Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.1, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.42.1, and 4000 Manager V10 R0 allow Authenticated Command Injection via AShbr. This is also known as OSFOURK-24039. | |
| Modificada | Alta (7.5) | 0.47% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 9/10/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.34.7, 4000 Assistant V10 R1.42.0, 4000 Assistant V10 R0, 4000 Manager V10 R1 before V10 R1.34.7, 4000 Manager V10 R1.42.0, and 4000 Manager V10 R0 expose sensitive information that may allow lateral movement to the backup system via AShbr. This is also known as… | |
| Modificada | Media (5.4) | 0.26% | — | Samsung Assistant | 4/10/2023 | 17/6/2026 | Improper authorization in PushMsgReceiver of Samsung Assistant prior to version 8.7.00.1 allows attacker to execute javascript interface. To trigger this vulnerability, user interaction is required. | |
| Modificada | Baja (3.3) | 0.14% | — | Samsung Sassistant | 4/10/2023 | 17/6/2026 | Improper Preservation of Permissions vulnerability in SAssistant prior to version 8.7 allows local attackers to access backup data in SAssistant. | |
| Modificada | Media (6.5) | 0.84% | — | Gladysassistant Gladys Assistant | 25/9/2023 | 17/6/2026 | A path traversal in Gladys Assistant v4.26.1 and below allows authenticated attackers to extract sensitive files in the host machine by exploiting a non-sanitized user input. | |
| Modificada | Media (5.4) | 0.55% | — | Davidlingren Media Library Assistant | 22/9/2023 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'mla_gallery' shortcode in versions up to, and including, 3.10 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with… | |
| Modificada | Alta (7.4) | 0.24% | — | Mimsoftware AssistantMimsoftware Client | 19/9/2023 | 17/6/2026 | Improper Restriction of XML External Entity Reference vulnerability in MIM Assistant and Client DICOM RTst Loading modules allows XML Entity Linking / XML External Entities Blowup. In order to take advantage of this vulnerability, an attacker must craft a malicious XML document, embed this document into specific 3rd… | |
| Modificada | Crítica (9.8) | 2.0% | — | Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+20 | 13/9/2023 | 17/6/2026 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | |
| Modificada | Crítica (9.8) | 86% | 💥 Exploit | Davidlingren Media Library Assistant | 6/9/2023 | 17/6/2026 | The Media Library Assistant plugin for WordPress is vulnerable to Local File Inclusion and Remote Code Execution in versions up to, and including, 3.09. This is due to insufficient controls on file paths being supplied to the 'mla_stream_file' parameter from the ~/includes/mla-stream-image.php file, where images are… | |
| Modificada | Alta (7.5) | 1.6% | — | LG LED Assistant | 4/9/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/thumbnail endpoint. The issue results from the lack of proper validation of a user-supplied… | |
| Modificada | Alta (7.5) | 1.6% | — | LG LED Assistant | 4/9/2023 | 17/6/2026 | This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from the lack of proper validation of a… | |
| Modificada | Crítica (9.8) | 2.5% | — | LG LED Assistant | 4/9/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from the lack of proper validation of a… | |
| Modificada | Crítica (9.8) | 2.5% | — | LG LED Assistant | 4/9/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of proper validation of a user-supplied… | |
| Modificada | Alta (8.1) | 0.47% | — | SAP Contributor License Agreement Assistant | 15/8/2023 | 17/6/2026 | A missing authorization check allows an arbitrary authenticated user to perform certain operations through the API of CLA-assistant by executing specific additional steps. This allows an arbitrary authenticated user to read CLA information including information of the persons who signed them as well as custom fields… | |
| Modificada | Crítica (9.6) | 0.57% | — | Intel Driver & Support Assistant | 11/8/2023 | 17/6/2026 | Cross-site scripting (XSS) for the Intel(R) DSA software before version 23.1.9 may allow unauthenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Media (6.1) | 0.36% | — | Davidlingren Media Library Assistant | 5/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in submodule of David Lingren Media Library Assistant plugin <= 3.0.7 versions. | |
| Modificada | Media (4.8) | 0.44% | — | Wpindeed Debug Assistant | 16/6/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in WPIndeed Debug Assistant plugin <= 1.4 versions. | |
| Modificada | Crítica (9.8) | 0.89% | — | HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware | 12/6/2023 | 17/6/2026 | Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23557. | |
| Modificada | Crítica (9.8) | 1.3% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow remote code execution by unauthenticated users, aka OSFOURK-24033. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-23556. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8 and Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8 allow command injection by authenticated users, aka OSFOURK-23554. | |
| Modificada | Alta (8.8) | 1.6% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 12/6/2023 | 17/6/2026 | Atos Unify OpenScape 4000 Assistant V10 R1 before V10 R1.42.0 and V10 R1.34.8, Assistant V10 R0, Manager V10 R1 before V10 R1.42.0 and V10 R1.34.8, and Manager V10 R0 allow command injection by authenticated users, aka OSFOURK-24036. | |
| Modificada | Alta (7.1) | 0.31% | — | Ubuntukylin Youker-assistant | 5/6/2023 | 17/6/2026 | A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function delete_file in the library dbus.SystemBus of the component Arbitrary File Handler. The manipulation leads to improper access controls. It is possible to launch the attack on the… | |
| Modificada | Alta (7.8) | 0.68% | — | Ubuntukylin Youker-assistant | 5/6/2023 | 17/6/2026 | A vulnerability classified as critical has been found in KylinSoft youker-assistant on KylinOS. Affected is the function restore_all_sound_file. The manipulation leads to path traversal: '../filedir'. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to version… |