Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

489 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.57%—Performance Indicator System Project Performance Indicator System9/6/202317/6/2026
A vulnerability was found in SourceCodester Performance Indicator System 1.0. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/addproduct.php. The manipulation of the argument prodname leads to cross site scripting. The attack can be launched remotely.…
ModificadaAlta (8.8)0.26%—Wordpress Performance LAB25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WordPress Performance Team Performance Lab plugin <= 2.2.0 versions.
ModificadaAlta (7.5)0.57%—Jenkins Ns-nd Integration Performance Publisher16/5/202317/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them.
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.16%—Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+3710/5/202317/6/2026
Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.17%—Intel Integrated Performance Primitives Cryptography10/5/202317/6/2026
Insufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.20%—Intel Integrated Performance Primitives Cryptography10/5/202317/6/2026
Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.17%—Intel Integrated Performance Primitives Cryptography10/5/202317/6/2026
Insufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (4.4)0.16%—Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+3510/5/202317/6/2026
Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service via local access.
ModificadaMedia (6.5)1.3%—Solarwinds Database Performance Analyzer25/4/202317/6/2026
Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server.
ModificadaAlta (7.5)0.81%—Solarwinds Database Performance Analyzer25/4/202317/6/2026
No exception handling vulnerability which revealed sensitive or excessive information to users.
ModificadaMedia (6.1)0.41%—Rarathemes Vryasage Marketing Performance23/4/202317/6/2026
Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions.
ModificadaAlta (8.8)0.95%—Employee Performance Evaluation System Project Employee Performance Evaluation System14/4/202317/6/2026
Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server.
ModificadaAlta (8.2)0.57%—Jenkins Performance Publisher2/4/202317/6/2026
Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks.
ModificadaAlta (7.5)0.42%—Solarwinds Database Performance Analyzer20/1/202317/6/2026
In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext.
ModificadaMedia (5.4)0.40%—Solarwinds Database Performance Analyzer20/1/202317/6/2026
In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting.
ModificadaAlta (7.1)0.37%—Hitachienergy Lumada Asset Performance Management12/1/202317/6/2026
A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role, granting it access to the embedded Power BI reports feature. An attacker that manages to exploit the vulnerability on a customer’s Lumada APM…
ModificadaMedia (4.8)0.45%—Employee Performance Evaluation System Project Employee Performance Evaluation System19/12/20229/7/2026
Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module.
AnalizadaAlta (7.5)0.53%—CertifiNetapp E-series Performance AnalyzerNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI7/12/202217/6/2026
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root…
ModificadaMedia (6.5)0.68%—Jenkins Ns-nd Integration Performance Publisher15/11/202217/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system.
ModificadaAlta (7.5)0.42%—Jenkins Ns-nd Integration Performance Publisher15/11/202217/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM.
ModificadaAlta (7.5)0.42%—Jenkins Ns-nd Integration Performance Publisher15/11/202217/6/2026
Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features.
ModificadaAlta (7.8)0.17%—Intel NUC 10 Performance KIT Nuc10i7fnhn FirmwareIntel NUC 10 Performance KIT Nuc10i5fnkn FirmwareIntel NUC 10 Performance KIT Nuc10i5fnhn FirmwareIntel NUC 10 Performance KIT Nuc10i7fnkn Firmware+2211/11/202217/6/2026
Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0053 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.23%—Intel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+711/11/202217/6/2026
Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.5)2.7%—PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+59/11/202217/6/2026
An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote…
Orbitaley — Vulnerabilidades