Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Keyfactor Primekey Ejbca | 17/11/2022 | 17/6/2026 | A stored XSS vulnerability was discovered in adminweb/ra/viewendentity.jsp in PrimeKey EJBCA through 7.9.0.2. A low-privilege user can store JavaScript in order to exploit a higher-privilege user. | |
| Modificada | Alta (7.5) | 0.64% | — | Intel Quartus Prime | 11/11/2022 | 17/6/2026 | XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Quartus Prime | 11/11/2022 | 17/6/2026 | Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 1.0% | — | Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware | 23/9/2022 | 17/6/2026 | This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper session management in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by… | |
| Modificada | Alta (7.5) | 1.5% | — | Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware | 23/9/2022 | 17/6/2026 | This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to insecure design in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability by sending a… | |
| Modificada | Crítica (9.8) | 2.2% | — | Tacitine En6200-prime Quad-35 FirmwareTacitine En6200-prime Quad-100 Firmware | 23/9/2022 | 17/6/2026 | This vulnerability exists in Tacitine Firewall, all versions of EN6200-PRIME QUAD-35 and EN6200-PRIME QUAD-100 between 19.1.1 to 22.20.1 (inclusive), due to improper control of code generation in the Tacitine Firewall web-based management interface. An unauthenticated remote attacker could exploit this vulnerability… | |
| Modificada | Crítica (9.8) | 0.52% | — | Primekey Ejbca | 14/9/2022 | 17/6/2026 | An issue was discovered in Keyfactor PrimeKey EJBCA before 7.9.0, related to possible inconsistencies in DNS identifiers submitted in an ACME order and the corresponding CSR submitted during finalization. During the ACME enrollment process, an order is submitted containing an identifier for one or multiple dnsNames.… | |
| Modificada | Crítica (9.8) | 4.1% | — | Mersenne Prime95 | 16/5/2022 | 17/6/2026 | Prime95 30.7 build 9 suffers from a Buffer Overflow vulnerability that could lead to Remote Code Execution. | |
| Modificada | Alta (7.5) | 2.7% | 💥 PoC | Primeur Spazio | 11/5/2022 | 17/6/2026 | The HTTP Server in PRIMEUR SPAZIO 2.5.1.954 (File Transfer) allows an unauthenticated attacker to obtain sensitive data (related to the content of transferred files) via a crafted HTTP request. | |
| Modificada | Media (4.8) | 0.65% | — | Primekey Signserver | 21/3/2022 | 17/6/2026 | An XSS was identified in the Admin Web interface of PrimeKey SignServer before 5.8.1. JavaScript code must be used in a worker name before a Generate CSR request. Only an administrator can update a worker name. | |
| Modificada | Crítica (9.1) | 0.97% | — | Rambus Safezone Basic Crypto ModuleFujifilm Apeos C7070 FirmwareFujifilm Apeos C6570 FirmwareFujifilm Apeos C5570 Firmware+88 | 14/3/2022 | 17/6/2026 | The Rambus SafeZone Basic Crypto Module before 10.4.0, as used in certain Fujifilm (formerly Fuji Xerox) devices before 2022-03-01, Canon imagePROGRAF and imageRUNNER devices through 2022-03-14, and potentially many other devices, generates RSA keys that can be broken with Fermat's factorization method. This allows… | |
| Modificada | Media (6.1) | 1.2% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 17/2/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability exists… | |
| Modificada | Media (6.5) | 1.1% | — | Cisco Prime Service Catalog | 10/2/2022 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Service Catalog could allow an authenticated, remote attacker to access sensitive information on an affected device. This vulnerability is due to improper enforcement of Administrator privilege levels for low-value sensitive data. An attacker with… | |
| Modificada | Alta (7.8) | 0.24% | — | Intel Quartus Prime | 9/2/2022 | 17/6/2026 | Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.5) | 1.1% | — | Intel Quartus Prime | 9/2/2022 | 17/6/2026 | Improper restriction of XML external entity reference in DSP Builder Pro for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Alta (7.8) | 0.22% | — | Intel Quartus Prime | 9/2/2022 | 17/6/2026 | Improper permissions for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.22% | — | Intel Quartus Prime | 9/2/2022 | 17/6/2026 | Improper permissions in the SafeNet Sentinel driver for Intel(R) Quartus(R) Prime Standard Edition before version 21.1 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.26% | — | Intel Quartus Prime | 9/2/2022 | 17/6/2026 | Improper access control in a third-party component of Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.26% | — | Intel Quartus Prime | 9/2/2022 | 17/6/2026 | Improper input validation in a third-party component for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa💥 Exploit | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (5.4) | 0.60% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 4/11/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Infrastructure (PI) and Cisco Evolved Programmable Network Manager (EPNM) could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the web-based management interface of an affected device.… | |
| Modificada | Media (4.8) | 0.59% | — | Cisco Prime Access Registrar | 4/11/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Access Registrar could allow an authenticated, remote attacker to perform a stored cross-site scripting attack on an affected system. This vulnerability exists because the web-based management interface does not sufficiently validate user-supplied… | |
| Modificada | Crítica (9.8) | 1.8% | — | HPE 3par OSHPE Primera 630 FirmwareHPE Primera 650 FirmwareHPE Primera 670 Firmware+2 | 11/10/2021 | 17/6/2026 | A potential security vulnerability has been identified in HPE 3PAR StoreServ, HPE Primera Storage and HPE Alletra 9000 Storage array firmware. An unauthenticated user could remotely exploit the low complexity issue to execute code as administrator. This vulnerability impacts completely the confidentiality, integrity,… | |
| Modificada | Media (5.5) | 0.22% | — | Cisco Evolved Programmable Network ManagerCisco Prime Infrastructure | 2/9/2021 | 17/6/2026 | A vulnerability in the CLI of Cisco Prime Infrastructure and Cisco Evolved Programmable Network (EPN) Manager could allow an authenticated, local attacker to access sensitive information stored on the underlying file system of an affected system. This vulnerability exists because sensitive information is not… | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Prime Collaboration Provisioning | 2/9/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Prime Collaboration Provisioning could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input by the web-based… |