Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
252 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.25% | — | Lenovo System Interface Foundation | 15/9/2020 | 17/6/2026 | A denial of service vulnerability was reported in the Lenovo Vantage component called Lenovo System Interface Foundation prior to version 1.1.19.5 that could allow configuration files to be written to non-standard locations. | |
| Modificada | Alta (7.8) | 0.28% | — | Intel Mailbox Interface Driver | 13/8/2020 | 17/6/2026 | Improper permissions in the installer for the Intel(R) Mailbox Interface driver, all versions, may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.38% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 24/7/2020 | 17/6/2026 | In OSIsoft PI System multiple products and versions, a local attacker can modify a search path and plant a binary to exploit the affected PI System software to take control of the local computer at Windows system privilege level, resulting in unauthorized information disclosure, deletion, or modification. | |
| Modificada | Alta (7.8) | 0.22% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 24/7/2020 | 17/6/2026 | In OSIsoft PI System multiple products and versions, a local attacker can plant a binary and bypass a code integrity check for loading PI System libraries. This exploitation can target another local user of PI System software on the computer to escalate privilege and result in unauthorized information disclosure,… | |
| Modificada | Alta (7.8) | 0.27% | — | Osisoft PI APIOsisoft PI Buffer SubsystemOsisoft PI ConnectorOsisoft PI Connector Relay+5 | 24/7/2020 | 17/6/2026 | In OSIsoft PI System multiple products and versions, a local attacker can exploit incorrect permissions set by affected PI System software. This exploitation can result in unauthorized information disclosure, deletion, or modification if the local computer also processes PI System data from other users, such as from a… | |
| Modificada | Crítica (9.8) | 1.6% | — | Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+1 | 14/7/2020 | 17/6/2026 | An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a least privilege violation. | |
| Modificada | Alta (8.8) | 1.3% | — | Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+1 | 14/7/2020 | 17/6/2026 | An issue was discovered on Rittal PDU-3C002DEC through 5.15.70 and CMCIII-PU-9333E0FB through 3.15.70 devices. There are insecure permissions. | |
| Modificada | Alta (8.8) | 2.5% | — | Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+1 | 14/7/2020 | 17/6/2026 | An issue was discovered on Rittal PDU-3C002DEC through 5.15.40 and CMCIII-PU-9333E0FB through 3.15.70_4 devices. Attackers can execute code. | |
| Modificada | Media (6.2) | 0.53% | — | Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+1 | 14/7/2020 | 17/6/2026 | An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. Attackers can bypass the CLI menu. | |
| Modificada | Crítica (9.8) | 1.7% | — | Rittal Cmciii-pu-9333e0fb FirmwareRittal Pdu-3c002dec FirmwareRittal CMC III PU 7030.000 FirmwareRittal Lcp-cw Firmware+1 | 14/7/2020 | 17/6/2026 | An issue was discovered on Rittal PDU-3C002DEC through 5.17.10 and CMCIII-PU-9333E0FB through 3.17.10 devices. There is a Backdoor root account. | |
| Modificada | Media (6.5) | 0.82% | — | Icatchinc DVR Interface | 15/4/2020 | 17/6/2026 | The file management interface of iCatch DVR firmware before 20200103 contains broken access control which allows the attacker to remotely manipulate arbitrary file. | |
| Modificada | Media (5.5) | 0.35% | — | Lenovo System Interface Foundation | 14/4/2020 | 17/6/2026 | A vulnerability was reported in LenovoAppScenarioPluginSystem for Lenovo System Interface Foundation prior to version 1.2.184.31 that could allow unsigned DLL files to be executed. | |
| Modificada | Alta (7.8) | 0.41% | — | Lenovo System Interface Foundation | 14/4/2020 | 17/6/2026 | A privilege escalation vulnerability was reported in Lenovo System Interface Foundation prior to version 1.1.19.3 that could allow an authenticated user to execute code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.42% | — | Lenovo System Interface Foundation | 14/4/2020 | 17/6/2026 | A privilege escalation vulnerability was reported in the LenovoSystemUpdatePlugin for Lenovo System Interface Foundation prior to version that could allow an authenticated user to execute code with elevated privileges. | |
