Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.20%—Intel AdvisorIntel Oneapi Base Toolkit12/2/202517/6/2026
Uncontrolled search path for some Intel(R) Advisor software before version 2024.2 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6.3)0.27%—Google Gvisor30/1/202517/6/2026
Weaknesses in the generation of TCP/UDP source ports and some other header values in Google's gVisor allowed them to be predicted by an external attacker in some circumstances.
AnalizadaMedia (6.3)0.22%—Google Gvisor30/1/202517/6/2026
A weak hashing algorithm and small sizes of seeds/secrets in Google's gVisor allowed for a remote attacker to calculate a local IP address and a per-boot identifier that could aid in tracking of a device in certain circumstances.
AplazadaCrítica (9.4)0.78%—Hitachi OPS Center AnalyzerAIHitachi Infrastructure Analytics AdvisorAI17/12/202417/6/2026
Authentication Bypass vulnerability in Hitachi Ops Center Analyzer on Linux, 64 bit (Hitachi Ops Center Analyzer detail view component), Hitachi Infrastructure Analytics Advisor on Linux, 64 bit (Hitachi Data Center Analytics component ).This issue affects Hitachi Ops Center Analyzer: from 10.0.0-00 before 11.0.3-00;…
AnalizadaMedia (5.9)0.35%—IBM Powervm Hypervisor22/11/202417/6/2026
IBM PowerVM Platform KeyStore (IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1030.00 through FW1030.60, FW1050.00 through FW1050.20, and FW1060.00 through FW1060.10 functionality can be compromised if an attacker gains service access to the HMC. An attacker that gains service access to the HMC can locate and…
ModificadaAlta (7.2)44%—Kemptechnologies LoadmasterKemptechnologies Multi-tenant Hypervisor Firmware5/9/202417/6/2026
Improper Input Validation vulnerability in Progress LoadMaster allows OS Command Injection.This issue affects: * LoadMaster: 7.2.40.0 and above * ECS: All versions * Multi-Tenancy: 7.1.35.4 and above
AnalizadaMedia (5.4)0.12%—Intel AdvisorIntel Oneapi Base Toolkit14/8/202417/6/2026
Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaAlta (8.1)0.41%—Ncia Advisor Network17/7/202417/6/2026
NATO NCI ANET 3.4.1 allows Insecure Direct Object Reference via a modified ID field in a request for a private draft report (that belongs to an arbitrary user).
AnalizadaMedia (6.5)0.35%—Ncia Advisor Network17/7/202417/6/2026
NATO NCI ANET 3.4.1 mishandles report ownership. A user can create a report and, despite the restrictions imposed by the UI, change the author of that report to an arbitrary user (without their consent or knowledge) via a modified UUID in a POST request.
ModificadaMedia (6)0.17%—Citrix XenserverCitrix Hypervisor13/6/202417/6/2026
An issue has been identified in both XenServer 8 and Citrix Hypervisor 8.2 CU1 LTSR which may allow a malicious administrator of a guest VM to cause the host to become slow and/or unresponsive.
AplazadaAlta (7.6)0.39%—Ljapps WP Tripadvisor Review SliderAI3/6/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in LJ Apps WP TripAdvisor Review Slider allows Blind SQL Injection.This issue affects WP TripAdvisor Review Slider: from n/a through 12.6.
ModificadaMedia (5.5)0.50%—Linux KernelNetapp Converged Systems Advisor AgentNetapp Solidfire & HCI Management NodeNetapp Solidfire & HCI Storage Node+630/5/20244/8/2026
In the Linux kernel, the following vulnerability has been resolved: NFSD: Fix nfsd4_encode_fattr4() crasher Ensure that args.acl is initialized early. It is used in an unconditional call to kfree() on the way out of nfsd4_encode_fattr4().
