Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

512 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (3.3)0.20%—Nvidia Cuda Toolkit3/10/202417/6/2026
NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause a NULL pointer dereference by running nvdisasm on a malformed ELF file. A successful exploit of this vulnerability might lead to a limited denial of service.
AnalizadaBaja (3.3)0.20%—Nvidia Cuda Toolkit3/10/202417/6/2026
NVIDIA CUDA Toolkit for Windows and Linux contains a vulnerability in the nvdisam command line tool, where a user can cause nvdisasm to read freed memory by running it on a malformed ELF file. A successful exploit of this vulnerability might lead to a limited denial of service.
AnalizadaBaja (3.3)0.21%—Nvidia Cuda Toolkit3/10/202417/6/2026
NVIDIA CUDA toolkit for Windows and Linux contains a vulnerability in the nvdisasm command line tool where an attacker may cause an improper validation in input issue by tricking the user into running nvdisasm on a malicious ELF file. A successful exploit of this vulnerability may lead to denial of service.
AnalizadaBaja (3.4)0.25%—Nvidia Container ToolkitNvidia GPU Operator26/9/202417/6/2026
NVIDIA Container Toolkit 1.16.1 or earlier contains a vulnerability in the default mode of operation allowing a specially crafted container image to create empty files on the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability may lead to data tampering.
AnalizadaAlta (8.3)41%💥 ExploitNvidia Container ToolkitNvidia GPU Operator26/9/202417/6/2026
NVIDIA Container Toolkit 1.16.1 or earlier contains a Time-of-check Time-of-Use (TOCTOU) vulnerability when used with default configuration where a specifically crafted container image may gain access to the host file system. This does not impact use cases where CDI is used. A successful exploit of this vulnerability…
AnalizadaMedia (6.1)0.39%—Madfishdigital Bulk Noindex & Nofollow Toolkit26/9/202417/6/2026
The Bulk NoIndex & NoFollow Toolkit plugin for WordPress is vulnerable to Reflected Cross-Site Scripting due to the use of remove_query_arg without appropriate escaping on the URL in all versions up to, and including, 2.15. This makes it possible for unauthenticated attackers to inject arbitrary web scripts in pages…
ModificadaAlta (7.5)3.2%💥 ExploitGithub Actions/artifactGithub Actions Toolkit2/9/202417/6/2026
actions/artifact is the GitHub ToolKit for developing GitHub Actions. Versions of `actions/artifact` on the 2.x branch before 2.1.2 are vulnerable to arbitrary file write when using `downloadArtifactInternal`, `downloadArtifactPublic`, or `streamExtractExternal` for extracting a specifically crafted artifact that…
AnalizadaMedia (4.4)0.20%—Nvidia Cuda Toolkit31/8/202417/6/2026
NVIDIA CUDA Toolkit contains a vulnerability in command 'cuobjdump' where a user may cause a crash or produce incorrect output by passing a malformed ELF file. A successful exploit of this vulnerability may lead to a limited denial of service or data tampering.
AnalizadaAlta (7.8)0.23%—Nvidia Cuda Toolkit31/8/202417/6/2026
NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause an out-of-bound write by passing in a malformed ELF file. A successful exploit of this vulnerability may lead to code execution or denial of service.
AnalizadaBaja (3.3)0.20%—Nvidia Cuda Toolkit31/8/202417/6/2026
NVIDIA CUDA Toolkit contains a vulnerability in command `cuobjdump` where a user may cause a crash by passing in a malformed ELF file. A successful exploit of this vulnerability may cause an out of bounds read in the unprivileged process memory which could lead to a limited denial of service.
AnalizadaMedia (5.3)0.32%—Hyperview Geoportal Toolkit28/8/202417/6/2026
HyperView Geoportal Toolkit in versions lower than 8.5.0 is vulnerable to Reflected Cross-Site Scripting (XSS). An unauthenticated attacker might trick somebody into using a crafted URL, which will cause a script to be run in user's browser.
AnalizadaMedia (5.3)0.35%—Hyperview Geoportal Toolkit28/8/202417/6/2026
HyperView Geoportal Toolkit in versions lower than 8.5.0 does not restrict cross-domain requests when fetching remote content pointed by one of GET request parameters. An unauthenticated remote attacker can prepare links, which upon opening will load scripts from a remote location controlled by the attacker and…
AnalizadaMedia (5.4)0.14%—Intel Oneapi Base ToolkitIntel Vtune Profiler14/8/202417/6/2026
Uncontrolled search path in some Intel(R) VTune(TM) Profiler software before versions 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.14%—Intel Integrated Performance PrimitivesIntel Oneapi Base Toolkit14/8/202417/6/2026
Uncontrolled search path in some Intel(R) IPP software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.14%—Intel MPI LibraryIntel Oneapi HPC Toolkit14/8/202417/6/2026
Uncontrolled search path for some Intel(R) MPI Library software before version 2021.12 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.14%—Intel Oneapi HPC ToolkitIntel Trace Analyzer AND Collector14/8/202417/6/2026
Uncontrolled search path for some Intel(R) Trace Analyzer and Collector software before version 2022.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.12%—Intel AdvisorIntel Oneapi Base Toolkit14/8/202417/6/2026
Incorrect default permissions for some Intel(R) Advisor software before version 2024.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.8)0.13%—Intel Distribution FOR GDBIntel Oneapi Base Toolkit14/8/202417/6/2026
Improper buffer restrictions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaBaja (1)0.13%—Intel Distribution FOR GDBIntel Oneapi Base Toolkit14/8/202417/6/2026
Improper input validation for some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable denial of service via local access.
AnalizadaMedia (5.4)0.13%—Intel Distribution FOR GDBIntel Oneapi Base Toolkit14/8/202417/6/2026
Incorrect default permissions in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.15%—Intel Distribution FOR GDBIntel Oneapi Base Toolkit14/8/202417/6/2026
Uncontrolled search path in some Intel(R) Distribution for GDB software before version 2024.0.1 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaMedia (5.4)0.15%—Intel Integrated Performance Primitives CryptographyIntel Oneapi Base Toolkit14/8/202417/6/2026
Uncontrolled search path for some Intel(R) IPP Cryptography software before version 2021.11 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.3)0.59%—Servit Affiliate-toolkitAI12/8/202417/6/2026
The affiliate-toolkit – WordPress Affiliate Plugin plugin for WordPress is vulnerable to Full Path Disclosure in all versions up to, and including, 3.5.5. This is due display_errors being set to true . This makes it possible for unauthenticated attackers to retrieve the full path of the web application, which can be…
AnalizadaMedia (5.5)0.24%—Nvidia Cuda Toolkit8/8/202417/6/2026
NVIDIA CUDA Toolkit for all platforms contains a vulnerability in nvdisasm, where an attacker can cause an out-of-bounds read issue by deceiving a user into reading a malformed ELF file. A successful exploit of this vulnerability might lead to denial of service.
AplazadaAlta (7.1)0.27%—Uncannyowl Uncanny Toolkit PRO FOR LearndashAI22/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Uncanny Owl Uncanny Toolkit Pro for LearnDash allows Reflected XSS.This issue affects Uncanny Toolkit Pro for LearnDash: from n/a before 4.1.4.1.
Orbitaley — Vulnerabilidades