Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
92 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Vtune Profiler | 10/5/2023 | 17/6/2026 | Uncontrolled search path element in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Vtune Profiler | 10/5/2023 | 17/6/2026 | Insecure inherited permissions in the Intel(R) VTune(TM) Profiler software before version 2023.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 6.1% | 💥 Exploit | Filereplicationpro File Replication PRO | 14/4/2023 | 17/6/2026 | Diasoft File Replication Pro 7.5.0 allows attackers to escalate privileges by replacing a legitimate file with a Trojan horse that will be executed as LocalSystem. This occurs because %ProgramFiles%\FileReplicationPro allows Everyone:(F) access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Vtune Profiler | 11/11/2022 | 17/6/2026 | Uncontrolled search path in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.27% | — | Intel Vtune Profiler | 18/8/2022 | 17/6/2026 | Uncontrolled search path elements in the Intel(R) VTune(TM) Profiler software before version 2022.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 1.4% | — | Afian Filerun | 6/6/2022 | 17/6/2026 | In Afian Filerun 20220202, lack of sanitization of the POST parameter "metadata[]" in `/?module=fileman§ion=get&page=grid` leads to SQL injection. | |
| Modificada | Crítica (9.8) | 2.6% | — | Afian Filerun | 2/6/2022 | 17/6/2026 | In Afian Filerun 20220202 Changing the "search_tika_path" variable to a custom (and previously uploaded) jar file results in remote code execution in the context of the webserver user. | |
| Modificada | Alta (7.5) | 3.1% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Uncaught exceptions that can be generated in Trend Micro ServerProtection 6.0/5.8 Information Server could allow a remote attacker to crash the process. | |
| Modificada | Crítica (9.8) | 5.2% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Integer overflow conditions that exist in Trend Micro ServerProtect 6.0/5.8 Information Server could allow a remote attacker to crash the process or achieve remote code execution. | |
| Modificada | Crítica (9.8) | 2.7% | — | Trendmicro ServerprotectTrendmicro Serverprotect FOR Network Appliance FilerTrendmicro Serverprotect FOR Storage | 24/2/2022 | 17/6/2026 | Trend Micro ServerProtect 6.0/5.8 Information Server uses a static credential to perform authentication when a specific command is typed in the console. An unauthenticated remote attacker with access to the Information Server could exploit this to register to the server and perform authenticated actions. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Vtune Profiler | 17/11/2021 | 17/6/2026 | Incorrect default permissions in the software installer for the Intel(R) VTune(TM) Profiler before version 2021.3.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 0.74% | — | Afian Filerun | 5/10/2021 | 5/7/2026 | Afian FileRun 2021.03.26 allows XSS when an administrator encounters a crafted document during use of the HTML Editor for a preview or edit action. | |
| Modificada | Alta (7.2) | 2.8% | — | Afian Filerun | 5/10/2021 | 5/7/2026 | Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the magick binary. | |
| Modificada | Alta (7.2) | 3.2% | — | Afian Filerun | 5/10/2021 | 5/7/2026 | Afian FileRun 2021.03.26 allows Remote Code Execution (by administrators) via the Check Path value for the ffmpeg binary. | |
| Modificada | Media (6.1) | 0.74% | — | Afian Filerun | 5/10/2021 | 5/7/2026 | Afian FileRun 2021.03.26 allows stored XSS via an HTTP X-Forwarded-For header that is mishandled when rendering Activity Logs. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel Vtune Profiler | 9/6/2021 | 17/6/2026 | Insecure inherited permissions in the installer for the Intel(R) VTune(TM) Profiler before version 2021.1.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.62% | — | Trendmicro Apex CentralTrendmicro Apex ONETrendmicro Cloud EdgeTrendmicro Deep Security+15 | 3/3/2021 | 17/6/2026 | Trend Micro's Virus Scan API (VSAPI) and Advanced Threat Scan Engine (ATSE) - are vulnerable to a memory exhaustion vulnerability that may lead to denial-of-service or system freeze if exploited by an attacker using a specially crafted file. | |
| Modificada | Alta (7.8) | 0.32% | — | Intel Vtune Profiler | 12/11/2020 | 17/6/2026 | Uncontrolled search path in the Intel(R) VTune(TM) Profiler before version 2020 Update 1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 1.7% | — | Openfiler | 7/2/2020 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in admin/system.html in Openfiler 2.3 allows remote attackers to inject arbitrary web script or HTML via the device parameter. | |
| Modificada | Alta (7.8) | 0.34% | — | Intel Vtune Profiler | 17/1/2020 | 17/6/2026 | Improper access control in driver for Intel(R) VTune(TM) Amplifier for Windows* before update 8 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.1) | 3.6% | 💥 Exploit | Afian Filerun | 20/6/2019 | 17/6/2026 | FileRun 2019.05.21 allows XSS via the filename to the ?module=fileman§ion=do&page=up URI. This issue has been fixed in FileRun 2019.06.01. | |
| Modificada | Media (5.3) | 1.8% | — | Afian Filerun | 30/5/2019 | 17/6/2026 | FileRun 2019.05.21 allows customizables/plugins/audio_player Directory Listing. This issue has been fixed in FileRun 2019.06.01. | |
| Modificada | Media (5.3) | 1.8% | — | Afian Filerun | 30/5/2019 | 17/6/2026 | FileRun 2019.05.21 allows css/ext-ux Directory Listing. This issue has been fixed in FileRun 2019.06.01. | |
| Modificada | Media (5.3) | 1.8% | — | Afian Filerun | 30/5/2019 | 17/6/2026 | FileRun 2019.05.21 allows images/extjs Directory Listing. This issue has been fixed in FileRun 2019.06.01. |