Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.25%—Lenovo System Interface Foundation15/9/202017/6/2026
A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations.
ModificadaAlta (7.8)0.28%—Intel Mailbox Interface Driver13/8/202017/6/2026
Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.38%—Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+524/7/202017/6/2026
In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification.
ModificadaAlta (7.8)0.22%—Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+524/7/202017/6/2026
In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure,…
ModificadaAlta (7.8)0.27%—Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+524/7/202017/6/2026
In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a…
ModificadaCrítica (9.8)1.6%—Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+114/7/202017/6/2026
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation.
ModificadaAlta (8.8)1.3%—Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+114/7/202017/6/2026
An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices. There are insecure permissions.
ModificadaAlta (8.8)2.5%—Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+114/7/202017/6/2026
An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code.
ModificadaMedia (6.2)0.53%—Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+114/7/202017/6/2026
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. Attackers can bypass the CLI menu.
ModificadaCrítica (9.8)1.7%—Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+114/7/202017/6/2026
An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a Backdoor root account.
ModificadaMedia (6.5)0.82%—Icatchinc DVR Interface15/4/202017/6/2026
The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the attacker to remotely manipulate arbitrary file.
ModificadaMedia (5.5)0.35%—Lenovo System Interface Foundation14/4/202017/6/2026
A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed.
ModificadaAlta (7.8)0.41%—Lenovo System Interface Foundation14/4/202017/6/2026
A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated user to execute code with elevated privileges.
ModificadaAlta (7.8)0.42%—Lenovo System Interface Foundation14/4/202017/6/2026
A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could allow an authenticated user to execute code with elevated privileges.
ModificadaMedia (6.5)2.6%💥 PoCTesla Model 3 WEB Interface20/3/202017/6/2026
The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other…
ModificadaMedia (4.3)4.4%—Supermicro Intelligent Platform Management Interface23/1/202017/6/2026
Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter.
ModificadaAlta (7.8)0.32%—Lenovo System Interface Foundation20/11/201917/6/2026
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL.
ModificadaAlta (8.8)1.5%—Lenovo System Interface Foundation20/11/201917/6/2026
A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user.
ModificadaAlta (7.8)2.1%—Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+515/8/201917/6/2026
CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials.
ModificadaAlta (7.5)1.8%—Dell Avamar Data Migration Enabler WEB Interface19/6/201917/6/2026
Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to the Web Interface application.
ModificadaMedia (6.7)0.61%—Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+2313/5/201917/6/2026
A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based…
ModificadaAlta (8.8)1.3%—Cloudfoundry Command Line Interface7/3/201917/6/2026
Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password.
ModificadaAlta (7.8)1.3%—Panasonic System Interface Device 0021Panasonic System Interface Device 00409/1/201917/6/2026
An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windows 7 (64bit), Windows 8 (64bit), Windows 8.1 (64bit), Windows 10 (64bit) delivered in or later than October 2009 allow local users to gain privileges via a Trojan horse executable file and execute…
ModificadaCrítica (9.8)1.4%—Npci Bharat Interface FOR Money (bhim)24/8/201817/6/2026
The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication.
ModificadaCrítica (9.8)1.8%—Npci Bharat Interface FOR Money (bhim)24/8/201817/6/2026
The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes it easier for attackers to bypass authentication.
Orbitaley — Vulnerabilidades