AnalizadaMedia (6.5)0.13%—Dell Data Protection AdvisorDell Dp4400 FirmwareDell Dp5900 Firmware29/5/202417/6/2026
Dell Data Protection Advisor, version(s) 19.9, contain(s) an Inadequate Encryption Strength vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Denial of service.
AnalizadaAlta (7.8)0.19%—Intel AdvisorIntel Oneapi Base Toolkit16/5/202417/6/2026
Uncontrolled search path in some Intel(R) Advisor software before version 2024.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6.5)0.17%—Google Gvisor15/5/202417/6/2026
A denial of service exists in Gvisor Sandbox where a bug in reference counting code in mount point tracking could lead to a panic, making it possible for an attacker running as root and with permission to mount volumes to kill the sandbox. We recommend upgrading past commit 6a112c60a257dadac59962e0bc9e9b5aee70b5b6
AnalizadaAlta (8.1)1.6%—Redhat Build OF KeycloakRedhat Jboss Middleware Text-only AdvisoriesRedhat KeycloakRedhat Migration Toolkit FOR Applications+617/4/20244/8/2026
A flaw was found in Keycloak, where it does not properly validate URLs included in a redirect. This issue could allow an attacker to construct a malicious request to bypass validation and access other URLs and sensitive information within the domain or conduct further attacks. This flaw affects any client that…
AnalizadaBaja (2.5)0.22%—Iovisor BPF Compiler Collection10/3/202417/6/2026
If kernel headers need to be extracted, bcc will attempt to load them from a temporary directory. An unprivileged attacker could use this to force bcc to load compromised linux headers. Linux distributions which provide kernel headers by default are not affected by default.
AnalizadaAlta (7.8)0.16%—Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+1214/2/202417/6/2026
Improper access control in the Intel(R) oneAPI DPC++/C++ Compiler before version 2022.2.1 for some Intel(R) oneAPI Toolkits before version 2022.3.1 may allow authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (6)0.17%—Intel AdvisorIntel Cluster CheckerIntel Distribution FOR PythonIntel Inspector+1214/2/202417/6/2026
Improper buffer restrictions the Intel(R) C++ Compiler Classic before version 2021.8 for Intel(R) oneAPI Toolkits before version 2022.3.1 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.17%—IBM Powervm Hypervisor6/2/202417/6/2026
IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could allow a system administrator to obtain sensitive partition information. IBM X-Force ID: 269695.
ModificadaMedia (4.9)0.37%—IBM Powervm Hypervisor4/2/202417/6/2026
IBM PowerVM Hypervisor FW950.00 through FW950.90, FW1020.00 through FW1020.40, and FW1030.00 through FW1030.30 could reveal sensitive partition data to a system administrator. IBM X-Force ID: 257135.
ModificadaMedia (4.8)0.40%—Ljapps WP Tripadvisor Review Slider1/1/202417/6/2026
The WP TripAdvisor Review Slider WordPress plugin before 11.9 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup)
ModificadaMedia (6.8)0.38%—Intel AdvisorIntel InspectorIntel MPI LibraryIntel Oneapi Base Toolkit+114/11/202317/6/2026
Protection mechanism failure in some Intel(R) oneAPI HPC Toolkit 2023.1 and Intel(R)MPI Library software before version 2021.9 may allow a privileged user to potentially enable escalation of privilege via adjacent access.
ModificadaAlta (7.8)0.25%—Intel AdvisorIntel InspectorIntel MPI LibraryIntel Oneapi Base Toolkit+114/11/202317/6/2026
Path traversal in the some Intel(R) oneAPI Toolkits and Component software before version 2023.1 may allow authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)2.7%—Redhat UndertowRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR IBM LinuxoneRedhat Openshift Container Platform FOR Power+327/9/202317/6/2026
A flaw was found in undertow. Servlets annotated with @MultipartConfig may cause an OutOfMemoryError due to large multipart content. This may allow unauthorized users to cause remote Denial of Service (DoS) attack. If the server uses fileSizeThreshold to limit the file size, it's possible to bypass the limit by…