Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

103 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.6)8.6%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+22110/7/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis.
ModificadaAlta (7.6)0.37%—Intel Xeon E3Intel Xeon E3 1220 V5Intel Xeon E3 1220 V6Intel Xeon E3 1225 V5+3010/7/201817/6/2026
Existing UEFI setting restrictions for DCI (Direct Connect Interface) in 5th and 6th generation Intel Xeon Processor E3 Family, Intel Xeon Scalable processors, and Intel Xeon Processor D Family allows a limited physical presence attacker to potentially access platform secrets via debug interfaces.
ModificadaMedia (5.6)7.5%—Intel Atom CIntel Atom EIntel Atom ZIntel Celeron J+19522/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and that perform speculative reads of system registers may allow unauthorized disclosure of system parameters to an attacker with local user access via a side-channel analysis, aka Rogue System Register Read (RSRE), Variant 3a.
ModificadaMedia (5.5)61%💥 ExploitIntel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+27822/5/201817/6/2026
Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),…
ModificadaMedia (5.6)0.67%—Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+20527/3/201817/6/2026
Systems with microprocessors utilizing speculative execution may allow unauthorized disclosure of information to an attacker with local user access via a side-channel attack on the directional branch predictor, as demonstrated by a pattern history table (PHT), aka BranchScope.
ModificadaMedia (5.6)84%💥 PoCIntel Atom CIntel Atom EIntel Atom X3Intel Atom Z+2054/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis of the data cache.
ModificadaMedia (5.6)94%💥 ExploitIntel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+3044/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaMedia (5.6)74%💥 ExploitIntel Atom CIntel Atom EIntel Atom X3Intel Atom X5-e3930+2164/1/201817/6/2026
Systems with microprocessors utilizing speculative execution and indirect branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis.
ModificadaMedia (4.3)1.6%—Platinum SEO Project Platinum SEO Plugin23/9/201316/6/2026
Cross-site scripting (XSS) vulnerability in platinum_seo_pack.php in the Platinum SEO plugin before 1.3.8 for WordPress allows remote attackers to inject arbitrary web script or HTML via the s parameter.
ModificadaAlta (7.5)0.99%💥 ExploitAlibabaclone Alibaba Clone Platinum6/5/201016/6/2026
SQL injection vulnerability in offers_buy.php in Alibaba Clone Platinum allows remote attackers to execute arbitrary SQL commands via the id parameter.
ModificadaMedia (4.3)1.2%💥 ExploitPlatinumprofitzone Turnkey Ebook Store2/4/200916/6/2026
Cross-site scripting (XSS) vulnerability in index.php in Turnkey Ebook Store 1.1 allows remote attackers to inject arbitrary web script or HTML via the keywords parameter in a search action.
ModificadaAlta (7.5)1.2%💥 ExploitGreatclone Auction Platinum31/7/200816/6/2026
SQL injection vulnerability in category.php in Greatclone GC Auction Platinum allows remote attackers to execute arbitrary SQL commands via the cate_id parameter.
ModificadaMedia (5)2.2%💥 ExploitFuture Nuke Php-nuke Platinum4/4/200816/6/2026
PHP-Nuke Platinum 7.6.b.5 allows remote attackers to obtain configuration information via a direct request to maintenance/index.php, which reveals settings such as magic_quotes_gpc.
ModificadaAlta (7.5)0.97%💥 ExploitFuturenuke PHP Nuke Platinum28/3/200816/6/2026
SQL injection vulnerability in includes/dynamic_titles.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary SQL commands via the p parameter to modules.php for the Forums module.
ModificadaMedia (6.8)2.3%💥 ExploitFuturenuke Platinum24/10/200716/6/2026
PHP remote file inclusion vulnerability in modules/Forums/favorites.php in PHP-Nuke Platinum 7.6.b.5 allows remote attackers to execute arbitrary PHP code via a URL in the nuke_bb_root_path parameter.
ModificadaAlta (7.8)3.0%—Panda ActivescanPanda AntivirusPanda Platinum 2006 Internet SecurityPanda Platinum 2007 Internet Security+29/5/200716/6/2026
Panda Software Antivirus before 20070402 allows remote attackers to cause a denial of service (infinite loop) via a ZOO archive with a direntry structure that points to a previous file.
ModificadaAlta (7.2)0.37%—Panda Platinum Internet Security9/9/200616/6/2026
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 stores service executables under the product's installation directory with weak permissions, which allows local users to obtain LocalSystem privileges by modifying (1) WebProxy.exe or (2) PAVSRV51.EXE.
ModificadaMedia (5)2.1%—Panda Platinum Internet Security9/9/200616/6/2026
The Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses predictable URLs for the spam classification of each message, which allows remote attackers to cause Panda to classify arbitrary messages as spam via a web page that contains IMG tags with the predictable URLs. NOTE: this issue could also be…
ModificadaMedia (5)2.1%—Panda Platinum Internet Security9/9/200616/6/2026
Panda Platinum Internet Security 2006 10.02.01 and 2007 11.00.00 uses sequential message numbers in generated URLs that are not filtered if the user replies to a message, which might allow remote attackers to determine mail usage patterns.
ModificadaMedia (5)3.8%💥 ExploitI-rater Platinum1/5/200616/6/2026
PHP remote file include vulnerability in admin/config_settings.tpl.php in I-RATER Platinum allows remote attackers to execute arbitrary code via a URL in the include_path parameter. NOTE: this is a different vector, and possibly a different vulnerability, than CVE-2006-1929.
ModificadaMedia (5)7.0%💥 ExploitI-rater Platinum20/4/200616/6/2026
PHP remote file inclusion vulnerability in include/common.php in I-Rater Platinum allows remote attackers to execute arbitrary PHP code via a URL in the include_path parameter.
ModificadaMedia (5)2.1%—E-blah Platinum21/2/200616/6/2026
Cross-site scripting vulnerability in E-Blah Platinum 9.7 allows remote attackers to inject arbitrary web script or HTML via the referer (HTTP_REFERER), which is not sanitized when the log file is viewed by the administrator using "Click Log".
ModificadaAlta (7.5)5.6%—Panda ActivescanPanda AntivirusPanda Antivirus PlatinumPanda Businessecure Antivirus+1530/11/200516/6/2026
Heap-based buffer overflow in pskcmp.dll in Panda Software Antivirus library allows remote attackers to execute arbitrary code via a crafted ZOO archive.
ModificadaAlta (7.5)1.5%—Platinum Dboardgear30/10/200516/6/2026
Multiple SQL injection vulnerabilities in DboardGear allow remote attackers to execute arbitrary SQL commands via (1) the buddy parameter in buddy.php, (2) the u2uid parameter in u2u.php, and (3) an invalid theme file in the themes action to ctrtools.php.
ModificadaMedia (5)3.1%💥 ExploitPlatinumftpserver2/5/200516/6/2026
PlatinumFTP 1.0.18, and possibly earlier versions, allows remote attackers to cause a denial of service (server crash) via multiple connection attempts with a \ (backslash) in the username.
Orbitaley — Vulnerabilidades