | 17/6/2026 | Pointer corruption in the Unified Shader Compiler in Intel(R) Graphics Drivers before 10.18.14.5074 (aka 15.36.x.5074) may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.31% | — | Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage+1 | 14/11/2019 | 17/6/2026 | Insufficient input validation in Kernel Mode module for Intel(R) Graphics Driver before version 25.20.100.6519 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.36% | — | Intel Graphics DriverNetapp Cloud BackupNetapp Data Availability ServicesNetapp Steelstore Cloud Integrated Storage | 14/11/2019 | 17/6/2026 | Memory corruption in Kernel Mode Driver in Intel(R) Graphics Driver before 26.20.100.6813 (DCH) or 26.20.100.6812 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.67% | — | Redhat Enterprise Linux Server AUSRedhat Enterprise Linux Server EUSRedhat Enterprise Linux Server TUSIntel Graphics Driver+353 | 14/11/2019 | 17/6/2026 | Insufficient access control in a subsystem for Intel (R) processor graphics in 6th, 7th, 8th and 9th Generation Intel(R) Core(TM) Processor Families; Intel(R) Pentium(R) Processor J, N, Silver and Gold Series; Intel(R) Celeron(R) Processor J, N, G3900 and G4900 Series; Intel(R) Atom(R) Processor A and E3900 Series;… | |
| Modificada | Alta (8.2) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient input validation in system firmware for Intel(R) Xeon(R) Scalable Processors, Intel(R) Xeon(R) Processors D Family, Intel(R) Xeon(R) Processors E5 v4 Family, Intel(R) Xeon(R) Processors E7 v4 Family and Intel(R) Atom(R) processor C Series may allow a privileged user to potentially enable escalation of… | |
| Modificada | Media (6.7) | 0.38% | — | Intel Xeon Platinum 8253 FirmwareIntel Xeon Platinum 8256 FirmwareIntel Xeon Platinum 8260 FirmwareIntel Xeon Platinum 8276 Firmware+280 | 14/11/2019 | 17/6/2026 | Insufficient access control in system firmware for Intel(R) Xeon(R) Scalable Processors, 2nd Generation Intel(R) Xeon(R) Scalable Processors and Intel(R) Xeon(R) Processors D Family may allow a privileged user to potentially enable escalation of privilege, denial of service and/or information disclosure via local… | |
| Modificada | Media (6.1) | 2.2% | 💥 PoC | Redhat Hibernate ValidatorRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+183 | 8/11/2019 | 25/8/2026 | A vulnerability was found in Hibernate-Validator. The SafeHtml validator annotation fails to properly sanitize payloads consisting of potentially malicious code in HTML comments and instructions. This vulnerability can result in an XSS attack. | |
| Modificada | Crítica (9.8) | 2.6% | — | Osgeo GdalOracle Spatial AND GraphDebian LinuxFedoraproject Fedora+2 | 14/10/2019 | 17/6/2026 | GDAL through 3.0.1 has a poolDestroy double free in OGRExpatRealloc in ogr/ogr_expat.cpp when the 10MB threshold is exceeded. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Graphite Project Graphite | 11/10/2019 | 17/6/2026 | send_email in graphite-web/webapp/graphite/composer/views.py in Graphite through 1.1.5 is vulnerable to SSRF. The vulnerable SSRF endpoint can be used by an attacker to have the Graphite web server request any resource. The response to this SSRF request is encoded into an image file and then sent to an e-mail address… | |
| Modificada | Alta (7.5) | 1.2% | — | Hasura Graphql Engine | 29/7/2019 | 17/6/2026 | graphql-engine (aka Hasura GraphQL Engine) before 1.0.0-beta.3 mishandles the audience check while verifying JWT. | |
| Modificada | Alta (7.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 15/7/2019 | 17/6/2026 | A CWE-787: Out-of-bounds Write vulnerability exists in Interactive Graphical SCADA System (IGSS), Version 14 and prior, which could cause a software crash when data in the mdb database is manipulated. | |
| Modificada | Crítica (9.8) | 2.3% | — | Archivesunleashed Graphpass | 15/7/2019 | 17/6/2026 | borg-reducer c6d5240 is affected by: Buffer Overflow. The impact is: Possible code execution and denial of service. The component is: Output parameter within the executable. | |
| Modificada | Media (5.4) | 3.9% | 💥 Exploit | Jenkins Dependency Graph Viewer | 11/7/2019 | 17/6/2026 | A stored cross site scripting vulnerability in Jenkins Dependency Graph Viewer Plugin 0.13 and earlier allowed attackers able to configure jobs in Jenkins to inject arbitrary HTML and JavaScript in the plugin-provided web pages in Jenkins. | |
| Modificada | Alta (8.8) | 0.56% | — | Custom4web WP Open Graph | 5/7/2019 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WP Open Graph 1.6.1 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Media (6.1) | 1.5% | — | Draw.io DiagramsJgraph Mxgraph | 1/7/2019 | 17/6/2026 | An issue was discovered in mxGraph through 4.0.0, related to the "draw.io Diagrams" plugin before 8.3.14 for Confluence and other products. Improper input validation/sanitization of a color field leads to XSS. This is associated with javascript/examples/grapheditor/www/js/Dialogs.js. | |
| Modificada | Media (5.3) | 19% | 💥 Exploit | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | The createComment mutation in the WPGraphQL 0.2.3 plugin for WordPress allows unauthenticated users to post comments on any article, even when 'allow comment' is disabled. | |
| Modificada | Crítica (9.1) | 36% | 💥 Exploit | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | An issue was discovered in the WPGraphQL 0.2.3 plugin for WordPress. By querying the 'users' RootQuery, it is possible, for an unauthenticated attacker, to retrieve all WordPress users details such as email address, role, and username. | |
| Modificada | Crítica (9.8) | 47% | 💥 Exploit | Wpengine Wpgraphql | 10/6/2019 | 17/6/2026 | The WPGraphQL 0.2.3 plugin for WordPress allows remote attackers to register a new user with admin privileges, whenever new user registrations are allowed. This is related to the registerUser mutation. | |
| Modificada | Media (4.4) | 0.34% | — | Intel Graphics Driver | 17/5/2019 | 17/6/2026 | An out of bound read in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.34% | — | Intel Graphics Driver | 17/5/2019 | 17/6/2026 | Insufficient input validation in KMD module for Intel(R) Graphics Driver before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (4.7) | 0.22% | — | Intel Graphics Driver | 17/5/2019 | 17/6/2026 | A race condition in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Media (5.5) | 0.34% | — | Intel Graphics Driver | 17/5/2019 | 17/6/2026 | Insufficient bounds checking in Intel(R) Graphics Drivers before version 10.18.14.5067 (aka 15.36.x.5067) and 10.18.10.5069 (aka 15.33.x.5069) may allow an authenticated user to potentially enable a denial of service via local access. | |
| Modificada | Alta (8.8) | 2.6% | — | GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 24/4/2019 | 17/6/2026 | In GraphicsMagick from version 1.3.30 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WriteMATLABImage of coders/mat.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to ExportRedQuantumType in… | |
| Modificada | Alta (8.8) | 2.9% | — | GraphicsmagickDebian LinuxCanonical Ubuntu LinuxOpensuse Backports SLE+1 | 24/4/2019 | 17/6/2026 | In GraphicsMagick from version 1.3.8 to 1.4 snapshot-20190403 Q8, there is a heap-based buffer overflow in the function WritePDBImage of coders/pdb.c, which allows an attacker to cause a denial of service or possibly have unspecified other impact via a crafted image file. This is related to MagickBitStreamMSBWrite in… |