Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
795 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.73% | — | HP Support Assistant | 25/6/2019 | 17/6/2026 | HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329. | |
| Modificada | Alta (8.3) | 1.1% | — | ABB Board Support Package Un31ABB Cp620 FirmwareABB Cp620-web FirmwareABB Cp630 Firmware+4 | 24/6/2019 | 17/6/2026 | The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity… | |
| Modificada | Alta (7.8) | 0.26% | — | Dell Supportassist FOR Home PCSDell Supportassist FOR Business PCS | 20/6/2019 | 17/6/2026 | Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread… | |
| Modificada | Alta (8.8) | 0.91% | — | Ranksol Live Call Support | 19/6/2019 | 17/6/2026 | CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account. | |
| Modificada | Alta (7.8) | 1.7% | — | Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+14 | 18/6/2019 | 17/6/2026 | Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will… | |
| Modificada | Alta (7.8) | 50% | — | Haxx LibcurlOpensuse LeapFedoraproject FedoraDebian Linux+7 | 28/5/2019 | 17/6/2026 | A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1. | |
| Modificada | Media (4.4) | 0.33% | — | Intel Driver & Support Assistant | 17/5/2019 | 17/6/2026 | Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (4.4) | 0.38% | — | Intel Driver & Support Assistant | 17/5/2019 | 17/6/2026 | Insufficient access control in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.1) | 0.83% | — | Webidsupport Webid | 29/4/2019 | 17/6/2026 | WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php. | |
| Modificada | Alta (8) | 16% | 💥 PoC | Dell Supportassist | 18/4/2019 | 17/6/2026 | Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via… | |
| Modificada | Alta (8.8) | 0.67% | — | Dell Supportassist | 18/4/2019 | 17/6/2026 | Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems. | |
| Modificada | Crítica (9.8) | 8.8% | 💥 PoC | Supportcandy | 18/4/2019 | 17/6/2026 | An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension. | |
| Modificada | Media (4.3) | 0.82% | — | Apple Support | 3/4/2019 | 17/6/2026 | Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS. | |
| Modificada | Alta (7.3) | 0.38% | — | HP Support Assistant | 27/3/2019 | 17/6/2026 | HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code. | |
| Modificada | Media (6.1) | 1.7% | — | Wpsupportplus WP Support Plus Responsive Ticket System | 21/3/2019 | 17/6/2026 | A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in… | |
| Modificada | Media (5.5) | 0.30% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine. | |
| Modificada | Alta (7.8) | 0.50% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root. | |
| Modificada | Media (4.7) | 0.40% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files. | |
| Modificada | Media (5.5) | 0.46% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection | |
| Modificada | Alta (7.8) | 0.32% | — | Opensuse Supportutils | 5/3/2019 | 17/6/2026 | Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location it is executed with root privileges | |
| Modificada | Alta (7.8) | 0.35% | — | Intel System Support Utility | 10/1/2019 | 17/6/2026 | Insufficient path checking in Intel(R) System Support Utility for Windows before 2.5.0.15 may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 2.4% | — | Webidsupport Webid | 20/12/2018 | 17/6/2026 | WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attack appear to be exploitable via HTTP GET Request. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f. | |
| Modificada | Media (6.1) | 1.6% | — | Webidsupport Webid | 20/12/2018 | 17/6/2026 | WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup into the page. This attack appear to be exploitable via The victim user must click a malicous link.… | |
| Modificada | Alta (8.8) | 1.5% | — | Webidsupport Webid | 20/12/2018 | 17/6/2026 | WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit… | |
| Modificada | Media (6.5) | 0.50% | — | Intel Driver&support Assistant | 14/11/2018 | 17/6/2026 | Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access. |