Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.6) | 7.5% | — | Intel Atom CIntel Atom EIntel Atom ZIntel Celeron J+195 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a. | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Alta (8.8) | 34% | 💥 Exploit | Cognitect DatomicH2database H2 | 11/4/2018 | 17/6/2026 | H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment." | |
| Modificada | Media (6) | 0.34% | — | Intel Core I7-8550uIntel Core I7-8559uIntel Core I7-8650uIntel Core I7-8700+304 | 3/4/2018 | 17/6/2026 | Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially leading to a Denial of Service. | |
| Modificada | Media (5.6) | 0.67% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+205 | 27/3/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope. | |
| Modificada | Media (5.6) | 84% | 💥 PoC | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+205 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache. | |
| Modificada | Media (5.6) | 94% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+304 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Media (5.6) | 74% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+216 | 4/1/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis. | |
| Modificada | Crítica (10) | 3.2% | — | Projectatomic Bubblewrap | 29/3/2017 | 17/6/2026 | When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox. | |
| Modificada | Baja (3.3) | 0.40% | — | Projectatomic Oci-register-machine | 29/3/2017 | 17/6/2026 | The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Alta (7.5) | 1.6% | — | Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+16 | 27/2/2017 | 17/6/2026 | Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR. | |
| Modificada | Media (5.4) | 0.27% | — | Stephenvarga Atomic Fusion | 18/9/2014 | 17/6/2026 | The Atomic Fusion (aka com.bytesized.fusion) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.5) | 2.6% | 💥 Exploit | Atomic Photo Album | 23/10/2008 | 16/6/2026 | Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies. | |
| Modificada | Media (4.3) | 1.4% | 💥 Exploit | Constantin Charissis Atomic Photo Album | 30/9/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter. | |
| Modificada | Alta (7.5) | 1.1% | 💥 Exploit | Atomic Photo Album | 30/9/2008 | 16/6/2026 | SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter. | |
| Modificada | Alta (10) | 6.3% | 💥 Exploit | Neutrino-cms Atomic Edition | 11/7/2008 | 16/6/2026 | Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by manipulating data/sess.php in (1) usb and (2) del_pag actions. NOTE: this can be leveraged for code execution by performing an upload that bypasses the intended access… | |
| Modificada | Media (5) | 1.6% | — | Atomic Photo Album | 3/8/2005 | 16/6/2026 | PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter. |