Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.20% | — | Intel Driver & Support Assistant | 14/2/2024 | 17/6/2026 | Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Driver & Support Assistant | 14/2/2024 | 17/6/2026 | Improper access control in some Intel(R) DSA software before version 23.4.33 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.18% | — | Intel Driver & Support Assistant | 14/2/2024 | 17/6/2026 | Improper access control in some Intel(R) DSA software before version 23.4.33 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 0.70% | — | Mitel Unify Openscape Xpressions Webassistant | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows path traversal. | |
| Modificada | Alta (8.8) | 0.92% | — | Mitel Unify Openscape Xpressions Webassistant | 8/2/2024 | 17/6/2026 | An issue was discovered in Atos Unify OpenScape Xpressions WebAssistant V7 before V7R1 FR5 HF42 P911. It allows authenticated remote code execution via file upload. | |
| Modificada | Alta (8.8) | 1.4% | 💥 PoC | 10web AI Assistant | 5/2/2024 | 17/6/2026 | The 10Web AI Assistant – AI content writing assistant plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the install_plugin AJAX action in all versions up to, and including, 1.0.18. This makes it possible for authenticated attackers, with subscriber-level… | |
| Modificada | Alta (8.8) | 1.1% | 💥 PoC | Barassistant BAR Assistant | 10/1/2024 | 17/6/2026 | Blind Server-Side Request Forgery (SSRF) vulnerability in karlomikus Bar Assistant before version 3.2.0 does not validate a parameter before making a request through Image::make(), which could allow authenticated remote attackers to execute arbitrary code. | |
| Modificada | Media (5.9) | 0.56% | — | Bosch Building Integration System Video EngineBosch Video Management SystemBosch Video Management System ViewerBosch Configuration Manager+10 | 18/12/2023 | 17/6/2026 | An improper handling of a malformed API answer packets to API clients in Bosch BT software products can allow an unauthenticated attacker to cause a Denial of Service (DoS) situation. To exploit this vulnerability an attacker has to replace an existing API server e.g. through Man-in-the-Middle attacks. | |
| Modificada | Media (4.3) | 0.91% | — | Home-assistant | 15/12/2023 | 17/6/2026 | Home Assistant is open source home automation software. Prior to version 2023.12.3, the login page discloses all active user accounts to any unauthenticated browsing request originating on the Local Area Network. Version 2023.12.3 contains a patch for this issue. When starting the Home Assistant 2023.12 release, the… | |
| Modificada | Media (6.5) | 1.0% | — | Gladysassistant Gladys Assistant | 7/12/2023 | 17/6/2026 | Gladys Assistant v4.27.0 and prior is vulnerable to Directory Traversal. The patch of CVE-2023-43256 was found to be incomplete, allowing authenticated attackers to extract sensitive files in the host machine. | |
| Modificada | Alta (8.8) | 0.39% | — | Wpindeed Debug Assistant | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions. | |
| Modificada | Alta (7.8) | 0.17% | — | HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware | 31/10/2023 | 17/6/2026 | Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege. | |
| Modificada | Alta (8.8) | 0.69% | — | Fastlinemedia Assistant | 26/10/2023 | 17/6/2026 | The Assistant WordPress plugin before 1.4.4 does not validate a parameter before making a request to it via wp_remote_get(), which could allow users with a role as low as Editor to perform SSRF attacks | |
| Modificada | Media (5.3) | 0.42% | — | Home-assistant | 20/10/2023 | 17/6/2026 | Home assistant is an open source home automation. The assessment verified that webhooks available in the webhook component are triggerable via the `*.ui.nabu.casa` URL without authentication, even when the webhook is marked as Only accessible from the local network. This issue is facilitated by the SniTun proxy, which… | |
| Modificada | Media (5.4) | 0.40% | — | Home-assistant | 20/10/2023 | 17/6/2026 | Home assistant is an open source home automation. The audit team’s analyses confirmed that the `redirect_uri` and `client_id` are alterable when logging in. Consequently, the code parameter utilized to fetch the `access_token` post-authentication will be sent to the URL specified in the aforementioned parameters.… | |
| Modificada | Alta (8.8) | 0.28% | — | Home-assistant Home Assistant Companion | 19/10/2023 | 17/6/2026 | The Home Assistant Companion for iOS and macOS app up to version 2023.4 are vulnerable to Client-Side Request Forgery. Attackers may send malicious links/QRs to victims that, when visited, will make the victim to call arbitrary services in their Home Assistant installation. Combined with this security advisory, may… | |
| Modificada | Alta (7.2) | 0.46% | — | Home-assistant | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. In affected versions the `hassio.addon_stdin` is vulnerable to a partial Server-Side Request Forgery where an attacker capable of calling this service (e.g.: through GHSA-h2jp-7grc-9xpp) may be able to invoke any Supervisor REST API endpoints with a POST request. An… | |
| Modificada | Alta (7.8) | 0.17% | 💥 PoC | Home-assistant Home Assistant Companion | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. The Home Assistant Companion for Android app up to version 2023.8.2 is vulnerable to arbitrary URL loading in a WebView. This enables all sorts of attacks, including arbitrary JavaScript execution, limited native code execution, and credential theft. This issue has… | |
| Modificada | Crítica (9.6) | 0.95% | — | Home-assistant | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. Home Assistant server does not set any HTTP security headers, including the X-Frame-Options header, which specifies whether the web page is allowed to be framed. The omission of this and correlating headers facilitates covert clickjacking attacks and alternative… | |
| Modificada | Crítica (9) | 0.27% | — | Home-assistantHome-assistant-js-websocket | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. Whilst auditing the frontend code to identify hidden parameters, Cure53 detected `auth_callback=1`, which is leveraged by the WebSocket authentication logic in tandem with the `state` parameter. The state parameter contains the `hassUrl`, which is subsequently utilized… | |
| Modificada | Crítica (9.6) | 0.67% | — | Home-assistant | 19/10/2023 | 17/6/2026 | Home assistant is an open source home automation. The Home Assistant login page allows users to use their local Home Assistant credentials and log in to another website that specifies the `redirect_uri` and `client_id` parameters. Although the `redirect_uri` validation typically ensures that it matches the `client_id`… | |
| Modificada | Media (4.8) | 0.34% | — | Davidlingren Media Library Assistant | 17/10/2023 | 17/6/2026 | Auth. (author+) Stored Cross-Site Scripting (XSS) vulnerability in David Lingren Media Library Assistant plugin <= 3.11 versions. | |
| Modificada | Alta (8.8) | 0.21% | — | Rayhan1 AI Content Writing Assistant | 12/10/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ReCorp AI Content Writing Assistant (Content Writer, GPT 3 & 4, ChatGPT, Image Generator) All in One plugin <= 1.1.5 versions. | |
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access, via dtb pages of the platform portal. This is also known as… | |
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Platform V10 R1 before Hotfix V10 R1.42.2 and 4000 and Manager Platform V10 R1 before Hotfix V10 R1.42.2 allow command injection by an authenticated attacker into the platform operating system, leading to administrative access via the webservice. This is also known as OSFOURK-24120. |