Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

339 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.20%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.18%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.18%—Intel Driver & Support Assistant14/2/202417/6/2026
Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access.
ModificadaCrítica (9.8)0.70%—Mitel Unify Openscape Xpressions Webassistant8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal.
ModificadaAlta (8.8)0.92%—Mitel Unify Openscape Xpressions Webassistant8/2/202417/6/2026
An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload.
ModificadaAlta (8.8)1.4%💥 PoC10web AI Assistant5/2/202417/6/2026
The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin AJAX action in all versions up to, and including, 1.0.18. This makes it possible for authenticated attackers, with subscriber-level…
ModificadaAlta (8.8)1.1%💥 PoCBarassistant BAR Assistant10/1/202417/6/2026
Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code.
ModificadaMedia (5.9)0.56%—Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+1018/12/202317/6/2026
An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks.
ModificadaMedia (4.3)0.91%—Home-assistant15/12/202317/6/2026
Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch for this issue. When starting the Home Assistant 2023.12 release, the…
ModificadaMedia (6.5)1.0%—Gladysassistant Gladys Assistant7/12/202317/6/2026
Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine.
ModificadaAlta (8.8)0.39%—Wpindeed Debug Assistant13/11/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions.
ModificadaAlta (7.8)0.17%—HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware31/10/202317/6/2026
Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.
ModificadaAlta (8.8)0.69%—Fastlinemedia Assistant26/10/202317/6/2026
The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to perform SSRF attacks
ModificadaMedia (5.3)0.42%—Home-assistant20/10/202317/6/2026
Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessible from the local network. This issue is facilitated by the SniTun proxy, which…
ModificadaMedia (5.4)0.40%—Home-assistant20/10/202317/6/2026
Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication will be sent to the URL specified in the aforementioned parameters.…
ModificadaAlta (8.8)0.28%—Home-assistant Home Assistant Companion19/10/202317/6/2026
The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when visited, will make the victim to call arbitrary services in their Home Assistant installation. Combined with this security advisory, may…
ModificadaAlta (7.2)0.46%—Home-assistant19/10/202317/6/2026
Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able to invoke any Supervisor REST API endpoints with a POST request. An…
ModificadaAlta (7.8)0.17%💥 PoCHome-assistant Home Assistant Companion19/10/202317/6/2026
Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This enables all sorts of attacks, including arbitrary JavaScript execution, limited native code execution, and credential theft. This issue has…
ModificadaCrítica (9.6)0.95%—Home-assistant19/10/202317/6/2026
Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert clickjacking attacks and alternative…
ModificadaCrítica (9)0.27%—Home-assistantHome-assistant-js-websocket19/10/202317/6/2026
Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the `hassUrl`, which is subsequently utilized…
ModificadaCrítica (9.6)0.67%—Home-assistant19/10/202317/6/2026
Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redirect_uri` validation typically ensures that it matches the `client_id`…
ModificadaMedia (4.8)0.34%—Davidlingren Media Library Assistant17/10/202317/6/2026
Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 versions.
ModificadaAlta (8.8)0.21%—Rayhan1 AI Content Writing Assistant12/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in ReCorp AI Content Writing Assistant (Content Writer, GPT 3 & 4, ChatGPT, Image Generator) All in One plugin <= 1.1.5 versions.
ModificadaAlta (8.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform portal. This is also known as…
ModificadaAlta (8.8)1.3%—Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager9/10/202317/6/2026
Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This is also known as OSFOURK-24120.
Orbitaley — Vulnerabilidades