Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

69 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.6)7.5%—Intel Atom CIntel Atom EIntel Atom ZIntel Celeron J+19522/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
ModificadaMedia (5.5)61%💥 ExploitIntel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+27822/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),…
ModificadaAlta (8.8)34%💥 ExploitCognitect DatomicH2database H211/4/201817/6/2026
H2 1.4.197, as used in Datomic before 0.9.5697 and other products, allows remote code execution because CREATE ALIAS can execute arbitrary Java code. NOTE: the vendor's position is "h2 is not designed to be run outside of a secure environment."
ModificadaMedia (6)0.34%—Intel Core I7-8550uIntel Core I7-8559uIntel Core I7-8650uIntel Core I7-8700+3043/4/201817/6/2026
Configuration of SPI Flash in platforms based on multiple Intel platforms allow a local attacker to alter the behavior of the SPI flash potentially leading to a Denial of Service.
ModificadaMedia (5.6)0.67%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+20527/3/201817/6/2026
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.
ModificadaMedia (5.6)84%💥 PoCIntel Atom CIntel Atom EIntel Atom X3Intel Atom Z+2054/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
ModificadaMedia (5.6)94%💥 ExploitIntel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaMedia (5.6)74%💥 ExploitIntel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+2164/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaCrítica (10)3.2%—Projectatomic Bubblewrap29/3/201717/6/2026
When executing a program via the bubblewrap sandbox, the nonpriv session can escape to the parent session by using the TIOCSTI ioctl to push characters into the terminal's input buffer, allowing an attacker to escape the sandbox.
ModificadaBaja (3.3)0.40%—Projectatomic Oci-register-machine29/3/201717/6/2026
The machinectl command in oci-register-machine allows local users to list running containers and possibly obtain sensitive information by running that command.
ModificadaAlta (7.5)1.6%—Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+1627/2/201717/6/2026
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern ARM processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
ModificadaAlta (7.5)1.6%—Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+1627/2/201717/6/2026
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern AMD processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
ModificadaAlta (7.5)1.6%—Allwinner A64AMD Athlon II 640 X4AMD E-350AMD Fx-8120 8-core+1627/2/201717/6/2026
Page table walks conducted by the MMU during virtual to physical address translation leave a trace in the last level cache of modern Intel processors. By performing a side-channel attack on the MMU operations, it is possible to leak data and code pointers from JavaScript, breaking ASLR.
ModificadaMedia (5.4)0.27%—Stephenvarga Atomic Fusion18/9/201417/6/2026
The Atomic Fusion (aka com.bytesized.fusion) application 1.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.5)2.6%💥 ExploitAtomic Photo Album23/10/200816/6/2026
Atomic Photo Album 1.1.0 pre4 does not properly handle the apa_cookie_login and apa_cookie_password cookies, which probably allows remote attackers to bypass authentication and gain administrative access via modified cookies.
ModificadaMedia (4.3)1.4%💥 ExploitConstantin Charissis Atomic Photo Album30/9/200816/6/2026
Cross-site scripting (XSS) vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to inject arbitrary web script or HTML via the apa_album_ID parameter.
ModificadaAlta (7.5)1.1%💥 ExploitAtomic Photo Album30/9/200816/6/2026
SQL injection vulnerability in album.php in Atomic Photo Album (APA) 1.1.0pre4 allows remote attackers to execute arbitrary SQL commands via the apa_album_ID parameter.
ModificadaAlta (10)6.3%💥 ExploitNeutrino-cms Atomic Edition11/7/200816/6/2026
Directory traversal vulnerability in index.php in Neutrino Atomic Edition 0.8.4 allows remote attackers to read and modify files, as demonstrated by manipulating data/sess.php in (1) usb and (2) del_pag actions. NOTE: this can be leveraged for code execution by performing an upload that bypasses the intended access…
ModificadaMedia (5)1.6%—Atomic Photo Album3/8/200516/6/2026
PHP remote file inclusion vulnerability in apa_phpinclude.inc.php in Atomic Photo Album (APA) allows remote attackers to execute arbitrary PHP code via the apa_module_basedir parameter.
Orbitaley — Vulnerabilidades