| Modificada | Media (6.5) | 2.6% | 💥 PoC | Tesla Model 3 WEB Interface | 20/3/2020 | 17/6/2026 | The driving interface of Tesla Model 3 vehicles in any release before 2020.4.10 allows Denial of Service to occur due to improper process separation, which allows attackers to disable the speedometer, web browser, climate controls, turn signal visual and sounds, navigation, autopilot notifications, along with other… | |
| Modificada | Media (4.3) | 4.4% | — | Supermicro Intelligent Platform Management Interface | 23/1/2020 | 17/6/2026 | Directory traversal vulnerability in url_redirect.cgi in Supermicro IPMI before SMT_X9_315 allows authenticated attackers to read arbitrary files via the url_name parameter. | |
| Modificada | Alta (7.8) | 0.32% | — | Lenovo System Interface Foundation | 20/11/2019 | 17/6/2026 | A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an administrative user to load an unsigned DLL. | |
| Modificada | Alta (8.8) | 1.5% | — | Lenovo System Interface Foundation | 20/11/2019 | 17/6/2026 | A potential vulnerability was reported in Lenovo System Interface Foundation versions before v1.1.18.3 that could allow an authenticated user to execute code as another user. | |
| Modificada | Alta (7.8) | 2.1% | — | Pivotal Cloud Foundry Command Line InterfacePivotal Cloud Foundry Command Line Interface ReleasePivotal Cloud Foundry DeploymentPivotal Cloud Foundry Deployment Concourse Tasks+51 | 5/8/2019 | 17/6/2026 | CF CLI version prior to v6.45.0 (bosh release version 1.16.0) writes the client id and secret to its config file when the user authenticates with --client-credentials flag. A local authenticated malicious user with access to the CF CLI config file can act as that client, who is the owner of the leaked credentials. | |
| Modificada | Alta (7.5) | 1.8% | — | Dell Avamar Data Migration Enabler WEB Interface | 19/6/2019 | 17/6/2026 | Dell EMC Avamar ADMe Web Interface 1.0.50 and 1.0.51 are affected by an LFI vulnerability which may allow a malicious user to download arbitrary files from the affected system by sending a specially crafted request to the Web Interface application. | |
| Modificada | Media (6.7) | 0.61% | — | Cisco ASA 5500 FirmwareCisco Firepower 2100 FirmwareCisco Firepower 4000 FirmwareCisco Firepower 9000 Firmware+23 | 13/5/2019 | 17/6/2026 | A vulnerability in the logic that handles access control to one of the hardware components in Cisco's proprietary Secure Boot implementation could allow an authenticated, local attacker to write a modified firmware image to the component. This vulnerability affects multiple Cisco products that support hardware-based… | |
| Modificada | Alta (8.8) | 1.3% | — | Cloudfoundry Command Line Interface | 7/3/2019 | 17/6/2026 | Cloud Foundry CLI, versions prior to v6.43.0, improperly exposes passwords when verbose/trace/debugging is turned on. A local unauthenticated or remote authenticated malicious user with access to logs may gain part or all of a users password. | |
| Modificada | Alta (7.8) | 1.3% | — | Panasonic System Interface Device 0021Panasonic System Interface Device 0040 | 9/1/2019 | 17/6/2026 | An unquoted search path vulnerability in some pre-installed applications on Panasonic PC run on Windows 7 (32bit), Windows 7 (64bit), Windows 8 (64bit), Windows 8.1 (64bit), Windows 10 (64bit) delivered in or later than October 2009 allow local users to gain privileges via a Trojan horse executable file and execute… | |
| Modificada | Crítica (9.8) | 1.4% | — | Npci Bharat Interface FOR Money (bhim) | 24/8/2018 | 17/6/2026 | The National Payments Corporation of India BHIM application 1.3 for Android relies on three hardcoded strings (AK-NPCIMB, IM-NPCIBM, and VK-NPCIBM) for SMS validation, which makes it easier for attackers to bypass authentication. | |
| Modificada | Crítica (9.8) | 1.8% | — | Npci Bharat Interface FOR Money (bhim) | 24/8/2018 | 17/6/2026 | The National Payments Corporation of India BHIM application 1.3 for Android uses a custom keypad for which the input element is available to the Accessibility service, which makes it easier for attackers to bypass authentication. |