Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
–

795 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.73%—HP Support Assistant25/6/201917/6/2026
HP Support Assistant 8.7.50 and earlier allows a user to gain system privilege and allows unauthorized modification of directories or files. Note: A different vulnerability than CVE-2019-6329.
ModificadaAlta (8.3)1.1%—ABB Board Support Package Un31ABB Cp620 FirmwareABB Cp620-web FirmwareABB Cp630 Firmware+424/6/201917/6/2026
The ABB CP635 HMI uses two different transmission methods to upgrade its firmware and its software components: "Utilization of USB/SD Card to flash the device" and "Remote provisioning process via ABB Panel Builder 600 over FTP." Neither of these transmission methods implements any form of encryption or authenticity…
ModificadaAlta (7.8)0.26%—Dell Supportassist FOR Home PCSDell Supportassist FOR Business PCS20/6/201917/6/2026
Dell SupportAssist for Business PCs version 2.0 and Dell SupportAssist for Home PCs version 2.2, 2.2.1, 2.2.2, 2.2.3, 3.0, 3.0.1, 3.0.2, 3.1, 3.2, and 3.2.1 contain an Improper Privilege Management Vulnerability. A malicious local user can exploit this vulnerability by inheriting a system thread using a leaked thread…
ModificadaAlta (8.8)0.91%—Ranksol Live Call Support19/6/201917/6/2026
CSRF exists in server.php in Live Call Support Application 1.5 for adding an admin account.
ModificadaAlta (7.8)1.7%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine Browser Security PlusZohocorp Manageengine Desktop CentralZohocorp Manageengine Eventlog Analyzer+1418/6/201917/6/2026
Multiple Zoho ManageEngine products suffer from local privilege escalation due to improper permissions for the %SYSTEMDRIVE%\ManageEngine directory and its sub-folders. Moreover, the services associated with said products try to execute binaries such as sc.exe from the current directory upon system start. This will…
ModificadaAlta (7.8)50%—Haxx LibcurlOpensuse LeapFedoraproject FedoraDebian Linux+728/5/201917/6/2026
A heap buffer overflow in the TFTP receiving code allows for DoS or arbitrary code execution in libcurl versions 7.19.4 through 7.64.1.
ModificadaMedia (4.4)0.33%—Intel Driver & Support Assistant17/5/201917/6/2026
Insufficient input validation in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (4.4)0.38%—Intel Driver & Support Assistant17/5/201917/6/2026
Insufficient access control in Intel(R) Driver & Support Assistant version 19.3.12.3 and before may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (6.1)0.83%—Webidsupport Webid29/4/201917/6/2026
WeBid 1.2.2 has reflected XSS via the id parameter to admin/deletenews.php, admin/editbannersuser.php, admin/editfaqscategory.php, or admin/excludeuser.php, or the offset parameter to admin/edituser.php.
ModificadaAlta (8)16%💥 PoCDell Supportassist18/4/201917/6/2026
Dell SupportAssist Client versions prior to 3.2.0.90 contain a remote code execution vulnerability. An unauthenticated attacker, sharing the network access layer with the vulnerable system, can compromise the vulnerable system by tricking a victim user into downloading and executing arbitrary executables via…
ModificadaAlta (8.8)0.67%—Dell Supportassist18/4/201917/6/2026
Dell SupportAssist Client versions prior to 3.2.0.90 contain an improper origin validation vulnerability. An unauthenticated remote attacker could potentially exploit this vulnerability to attempt CSRF attacks on users of the impacted systems.
ModificadaCrítica (9.8)8.8%💥 PoCSupportcandy18/4/201917/6/2026
An Unrestricted File Upload Vulnerability in the SupportCandy plugin through 2.0.0 for WordPress allows remote attackers to execute arbitrary code by uploading a file with an executable extension.
ModificadaMedia (4.3)0.82%—Apple Support3/4/201917/6/2026
Analytics data was sent using HTTP rather than HTTPS. This was addressed by sending analytics data using HTTPS. This issue affected versions prior to Apple Support 2.4 for iOS.
ModificadaAlta (7.3)0.38%—HP Support Assistant27/3/201917/6/2026
HP Support Assistant before 8.7.50.3 allows an unauthorized person with local access to load arbitrary code.
ModificadaMedia (6.1)1.7%—Wpsupportplus WP Support Plus Responsive Ticket System21/3/201917/6/2026
A stored cross-site scripting (XSS) vulnerability in the submit_ticket.php module in the WP Support Plus Responsive Ticket System plugin 9.1.1 for WordPress allows remote attackers to inject arbitrary web script or HTML via the subject parameter in…
ModificadaMedia (5.5)0.30%—Opensuse Supportutils5/3/201917/6/2026
If the attacker manages to create files in the directory used to collect log files in supportutils before version 3.1-5.7.1 (e.g. with CVE-2018-19638) he can kill arbitrary processes on the local machine.
ModificadaAlta (7.8)0.50%—Opensuse Supportutils5/3/201917/6/2026
If supportutils before version 3.1-5.7.1 is run with -v to perform rpm verification and the attacker manages to manipulate the rpm listing (e.g. with CVE-2018-19638) he can execute arbitrary commands as root.
ModificadaMedia (4.7)0.40%—Opensuse Supportutils5/3/201917/6/2026
In supportutils, before version 3.1-5.7.1 and if pacemaker is installed on the system, an unprivileged user could have overwritten arbitrary files in the directory that is used by supportutils to collect the log files.
ModificadaMedia (5.5)0.46%—Opensuse Supportutils5/3/201917/6/2026
Supportutils, before version 3.1-5.7.1, wrote data to static file /tmp/supp_log, allowing local attackers to overwrite files on systems without symlink protection
ModificadaAlta (7.8)0.32%—Opensuse Supportutils5/3/201917/6/2026
Supportutils, before version 3.1-5.7.1, when run with command line argument -A searched the file system for a ndspath binary. If an attacker provides one at an arbitrary location it is executed with root privileges
ModificadaAlta (7.8)0.35%—Intel System Support Utility10/1/201917/6/2026
Insufficient path checking in Intel(R) System Support Utility for Windows before 2.5.0.15 may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.5)2.4%—Webidsupport Webid20/12/201817/6/2026
WeBid version up to current version 1.2.2 contains a Directory Traversal vulnerability in getthumb.php that can result in Arbitrary Image File Read. This attack appear to be exploitable via HTTP GET Request. This vulnerability appears to have been fixed in after commit 256a5f9d3eafbc477dcf77c7682446cc4b449c7f.
ModificadaMedia (6.1)1.6%—Webidsupport Webid20/12/201817/6/2026
WeBid version up to current version 1.2.2 contains a Cross Site Scripting (XSS) vulnerability in user_login.php, register.php that can result in Javascript execution in the user's browser, injection of malicious markup into the page. This attack appear to be exploitable via The victim user must click a malicous link.…
ModificadaAlta (8.8)1.5%—Webidsupport Webid20/12/201817/6/2026
WeBid version up to current version 1.2.2 contains a SQL Injection vulnerability in All five yourauctions*.php scripts that can result in Database Read via Blind SQL Injection. This attack appear to be exploitable via HTTP Request. This vulnerability appears to have been fixed in after commit…
ModificadaMedia (6.5)0.50%—Intel Driver&support Assistant14/11/201817/6/2026
Insufficient input validation in the Intel Driver & Support Assistant before 3.6.0.4 may allow an unauthenticated user to potentially enable information disclosure via adjacent access.