Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.8)0.85%—Dfir-iris Iris25/4/202417/6/2026
Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. Due to an improper setup of Jinja2 environment, reports generation in `iris-web` is prone to a Server Side Template Injection (SSTI). Successful exploitation of the vulnerability can lead to an…
AnalizadaMedia (5.4)0.34%—Dfir-iris Iris19/2/202417/6/2026
Iris is a web collaborative platform that helps incident responders share technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations in versions prior to v2.4.0. The vulnerability may allow an attacker to inject malicious…
ModificadaMedia (5.4)0.30%—Dfir-iris Iris22/12/202317/6/2026
Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations in versions prior to v2.3.7. The vulnerability may allow an attacker to inject…
ModificadaAlta (7.3)0.20%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Unquoted search path or element in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.22%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Out-of-bounds read in the Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaAlta (7.8)0.22%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Out-of-bounds write in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows drivers before version 31.0.101.4255 may allow authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.17%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Incorrect default permissions in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.21%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
Out-of-bounds write in some Intel(R) Arc(TM) Control software before version 1.73.5335.2 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.18%—Intel Iris XE GraphicsIntel ARC A Graphics14/11/202317/6/2026
NULL pointer dereference in some Intel(R) Arc(TM) & Iris(R) Xe Graphics - WHQL - Windows Drviers before version 31.0.101.4255 may allow authenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.1)0.37%—Evarisk Digirisk3/11/202317/6/2026
The Digirisk plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via the 'current_group_id' parameter in version 6.0.0.0 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages that execute if they can…
ModificadaMedia (5.4)0.38%—Dfir-iris Iris25/5/202317/6/2026
Iris is a web collaborative platform aiming to help incident responders sharing technical details during investigations. A stored Cross-Site Scripting (XSS) vulnerability has been identified in iris-web, affecting multiple locations . The vulnerability in allows an attacker to inject malicious scripts into the…
ModificadaMedia (4.4)0.19%—Intel Iris XE MAX Dedicated Graphics16/2/202317/6/2026
Uncaught exception in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1436(v2) may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (5.5)0.18%—Intel Iris XE MAX Dedicated Graphics16/2/202317/6/2026
Out-of-bounds read in the Intel(R) Iris(R) Xe MAX drivers for Windows before version 100.0.5.1474 may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (5.4)0.57%—Iris Isams27/9/202217/6/2026
ISAMS 22.2.3.2 is prone to stored Cross-site Scripting (XSS) attack on the title field for groups, allowing an attacker to store a JavaScript payload that will be executed when another user uses the application.
ModificadaAlta (7.5)1.3%—Wiris Mathtype16/6/202217/6/2026
Wiris Mathtype v7.28.0 was discovered to contain a path traversal vulnerability in the resourceFile parameter. This vulnerability is exploited via a crafted request to the resource handler.
ModificadaAlta (8.8)4.2%—Canon Irisnext25/4/202217/6/2026
The BeanShell components of IRISNext through 9.8.28 allow execution of arbitrary commands on the target server by creating a custom search (or editing an existing/predefined search) of the documents. The search components permit adding BeanShell expressions that result in Remote Code Execution in the context of the…
ModificadaAlta (8.8)1.8%—Iris-go Iris24/12/202117/6/2026
This affects all versions of package github.com/kataras/iris; all versions of package github.com/kataras/iris/v12. The unsafe handling of file names during upload using UploadFormFiles method may enable attackers to write to arbitrary locations outside the designated target folder.
ModificadaAlta (7.8)0.26%—Intel Iris XE MAX Dedicated Graphics17/11/202117/6/2026
Improper access control in the installer for some Intel(R) Iris(R) Xe MAX Dedicated Graphics Drivers for Windows 10 before version 27.20.100.9466 may allow authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.4)0.55%—Irislink Irisnext6/7/202117/6/2026
Multiple stored XSS vulnerabilities in IrisNext Edition 9.5.16, which allows an authenticated (or compromised) user to inject malicious JavaScript in folder/file name within the application in order to grab other users’ sessions or execute malicious code in their browsers (1-click RCE).
ModificadaMedia (6.5)1.3%—Iris Star Practice Management29/1/202117/6/2026
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access details about jobs he should not have access to via the Audit Trail Feature.
ModificadaAlta (8.8)1.6%—Iris Star Practice Management29/1/202117/6/2026
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to change the privileges of any user of the application. This can be used to grant himself the administrative role or remove all administrative accounts of the application.
ModificadaMedia (6.5)1.3%—Iris Star Practice Management29/1/202117/6/2026
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access the Billing page without the appropriate privileges.
ModificadaAlta (8.8)0.66%—Iris Star29/1/202117/6/2026
A Cross-Site Request Forgery (CSRF) vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an attacker to change the privileges of any user of the application. This can be used to grant himself administrative role or remove the administrative account of the application.
ModificadaAlta (8.8)1.4%—Iris Star Practice Management29/1/202117/6/2026
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access Launcher Configuration Panel.
ModificadaMedia (6.5)1.3%—Iris Star Practice Management29/1/202117/6/2026
An improper authorization vulnerability exists in Star Practice Management Web version 2019.2.0.6, allowing an unauthorized user to access WIP details about jobs he should not have access to.