Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (4.9) | 0.51% | — | Totalprocessing Nomupay Payment Processing GatewayAI | 23/5/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay Payment Processing Gateway totalprocessing-card-payments allows Path Traversal.This issue affects Nomupay Payment Processing Gateway: from n/a through <= 7.1.7. | |
| Aplazada | Media (5.7) | 0.19% | — | Intel Core Processors 10th GenerationAI | 13/5/2025 | 17/6/2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution for some Intel(R) Core™ processors (10th Generation) may allow an authenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Media (5.7) | 0.17% | — | Intel ProcessorsAI | 13/5/2025 | 17/6/2026 | Insufficient resource pool in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (6.8) | 0.17% | — | Intel ProcessorsAI | 13/5/2025 | 17/6/2026 | Uncaught exception in the core management mechanism for some Intel(R) Processors may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.3) | 0.15% | — | Intel Integrated Connectivity I O Interface CnviAIIntel Core Ultra ProcessorsAI | 13/5/2025 | 17/6/2026 | Improper locking in the Intel(R) Integrated Connectivity I/O interface (CNVi) for some Intel(R) Core™ Ultra Processors may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Aplazada | Alta (8.5) | 0.15% | — | Intel Xeon 6 Processor E-cores FirmwareAI | 13/5/2025 | 17/6/2026 | Insufficient control flow management in the Alias Checking Trusted Module for some Intel(R) Xeon(R) 6 processor E-Cores firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.7) | 0.14% | — | Intel Xeon 6 Processor With E-coresAIIntel Trust Domain ExtensionsAIIntel Software Guard ExtensionsAI | 13/5/2025 | 17/6/2026 | Improper restriction of software interfaces to hardware features for some Intel(R) Xeon(R) 6 processor with E-cores when using Intel(R) Trust Domain Extensions (Intel(R) TDX) or Intel(R) Software Guard Extensions (Intel(R) SGX) may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.7) | 0.27% | — | Intel ProcessorsAI | 13/5/2025 | 17/6/2026 | Exposure of sensitive information caused by shared microarchitectural predictor state that influences transient execution in the indirect branch predictors for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Media (5.7) | 0.41% | — | Intel ProcessorsAI | 13/5/2025 | 14/7/2026 | Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution for some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (7.1) | 0.29% | — | Totalprocessing Nomupay Payment Processing GatewayAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in totalprocessing Nomupay Payment Processing Gateway totalprocessing-card-payments allows Reflected XSS.This issue affects Nomupay Payment Processing Gateway: from n/a through <= 7.1.6. | |
| Analizada | Media (4.3) | 0.22% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 14/4/2025 | 17/6/2026 | IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. | |
| Aplazada | Media (6.5) | 0.48% | — | Totalprocessing Nomupay Payment Processing GatewayAI | 10/4/2025 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in totalprocessing Nomupay Payment Processing Gateway totalprocessing-card-payments allows Path Traversal.This issue affects Nomupay Payment Processing Gateway: from n/a through <= 7.1.5. | |
| Aplazada | Crítica (9.1) | 0.60% | 💥 PoC | Labcat Processing ProjectsAI | 10/4/2025 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in LABCAT Processing Projects processing-projects allows Upload a Web Shell to a Web Server.This issue affects Processing Projects: from n/a through <= 1.0.2. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8064au FirmwareQualcomm Aqt1000 Firmware+221 | 7/4/2025 | 17/6/2026 | Transient DOS while connecting STA to AP and initiating ADD TS request from AP to establish TSpec session. | |
| Analizada | Alta (7.5) | 0.26% | — | Qualcomm Sa9000p FirmwareQualcomm Sd626 FirmwareQualcomm Sd660 FirmwareQualcomm Sd670 Firmware+178 | 7/4/2025 | 17/6/2026 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request. | |
| Analizada | Alta (7.5) | 0.25% | — | Qualcomm Snapdragon 439 Mobile Platform FirmwareQualcomm Snapdragon 625 Mobile Platform FirmwareQualcomm Snapdragon 626 Mobile Platform FirmwareQualcomm Snapdragon 632 Mobile Platform Firmware+65 | 7/4/2025 | 17/6/2026 | Memory corruption occurs while connecting a STA to an AP and initiating an ADD TS request from the AP to establish a TSpec session. | |
| Analizada | Alta (8.2) | 0.26% | — | Qualcomm Apq8064au FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+142 | 7/4/2025 | 17/6/2026 | Information disclosure may occur during a video call if a device resets due to a non-conforming RTCP packet that doesn`t adhere to RFC standards. | |
| Analizada | Alta (7.8) | 0.11% | — | Qualcomm Csrb31024 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 FirmwareQualcomm Fastconnect 6800 Firmware+94 | 7/4/2025 | 17/6/2026 | Memory corruption while handling file descriptor during listener registration/de-registration. | |
| Aplazada | Media (6.5) | 0.22% | — | Labcat Processing ProjectsAI | 31/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in LABCAT Processing Projects processing-projects allows DOM-Based XSS.This issue affects Processing Projects: from n/a through <= 1.0.2. | |
| Aplazada | Media (4.7) | 0.17% | — | Intel ProcessorsAI | 14/2/2025 | 17/6/2026 | Unprotected alternative channel of return branch target prediction in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Aplazada | Media (5.7) | 0.24% | — | Intel ProcessorsAI | 12/2/2025 | 17/6/2026 | Improper handling of physical or environmental conditions in some Intel(R) Processors may allow an authenticated user to enable denial of service via local access. | |
| Aplazada | Media (6.8) | 0.25% | — | Intel ProcessorsAIIntel SGXAI | 12/2/2025 | 17/6/2026 | Improper access control in the EDECCSSA user leaf function for some Intel(R) Processors with Intel(R) SGX may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.6) | 0.24% | — | Intel ProcessorsAI | 12/2/2025 | 17/6/2026 | Improper Finite State Machines (FSMs) in Hardware Logic for some Intel(R) Processors may allow privileged user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.4) | 0.20% | — | Intel Video Processing LibraryAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path in some Intel(R) VPL software before version 2023.4.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.38% | — | Progress Telerik Document Processing Libraries | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), using .NET Standard 2.0, the contents of a file at an arbitrary path can be exported to RTF. |