Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

3834 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.12%—Intel Workload Sevices Framework11/8/20262/10/2026
Protection mechanism failure for some Intel(R) Workload Services Framework software within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur…
AnalizadaMedia (6.8)0.10%—Intel Vllm Hardware11/8/202624/9/2026
Improper input validation for some vLLM Hardware Plugin for Intel(R) Gaudi(R) software before version 0.16.0 within Ring 3: User Applications may allow a denial of service. Authorized adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AnalizadaMedia (5.4)0.12%—Intel Oneccl Bindings FOR Pytorch11/8/20261/10/2026
Protection mechanism failure for some Intel(R) oneCCL Bindings for PyTorch before version v2.8.0 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…
AnalizadaMedia (5.8)0.07%—Intel Neural Processing Unit Driver11/8/202628/9/2026
Time-of-check time-of-use race condition for the Intel(R) NPU Driver for Windows for all versions within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially…
AnalizadaMedia (5.4)0.16%—Intel Neural Compressor11/8/202628/9/2026
Protection mechanism failure for some Intel(R) Neural Compressor software before version v3.6 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may…
AnalizadaMedia (6.9)0.13%—Intel Neural Processing Unit Driver11/8/202628/9/2026
Out-of-bounds read for the Intel(R) NPU Driver for all versions within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack…
En análisisMedia (4.3)0.13%—Intel Software Guard Extensions Data Center Attestation PrimitivesAI11/8/202629/9/2026
Omission of security-relevant information for some Intel(R) Software Guard Extensions Data Center Attestation Primitives within Ring 0: Kernel may allow a denial of service. Authorized adversary with a privileged user combined with a high complexity attack may enable data alteration. This result may potentially occur…
Pendiente de análisisMedia (4.5)0.10%—Intel ProcessorsAI11/8/202629/9/2026
Improper handling of values for some Intel(R) Processors within Ring 0: Kernel, Hypervisor and Bare Metal OS may allow an escalation of privilege. Authorized adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur via local access…
Pendiente de análisisMedia (4.3)0.09%—Intel Xeon 6 Scalable ProcessorsAIIntel TDXAI11/8/202629/9/2026
Insufficient granularity of access control in some subsystem for some Intel(R) Xeon(R) 6 Scalable processors with Intel(R) TDX may allow an information disclosure. Authorized adversary with an authenticated user combined with a high complexity attack may enable data exposure. This result may potentially occur via…
AnalizadaAlta (7)0.10%—Intel Xeon 6337p FirmwareIntel Xeon 6349p FirmwareIntel Xeon 6353p FirmwareIntel Xeon 6357p Firmware+6911/8/202629/9/2026
Improper handling of overlap between protected memory ranges for some Intel(R) Xeon(R) 6 processors when using Intel(R) TDX within SMM may allow an escalation of privilege. SMM adversary with a privileged user combined with a high complexity attack may enable escalation of privilege. This result may potentially occur…
Pendiente de análisisMedia (5.7)0.07%—Intel Trust Domain ExtensionsAI11/8/202629/9/2026
Insufficient verification of data authenticity for some Intel(R) Trust Domain Extensions (Intel(R) TDX) within Ring 0: Hypervisor may allow an information disclosure. A system software adversary with a privileged user access combined with a high complexity attack may enable data exposure. This result may potentially…
AplazadaMedia (6.5)0.52%—Intelliants Subrion CMSAI11/8/202628/8/2026
A path traversal vulnerability in Intelliants Subrion CMS through 4.2.1 allows authenticated administrators to delete arbitrary files on the server via the admin panel file deletion endpoint. The endpoint passes a user-supplied file path directly to unlink() without sanitization or path canonicalization. An…
Pendiente de análisisMedia (4.3)0.30%—SAP Businessobjects Business Intelligence PlatformAI11/8/202626/8/2026
SAP BusinessObjects Business Intelligence Platform (Admin Tools) does not perform sufficient authorization check on certain administrative functionality. An attacker authenticated as a non-administrative user could bypass this restriction to gain limited information about affected functionality. This results in a low…
