Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
100 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.89% | — | HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware | 12/6/2023 | 17/6/2026 | Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege. | |
| Modificada | Alta (8.8) | 24% | 💥 PoC | Bolt CMS | 16/9/2022 | 9/7/2026 | Bolt CMS contains a vulnerability in version 5.1.12 and below that allows an authenticated user with the ROLE_EDITOR privileges to upload and rename a malicious file to achieve remote code execution. | |
| Modificada | Crítica (9.1) | 0.85% | — | Boltcms Bolt | 1/8/2022 | 9/7/2026 | The foldername parameter in Bolt 5.1.7 was discovered to have incorrect input validation, allowing attackers to perform directory enumeration or cause a Denial of Service (DoS) via a crafted input. | |
| Modificada | Baja (3.5) | 0.54% | — | Perforce Puppet Bolt | 19/7/2022 | 17/6/2026 | Puppet Bolt prior to version 3.24.0 will print sensitive parameters when planning a run resulting in them potentially being logged when run programmatically, such as via Puppet Enterprise. | |
| Modificada | Alta (8.8) | 3.4% | — | Bolt CMS | 11/4/2022 | 9/7/2026 | Bolt CMS <= 4.2 is vulnerable to Remote Code Execution. Unsafe theme rendering allows an authenticated attacker to edit theme to inject server-side template injection that leads to remote code execution. | |
| Modificada | Media (6.1) | 2.3% | 💥 PoC | Boltwire | 15/2/2022 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in BoltWire v7.10 and v 8.00 allows attackers to execute arbitrary web scripts or HTML via a crafted payload in the name and lastname parameters. | |
| Modificada | Media (6.1) | 0.92% | — | Wbolt Smart SEO Tool | 24/1/2022 | 17/6/2026 | The Smart SEO Tool WordPress plugin before 3.0.6 does not sanitise and escape the search parameter before outputting it back in an attribute when the TDK optimisation setting is enabled, leading to a Reflected Cross-Site Scripting | |
| Modificada | Media (5.5) | 0.22% | — | Intel Thunderbolt DCH Driver | 17/11/2021 | 17/6/2026 | Improper access control in some Intel(R) Thunderbolt(TM) Windows DCH Drivers before version 1.41.1054.0 may allow unauthenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Thunderbolt Non-dch Driver | 17/11/2021 | 17/6/2026 | Improper permissions in the installer for the Intel(R) Thunderbolt(TM) non-DCH driver, all versions, for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.4) | 0.39% | — | Wbolt Donate With Qrcode | 20/9/2021 | 17/6/2026 | The Donate With QRCode WordPress plugin before 1.4.5 does not sanitise or escape its QRCode Image setting, which result into a Stored Cross-Site Scripting (XSS). Furthermore, the plugin also does not have any CSRF and capability checks in place when saving such setting, allowing any authenticated user (as low as… | |
| Modificada | Media (5.5) | 0.22% | — | Intel Dsl5320 Thunderbolt 2 FirmwareIntel Dsl5520 Thunderbolt 2 FirmwareIntel Dsl6340 Thunderbolt 3 FirmwareIntel Dsl6540 Thunderbolt 3 Firmware+9 | 9/6/2021 | 17/6/2026 | Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Jhl6240 Thunderbolt 3 FirmwareIntel Jhl6340 Thunderbolt 3 FirmwareIntel Jhl6540 Thunderbolt 3 FirmwareIntel Jhl7040 Thunderbolt 3 Retimer Firmware+9 | 9/6/2021 | 17/6/2026 | Improper input validation in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Jhl6240 Thunderbolt 3 FirmwareIntel Jhl6340 Thunderbolt 3 FirmwareIntel Jhl6540 Thunderbolt 3 FirmwareIntel Jhl7040 Thunderbolt 3 Retimer Firmware+9 | 9/6/2021 | 17/6/2026 | Insufficient control flow management in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Jhl6240 Thunderbolt 3 FirmwareIntel Jhl6340 Thunderbolt 3 FirmwareIntel Jhl6540 Thunderbolt 3 FirmwareIntel Jhl7040 Thunderbolt 3 Retimer Firmware+9 | 9/6/2021 | 17/6/2026 | Improper control of a resource through its lifetime in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Jhl6240 Thunderbolt 3 FirmwareIntel Jhl6340 Thunderbolt 3 FirmwareIntel Jhl6540 Thunderbolt 3 FirmwareIntel Jhl7040 Thunderbolt 3 Retimer Firmware+9 | 9/6/2021 | 17/6/2026 | Improper conditions check in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Jhl6240 Thunderbolt 3 FirmwareIntel Jhl6340 Thunderbolt 3 FirmwareIntel Jhl6540 Thunderbolt 3 FirmwareIntel Jhl7040 Thunderbolt 3 Retimer Firmware+9 | 9/6/2021 | 17/6/2026 | Uncontrolled resource consumption in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Jhl6240 Thunderbolt 3 FirmwareIntel Jhl6340 Thunderbolt 3 FirmwareIntel Jhl6540 Thunderbolt 3 FirmwareIntel Jhl7040 Thunderbolt 3 Retimer Firmware+9 | 9/6/2021 | 17/6/2026 | Improper access control in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Jhl6240 Thunderbolt 3 FirmwareIntel Jhl6340 Thunderbolt 3 FirmwareIntel Jhl6540 Thunderbolt 3 FirmwareIntel Jhl7040 Thunderbolt 3 Retimer Firmware+9 | 9/6/2021 | 17/6/2026 | Out-of-bounds write in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.22% | — | Intel Jhl6240 Thunderbolt 3 FirmwareIntel Jhl6340 Thunderbolt 3 FirmwareIntel Jhl6540 Thunderbolt 3 FirmwareIntel Jhl7040 Thunderbolt 3 Retimer Firmware+9 | 9/6/2021 | 17/6/2026 | Protection mechanism failure in some Intel(R) Thunderbolt(TM) controllers may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Alta (7.5) | 1.7% | — | Boltcms Bolt | 17/2/2021 | 17/6/2026 | Controller/Backend/FileEditController.php and Controller/Backend/FilemanagerController.php in Bolt before 4.1.13 allow Directory Traversal. | |
| Modificada | Media (5.3) | 1.1% | — | Boltcms Bolt | 30/12/2020 | 17/6/2026 | Bolt before 3.7.2 does not restrict filter options in a Request in the Twig context, and is therefore inconsistent with the "How to Harden Your PHP for Better Security" guidance. | |
| Modificada | Media (4.4) | 0.32% | — | Intel Thunderbolt DCH Driver | 12/11/2020 | 17/6/2026 | Protection mechanism failure in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.32% | — | Intel Thunderbolt DCH Driver | 12/11/2020 | 17/6/2026 | Insecure default variable initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.31% | — | Intel Thunderbolt DCH Driver | 12/11/2020 | 17/6/2026 | Improper initialization in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Thunderbolt DCH Driver | 12/11/2020 | 17/6/2026 | Improper buffer restrictions in some Intel(R) Thunderbolt(TM) DCH drivers for Windows* before version 72 may allow an authenticated user to potentially enable escalation of privilege via local access. |