Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
73 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.6) | 0.55% | — | Intel Core I3Intel Core I5Intel Core I7Intel Core I9+28 | 21/9/2018 | 17/6/2026 | Platform sample code firmware in 4th Generation Intel Core Processor, 5th Generation Intel Core Processor, 6th Generation Intel Core Processor, 7th Generation Intel Core Processor and 8th Generation Intel Core Processor contains a logic error which may allow physical attacker to potentially bypass firmware… | |
| Modificada | Media (6.8) | 0.53% | — | Lenovo E42-80 FirmwareLenovo E42-80 ISK FirmwareLenovo E52-80 FirmwareLenovo E52-80 ISK Firmware+35 | 19/7/2018 | 17/6/2026 | In some Lenovo ThinkPad products, one BIOS region is not properly included in the checks, allowing injection of arbitrary code. | |
| Modificada | Alta (7.5) | 1.1% | — | Supercarboncoin Project Supercarboncoin | 5/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Super Carbon Coin (SCC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Alta (7.5) | 0.92% | — | Carbonexchangecointoken Project Carbonexchangecointoken | 3/7/2018 | 17/6/2026 | The mintToken function of a smart contract implementation for Carbon Exchange Coin Token (CEC), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value. | |
| Modificada | Media (5.5) | 0.44% | — | Carbonblack Carbon Black CB | 13/6/2018 | 17/6/2026 | An issue was discovered in Carbon Black Cb Response. A maliciously crafted Universal/fat binary can evade third-party code signing checks. By not completing full inspection of the Universal/fat binary, the user of the third-party tool will believe that the code is signed by Apple, but the malicious unsigned code will… | |
| Modificada | Crítica (9.8) | 1.7% | — | Carbonblack Carbon Black | 19/2/2018 | 17/6/2026 | A security design issue can allow an unprivileged user to interact with the Carbon Black Sensor and perform unauthorized actions. | |
| Modificada | Alta (7.5) | 1.0% | — | Carbonblack Carbon Black | 12/2/2018 | 17/6/2026 | cb.exe in Carbon Black 5.1.1.60603 allows attackers to cause a denial of service (out-of-bounds read, invalid pointer dereference, and application crash) by leveraging access to the NetMon named pipe. | |
| Modificada | Media (4.4) | 0.27% | — | Carbonblack Carbon Black | 12/2/2018 | 17/6/2026 | The cbstream.sys driver in Carbon Black 5.1.1.60603 allows local users with admin privileges to cause a denial of service (out-of-bounds read and system crash) via a large counter value in an 0x62430028 IOCTL call. | |
| Modificada | Alta (7.8) | 0.38% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+144 | 18/8/2017 | 17/6/2026 | A privilege escalation vulnerability was identified in Lenovo Active Protection System for ThinkPad systems versions earlier than 1.82.0.17. An attacker with local privileges could execute code with administrative privileges via an unquoted service path. | |
| Modificada | Media (6.1) | 4.0% | 💥 Exploit | Wso2 Carbon | 17/2/2017 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in WSO2 Carbon 4.4.5 allow remote attackers to inject arbitrary web script or HTML via the (1) setName parameter to identity-mgt/challenges-mgt.jsp; the (2) webappType or (3) httpPort parameter to webapp-list/webapp_info.jsp; the (4) dsName or (5) description… | |
| Modificada | Media (5.7) | 2.8% | 💥 Exploit | Wso2 Carbon | 17/2/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in WSO2 Carbon 4.4.5 allows remote attackers to hijack the authentication of privileged users for requests that shutdown a server via a shutdown action to server-admin/proxy_ajaxprocessor.jsp. | |
| Modificada | Media (4.9) | 12% | 💥 Exploit | Wso2 Carbon | 17/2/2017 | 17/6/2026 | Directory traversal vulnerability in the LogViewer Admin Service in WSO2 Carbon 4.4.5 allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the logFile parameter to downloadgz-ajaxprocessor.jsp. | |
| Modificada | Media (4.4) | 0.30% | — | Lenovo Thinkpad 10 Ella 2 BiosLenovo Thinkpad 11E Beema BiosLenovo Thinkpad 11E Braswell BiosLenovo Thinkpad 11E Broadwell Bios+70 | 30/11/2016 | 17/6/2026 | A vulnerability has been identified in a signed kernel driver for the BIOS of some ThinkPad systems that can allow an attacker with Windows administrator-level privileges to call System Management Mode (SMM) services. This could lead to a denial of service attack or allow certain BIOS variables or settings to be… | |
| Modificada | Media (6.8) | 0.61% | — | Carbonblack Carbon Black | 22/4/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Carbon Black before 4.1.0 allow remote attackers to hijack the authentication of administrators for requests that add new administrative users and have other unspecified action, as demonstrated by a request to api/user. | |
| Modificada | Baja (2.1) | 0.33% | — | Apple MAC OS XApple CarboncoreApple MAC OS X Server | 23/3/2011 | 16/6/2026 | The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory. | |
| Modificada | Alta (9.3) | 3.8% | — | Apple Carboncore | 4/8/2008 | 16/6/2026 | Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long filename to the file management API. | |
| Modificada | Alta (7.5) | 1.2% | — | Carbon Communities | 22/4/2008 | 16/6/2026 | option_Update.asp in Carbon Communities 2.4 and earlier allows remote attackers to edit arbitrary member information via a modified ID field. | |
| Modificada | Media (4.3) | 1.7% | 💥 Exploit | Carboncommunities Carbon Communities | 18/4/2008 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to inject arbitrary web script or HTML via the (1) Redirect parameter to login.asp and the (2) OrderBy parameter to member_send.asp. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Carboncommunities Carbon Communities | 18/4/2008 | 16/6/2026 | Multiple SQL injection vulnerabilities in Carbon Communities 2.4 and earlier allow remote attackers to execute arbitrary SQL commands via the (1) ID parameter to events.asp, the (2) UserName parameter to getpassword.asp, and possibly an unspecified parameter to (3) option_Update.asp in an edit action. | |
| Modificada | Alta (10) | 2.9% | — | Carbonize Lazarus Guestbook | 16/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in template.class.php in Carbonize Lazarus Guestbook before 1.7.3 allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter to admin.php, probably due to a dynamic variable evaluation vulnerability. | |
| Modificada | Alta (7.5) | 1.6% | — | Carbon Communities | 5/1/2007 | 16/6/2026 | CarbonCommunities stores sensitive information under the web root with insufficient access control, which allows remote attackers to download a database containing passwords via a direct request for DataBase/Carbon2.4d.mdb. | |
| Modificada | Media (4.3) | 2.5% | 💥 Exploit | Carbonize Lazarus Guestbook | 18/7/2006 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Carbonize Lazarus Guestbook 1.6 and earlier allow remote attackers to inject arbitrary web script or HTML via (1) the show parameter in codes-english.php and (2) the img parameter in picture.php, after the name of an existing file. | |
| Modificada | Alta (7.2) | 0.34% | — | Altiris Carbon Copy | 21/10/2004 | 16/6/2026 | Carbon Copy 6.0.5257 does not drop system privileges when opening external programs through the help topic interface, which allows local users to gain privileges via (1) the help topic interface in CCW32.exe, which launches Notepad, or (2) the help button in the Carbon Copy Scheduler (CCSched.exe). |