Pendiente de análisisMedia (6.3)0.27%—SAP Social IntelligenceAI11/8/202626/8/2026
Due to an SQL Injection vulnerability in SAP Social intelligence, an authenticated attacker could directly inject an SQL DDL (Data Definition Language) string into the underlying database without further authorization. Successful exploitation could allow the attacker to make malicious changes to the database…
Pendiente de análisisAlta (7.9)0.20%—SAP Businessobjects Business Intelligence PlatformAI11/8/202626/8/2026
SAP BusinessObjects Business Intelligence Platform stores certain sensitive credentials associated with user objects using a hard-coded cryptographic key. An attacker with high privileges and local access to the server could retrieve these objects and decrypt the stored credentials. Successful exploitation could allow…
Pendiente de análisisMedia (6.5)0.39%—SAP Businessobjects Business Intelligence PlatformAISAP WEB IntelligenceAI11/8/202626/8/2026
SAP BusinessObjects Business Intelligence Platform (Web Intelligence) allows a low-privileged attacker to upload a specially crafted spreadsheet file containing malicious external references. When the file is processed as a data source, the affected component resolves these references and exposes the contents of…
Pendiente de análisisMedia (4.3)0.28%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
SAP Manufacturing Integration and Intelligence (MII) does not perform necessary authorization check on certain application function, allowing a low-privileged authenticated attacker to access information that should be restricted to privileged users. Successful exploitation could allow the attacker to access the users…
Pendiente de análisisAlta (7.3)0.38%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated remote attacker could access scheduling-related application functions without proper authorization validation. Successful exploitation could allow the attacker to retrieve, create, modify, or delete…
Pendiente de análisisAlta (7.3)0.32%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
Due to a Missing Authorization Check vulnerability in SAP Manufacturing Integration and Intelligence, an unauthenticated attacker could send crafted requests to the Cost Servlet using specific parameter values. If processed by the application, these requests enable access to backend operations. Successful exploitation…
Pendiente de análisisAlta (7.6)0.40%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
SAP Manufacturing Integration and Intelligence allows a privileged attacker to exploit insufficient file path validation in certain functions using specially crafted input. Exploitation also requires a legitimate user to subsequently access the attacker-influenced content and depends on conditions outside the…
Pendiente de análisisCrítica (9.1)0.77%—SAP Manufacturing Integration AND IntelligenceAI11/8/202626/8/2026
SAP Manufacturing Integration and Intelligence (MII) allows an attacker with high privileges to submit specially crafted input to certain affected functionality, which is processed without sufficient validation. Successful exploitation could allow the attacker to execute arbitrary commands on the underlying operating…
AplazadaMedia (6.9)0.49%—FlowintelAI3/8/202626/8/2026
FlowIntel is affected by a stored cross-site scripting vulnerability through multiple user-controlled or administrator-controlled fields. Persisted values—including case titles, ticket identifiers, recurring-case information, user profile attributes, organisation names, and role names—were rendered inside DOM elements…
AplazadaAlta (7.1)0.24%—Streamsoft Business IntelligenceAI29/7/202630/7/2026
Streamsoft Business Intelligence (BI) stores users' passwords in plaintext form in the database This issue was fixed in version 6.8.0.0, users were also requested to change their password on the first login.
AnalizadaCrítica (9.8)0.48%—Jetbrains Intellij Idea23/7/202628/7/2026
In JetBrains IntelliJ IDEA before 2026.2 arbitrary code injection was possible via UI Designer form files
AnalizadaAlta (8.6)0.39%—Jetbrains Intellij Idea23/7/202628/7/2026
In JetBrains IntelliJ IDEA before 2026.2 unauthorized file access was possible in a Remote Development session