Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
808 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.67% | — | Progress Telerik Document Processing Libraries | 12/2/2025 | 17/6/2026 | In Progress® Telerik® Document Processing Libraries, versions prior to 2025 Q1 (2025.1.205), unzipping an archive can lead to arbitrary file system access. | |
| Aplazada | Crítica (9.8) | 0.68% | — | Safety Production Process Management SystemAI | 29/1/2025 | 17/6/2026 | Password Vulnerability in Safety production process management system v1.0 allows a remote attacker to escalate privileges, execute arbitrary code and obtain sensitive information via the password and account number parameters. | |
| Analizada | Media (5.4) | 0.21% | — | IBM Robotic Process Automation FOR Cloud PAK | 22/1/2025 | 17/6/2026 | IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure… | |
| Analizada | Media (6.5) | 0.33% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 18/1/2025 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side… | |
| Analizada | Media (6.7) | 0.15% | — | IBM Robotic Process Automation | 18/1/2025 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A… | |
| Aplazada | Media (6.5) | 0.47% | — | Processmaker Pm4core-dockerAI | 15/1/2025 | 17/6/2026 | An arbitrary file upload vulnerability in the UI login page logo upload function of Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary code via uploading a crafted PHP or HTML file. | |
| Aplazada | Media (4.8) | 0.35% | 💥 PoC | Processmaker Pm4core-dockerAI | 15/1/2025 | 17/6/2026 | A cross-site scripting (XSS) vulnerability in Process Maker pm4core-docker 4.1.21-RC7 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Name parameter. | |
| Analizada | Media (5.9) | 0.28% | — | IBM Robotic Process Automation | 12/1/2025 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks. | |
| Analizada | Media (4.6) | 0.24% | — | IBM Robotic Process Automation | 19/12/2024 | 17/6/2026 | IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials. | |
| Aplazada | Media (5.1) | 0.29% | — | Cpci85 Central Processing CommunicationAI | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an unencrypted SPI bus. This could allow an attacker with physical access to the SPI bus to observe the password used for the secure element… | |
| Aplazada | Crítica (9.8) | 0.89% | — | Serviceware ProcessesAI | 9/12/2024 | 17/6/2026 | Serviceware Processes 6.0 through 7.3 before 7.4 allows attackers without valid authentication to send a specially crafted HTTP request to a service endpoint resulting in remote code execution. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Fastconnect 6800 FirmwareQualcomm Fastconnect 6900 Firmware+87 | 2/12/2024 | 17/6/2026 | Memory corruption while processing API calls to NPU with invalid input. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm 315 5G IOT Modem FirmwareQualcomm 9205 LTE Modem FirmwareQualcomm 9206 LTE Modem FirmwareQualcomm 9207 LTE Modem Firmware+325 | 2/12/2024 | 17/6/2026 | Memory corruption when allocating and accessing an entry in an SMEM partition continuously. | |
| Aplazada | Baja (2) | 0.17% | — | Intel Xeon Processor Family E-coreAI | 13/11/2024 | 17/6/2026 | Protection mechanism failure in the SPP for some Intel(R) Xeon(R) processor family (E-Core) may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7.3) | 0.18% | — | Intel ProcessorsAI | 13/11/2024 | 17/6/2026 | Protection mechanism failure in the SPP for some Intel(R) Processors may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.8) | 0.18% | — | Intel Xeon ProcessorsAIIntel Uefi FirmwareAI | 13/11/2024 | 17/6/2026 | Insufficient control flow management in UEFI firmware for some Intel(R) Xeon(R) Processors may allow an authenticated user to enable denial of service via local access. | |
| Aplazada | Alta (8.5) | 0.17% | — | Intel ActmAIIntel ProcessorsAI | 13/11/2024 | 17/6/2026 | Exposure of resource to wrong sphere in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.8) | 0.26% | — | Intel Xeon ProcessorAIIntel SGXAI | 13/11/2024 | 17/6/2026 | Improper conditions check in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.5) | 0.13% | — | Intel ActmAIIntel ProcessorsAI | 13/11/2024 | 17/6/2026 | Time-of-check Time-of-use Race Condition in some Intel(R) processors with Intel(R) ACTM may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.5) | 0.22% | — | Intel Xeon ProcessorAIIntel SGXAI | 13/11/2024 | 17/6/2026 | Incorrect default permissions in some Intel(R) Xeon(R) processor memory controller configurations when using Intel(R) SGX may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6.5) | 0.43% | — | Progress Telerik Document Processing Libraries | 13/11/2024 | 17/6/2026 | In Progress Telerik Document Processing Libraries, versions prior to 2024 Q4 (2024.4.1106), importing a document with unsupported features can lead to excessive processing, leading to excessive use of computing resources leaving the application process unavailable. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8835 FirmwareQualcomm Wsa8830 FirmwareQualcomm Wsa8815 FirmwareQualcomm Wsa8810 Firmware+202 | 4/11/2024 | 17/6/2026 | Memory corruption while processing GPU page table switch. | |
| Analizada | Alta (7.8) | 0.10% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+264 | 4/11/2024 | 17/6/2026 | Memory corruption while processing voice packet with arbitrary data received from ADSP. | |
| Analizada | Media (6.5) | 0.25% | — | Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+90 | 4/11/2024 | 17/6/2026 | Transient DOS as modem reset occurs when an unexpected MAC RAR (with invalid PDU length) is seen at UE. | |
| Analizada | Alta (8.1) | 0.43% | — | Oracle Process Manufacturing Product Development | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise… |