Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

808 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.34%💥 ExploitSubtitle ProcessorAI20/8/202516/6/2026
Subtitle Processor 7.7.1 contains a buffer overflow vulnerability in its .m3u file parser. When a crafted playlist file is opened, the application converts input to Unicode and copies it to a fixed-size stack buffer without proper bounds checking. This allows an attacker to overwrite the Structured Exception Handler…
AplazadaMedia (5.3)0.24%—Appian Enterprise Business Process ManagementAI19/8/202517/6/2026
A security issue has been identified in Appian Enterprise Business Process Management version 25.3. The vulnerability is related to incorrect access control, which under certain conditions could allow unauthorized access to information. NOTE: this has been disputed because the CVE Record information does not originate…
AplazadaMedia (4.5)0.14%—Intel Xeon 6 ProcessorsAIIntel SGXAIIntel TDXAI12/8/202517/6/2026
Improperly implemented security check for standard in the DDRIO configuration for some Intel(R) Xeon(R) 6 Processors when using Intel(R) SGX or Intel(R) TDX may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (7)0.14%—Intel Xeon ProcessorsAI12/8/202517/6/2026
Insufficient control flow management in the Alias Checking Trusted Module (ACTM) firmware for some Intel(R) Xeon(R) processors may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.3)0.14%—Intel ProcessorsAI12/8/202517/6/2026
Improper Isolation or Compartmentalization in the stream cache mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7)0.15%—Intel Xeon Processor FirmwareAI12/8/202517/6/2026
Improper buffer restrictions for some Intel(R) Xeon(R) Processor firmware with SGX enabled may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.7)2.1%💥 ExploitProcessmaker Open SourceAI31/7/202516/6/2026
A code injection vulnerability exists in ProcessMaker Open Source versions 2.x when using the default 'neoclassic' skin. An authenticated user can execute arbitrary PHP code via multiple endpoints, including appFolderAjax.php, casesStartPage_Ajax.php, and cases_SchedulerGetPlugins.php, by supplying crafted POST…
AnalizadaMedia (6.1)0.19%—Oracle MES FOR Process Manufacturing15/7/202517/6/2026
Vulnerability in the Oracle MES for Process Manufacturing product of Oracle E-Business Suite (component: Device Integration). Supported versions that are affected are 12.2.12-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle MES for Process…
AplazadaAlta (8.6)1.6%💥 ExploitProcessmakerAI10/7/202517/6/2026
An unrestricted file upload vulnerability exists in ProcessMaker versions prior to 3.5.4 due to improper handling of uploaded plugin archives. An attacker with administrative privileges can upload a malicious .tar plugin file containing arbitrary PHP code. Upon installation, the plugin’s install() method is invoked,…
AplazadaMedia (5.6)0.34%—AMD ProcessorsAI8/7/202517/6/2026
A transient execution vulnerability in some AMD processors may allow an attacker to infer data in the L1D cache, potentially resulting in the leakage of sensitive information across privileged boundaries.
AplazadaMedia (5.6)0.49%—AMD ProcessorsAI8/7/202517/6/2026
A transient execution vulnerability in some AMD processors may allow an attacker to infer data from previous stores, potentially resulting in the leakage of privileged information.
AplazadaBaja (3.8)0.18%—AMD ProcessorsAI8/7/202517/6/2026
A transient execution vulnerability in some AMD processors may allow a user process to infer TSC_AUX even when such a read is disabled, potentially resulting in information leakage.
AplazadaBaja (3.8)0.33%—AMD ProcessorsAI8/7/202517/6/2026
A transient execution vulnerability in some AMD processors may allow a user process to infer the control registers speculatively even if UMIP feature is enabled, potentially resulting in information leakage.
AnalizadaBaja (2.1)0.38%—Itsourcecode Student Transcript Processing System8/7/202517/6/2026
A vulnerability has been found in itsourcecode Student Transcript Processing System 1.0 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /admin/modules/subject/edit.php. The manipulation of the argument pre leads to cross site scripting. The attack can be launched…
AplazadaMedia (6.4)0.22%—ProcessingjsAI4/7/202517/6/2026
The ProcessingJS for WordPress plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'pjs4wp' shortcode in all versions up to, and including, 1.2.2 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers,…
AplazadaCrítica (9.1)0.47%—Open Source Risc V ProcessorAI1/7/202517/6/2026
Improper mstatus.SUM bit retention (non-zero) in Open-Source RISC-V Processor commit f517abb violates privileged spec constraints, enabling potential physical memory access attacks.
AnalizadaAlta (8.2)0.25%—IBM Process Mining21/6/202517/6/2026
IBM Process Mining 2.0.1 IF001 and 2.0.1 could allow a remote attacker to conduct phishing attacks, using an open redirect attack. By persuading a victim to visit a specially crafted Web site, a remote attacker could exploit this vulnerability to spoof the URL displayed to redirect a user to a malicious Web site that…
AplazadaAlta (7.9)0.18%—AMD ASPAIAMD Crypto Co-processorAI10/6/202517/6/2026
Improper register access control in ASP may allow a privileged attacker to perform unauthorized access to ASP’s Crypto Co-Processor (CCP) registers from x86 resulting in potential loss of control of cryptographic key pointer/index leading to loss of integrity or confidentiality.
AplazadaMedia (4.3)0.22%—SAP Manage Processing RulesAI10/6/202517/6/2026
SAP Manage Processing Rules (For Bank Statement) allows an attacker with basic privileges to edit shared rules of any user by tampering the request parameter. Due to missing authorization check, the attacker can edit rules that should be restricted, compromising the integrity of the application.
AnalizadaAlta (8.2)0.30%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+2303/6/202517/6/2026
Information disclosure when an invalid RTCP packet is received during a VoLTE/VoWiFi IMS call.
AnalizadaAlta (8.2)0.24%—Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+2213/6/202517/6/2026
Information disclosure may occur while processing goodbye RTCP packet from network.
AnalizadaAlta (8.2)0.24%—Qualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 Firmware+2303/6/202517/6/2026
Information disclosure may occur while decoding the RTP packet with invalid header extension from network.
AplazadaAlta (8.7)0.32%—3DS 3dexperienceAI3DS Service Process EngineerAI30/5/202517/6/2026
A stored Cross-site Scripting (XSS) vulnerability affecting Service Items Management in Service Process Engineer from Release 3DEXPERIENCE R2024x through Release 3DEXPERIENCE R2025x allows an attacker to execute arbitrary script code in user's browser session.
AnalizadaCrítica (9.8)0.34%—Forestryks Process-sync24/5/202517/6/2026
In the process-sync crate 0.2.2 for Rust, the drop function lacks a check for whether the pthread_mutex is unlocked.
AnalizadaCrítica (9.8)0.27%—Tickbh Process Lock24/5/202517/6/2026
The process_lock crate 0.1.0 for Rust allows data races in unlock.