Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
482 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.57% | — | Jenkins Ns-nd Integration Performance Publisher | 16/5/2023 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.149 and earlier does not mask credentials displayed on the configuration form, increasing the potential for attackers to observe and capture them. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.16% | — | Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+37 | 10/5/2023 | 17/6/2026 | Improper access control for some Intel(R) NUC BIOS firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.17% | — | Intel Integrated Performance Primitives Cryptography | 10/5/2023 | 17/6/2026 | Insufficient control flow management in the Intel(R) IPP Cryptography software before version 2021.6 may allow an unauthenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.20% | — | Intel Integrated Performance Primitives Cryptography | 10/5/2023 | 17/6/2026 | Incomplete cleanup in the Intel(R) IPP Cryptography software before version 2021.6 may allow a privileged user to potentially enable information disclosure via local access. | |
| Modificada | Media (5.5) | 0.17% | — | Intel Integrated Performance Primitives Cryptography | 10/5/2023 | 17/6/2026 | Insufficient control flow management for the Intel(R) IPP Cryptography software before version 2021.6 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Modificada | Media (4.4) | 0.16% | — | Intel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+35 | 10/5/2023 | 17/6/2026 | Improper access control in firmware for some Intel(R) NUC Boards, Intel(R) NUC 11 Performance Kit, Intel(R) NUC 11 Performance Mini PC, Intel(R) NUC Pro Compute Element may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Media (6.5) | 1.3% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | Directory traversal and file enumeration vulnerability which allowed users to enumerate to different folders of the server. | |
| Modificada | Alta (7.5) | 0.81% | — | Solarwinds Database Performance Analyzer | 25/4/2023 | 17/6/2026 | No exception handling vulnerability which revealed sensitive or excessive information to users. | |
| Modificada | Media (6.1) | 0.41% | — | Rarathemes Vryasage Marketing Performance | 23/4/2023 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) vulnerability in VryaSage Marketing Performance plugin <= 2.0.0 versions. | |
| Modificada | Alta (8.8) | 0.95% | — | Employee Performance Evaluation System Project Employee Performance Evaluation System | 14/4/2023 | 17/6/2026 | Employee Performance Evaluation System v1.0 was discovered to contain an arbitrary file upload vulnerability which allows attackers to execute arbitrary code via a crafted file uploaded to the server. | |
| Modificada | Alta (8.2) | 0.57% | — | Jenkins Performance Publisher | 2/4/2023 | 17/6/2026 | Jenkins Performance Publisher Plugin 8.09 and earlier does not configure its XML parser to prevent XML external entity (XXE) attacks. | |
| Modificada | Alta (7.5) | 0.42% | — | Solarwinds Database Performance Analyzer | 20/1/2023 | 17/6/2026 | In DPA 2022.4 and older releases, generated heap memory dumps contain sensitive information in cleartext. | |
| Modificada | Media (5.4) | 0.40% | — | Solarwinds Database Performance Analyzer | 20/1/2023 | 17/6/2026 | In Database Performance Analyzer (DPA) 2022.4 and older releases, certain URL vectors are susceptible to authenticated reflected cross-site scripting. | |
| Modificada | Alta (7.1) | 0.37% | — | Hitachienergy Lumada Asset Performance Management | 12/1/2023 | 17/6/2026 | A vulnerability exists in the affected versions of Lumada APM’s User Asset Group feature due to a flaw in access control mechanism implementation on the “Limited Engineer” role, granting it access to the embedded Power BI reports feature. An attacker that manages to exploit the vulnerability on a customer’s Lumada APM… | |
| Modificada | Media (4.8) | 0.45% | — | Employee Performance Evaluation System Project Employee Performance Evaluation System | 19/12/2022 | 9/7/2026 | Employee Performance Evaluation System v1.0 was discovered to contain a persistent cross-site scripting (XSS) vulnerability via adding new entries under the Departments and Designations module. | |
| Analizada | Alta (7.5) | 0.51% | — | CertifiNetapp E-series Performance AnalyzerNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI | 7/12/2022 | 17/6/2026 | Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root… | |
| Modificada | Media (6.5) | 0.68% | — | Jenkins Ns-nd Integration Performance Publisher | 15/11/2022 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier stores passwords unencrypted in job config.xml files on the Jenkins controller where they can be viewed by attackers with Extended Read permission, or access to the Jenkins controller file system. | |
| Modificada | Alta (7.5) | 0.42% | — | Jenkins Ns-nd Integration Performance Publisher | 15/11/2022 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.143 and earlier globally and unconditionally disables SSL/TLS certificate and hostname validation for the entire Jenkins controller JVM. | |
| Modificada | Alta (7.5) | 0.42% | — | Jenkins Ns-nd Integration Performance Publisher | 15/11/2022 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.146 and earlier unconditionally disables SSL/TLS certificate and hostname validation for several features. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel NUC 10 Performance KIT Nuc10i7fnhn FirmwareIntel NUC 10 Performance KIT Nuc10i5fnkn FirmwareIntel NUC 10 Performance KIT Nuc10i5fnhn FirmwareIntel NUC 10 Performance KIT Nuc10i7fnkn Firmware+22 | 11/11/2022 | 17/6/2026 | Improper access control in BIOS firmware for some Intel(R) NUC 10 Performance Kits and Intel(R) NUC 10 Performance Mini PCs before version FNCML357.0053 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.23% | — | Intel NUC 11 Performance KIT Nuc11pahi30z FirmwareIntel NUC 11 Performance KIT Nuc11pahi50z FirmwareIntel NUC 11 Performance KIT Nuc11pahi70z FirmwareIntel NUC 11 Performance KIT Nuc11pahi3 Firmware+7 | 11/11/2022 | 17/6/2026 | Improper input validation in BIOS firmware for some Intel(R) NUC 11 Performance kits and Intel(R) NUC 11 Performance Mini PCs before version PATGL357.0042 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 2.7% | — | PythonFedoraproject FedoraNetapp Active IQ Unified ManagerNetapp E-series Performance Analyzer+5 | 9/11/2022 | 17/6/2026 | An issue was discovered in Python before 3.11.1. An unnecessary quadratic algorithm exists in one path when processing some inputs to the IDNA (RFC 3490) decoder, such that a crafted, unreasonably long name being presented to the decoder could lead to a CPU denial of service. Hostnames are often supplied by remote… | |
| Modificada | Alta (7.8) | 0.27% | — | GrafanaNetapp E-series Performance Analyzer | 13/10/2022 | 17/6/2026 | Grafana is an open source observability and data visualization platform. Versions prior to 9.1.8 and 8.5.14 are vulnerable to a bypass in the plugin signature verification. An attacker can convince a server admin to download and successfully run a malicious plugin even though unsigned plugins are not allowed. Versions… | |
| Modificada | Media (5.4) | 0.62% | — | Jenkins Ns-nd Integration Performance Publisher | 21/9/2022 | 17/6/2026 | Jenkins NS-ND Integration Performance Publisher Plugin 4.8.0.134 and earlier does not escape configuration options of the Execute NetStorm/NetCloud Test build step, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers with Item/Configure permission. |