Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
339 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.16% | — | Intel Endpoint Management Assistant | 10/5/2023 | 17/6/2026 | Improper authorization in the Intel(R) EMA software before version 1.9.0.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (5.5) | 0.16% | — | Intel Endpoint Management Assistant Configuration ToolIntel Manageability Commander | 10/5/2023 | 17/6/2026 | Improper authorization in Intel(R) EMA Configuration Tool before version 1.0.4 and Intel(R) MC before version 2.4 software may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 0.64% | — | Vegayazilim Mobile Assistant | 17/4/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Veragroup Mobile Assistant allows SQL Injection. This issue affects Mobile Assistant: before 21.S.2343. | |
| Modificada | Alta (7.8) | 1.5% | — | Kylinos Youker-assistant | 15/4/2023 | 17/6/2026 | A vulnerability classified as critical was found in KylinSoft youker-assistant on KylinOS. Affected by this vulnerability is the function adjust_cpufreq_scaling_governer. The manipulation leads to os command injection. It is possible to launch the attack on the local host. The exploit has been disclosed to the public… | |
| Modificada | Crítica (10) | 72% | 💥 Exploit | Home-assistantHome-assistant Supervisor | 8/3/2023 | 17/6/2026 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home… | |
| Modificada | Alta (7.2) | 0.78% | — | Media Library Assistant Project Media Library Assistant | 27/2/2023 | 17/6/2026 | The Media Library Assistant WordPress plugin before 3.06 does not properly sanitise and escape a parameter before using it in a SQL statement, leading to a SQL injection exploitable by high privilege users such as admin. | |
| Modificada | Media (5.3) | 0.15% | — | Intel Endpoint Management Assistant | 16/2/2023 | 17/6/2026 | Improper neutralization in the Intel(R) EMA software before version 1.8.1.0 may allow a privileged user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (7) | 0.13% | — | Intel Driver & Support Assistant | 16/2/2023 | 17/6/2026 | Description: Race condition in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.23% | — | Intel Driver & Support Assistant | 16/2/2023 | 17/6/2026 | Protection mechanism failure in the Intel(R) DSA software before version 22.4.26 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.20% | — | Elecom Camera AssistantElecom Quickfiledealer | 15/2/2023 | 17/6/2026 | Untrusted search path vulnerability in ELECOM Camera Assistant 1.00 and QuickFileDealer Ver.1.2.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.19% | — | HP Support Assistant | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files. | |
| Modificada | Alta (7.8) | 0.19% | — | HP Support Assistant | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files. | |
| Modificada | Alta (7.8) | 0.19% | — | HP Support Assistant | 1/2/2023 | 17/6/2026 | Potential security vulnerabilities have been identified in HP Support Assistant. These vulnerabilities include privilege escalation, compromise of integrity, allowed communication with untrusted clients, and unauthorized modification of files. | |
| Modificada | Crítica (9.8) | 1.9% | — | Atos Unify Openscape 4000 AssistantAtos Unify Openscape 4000 Manager | 13/12/2022 | 17/6/2026 | A command injection vulnerability has been identified in Atos Unify OpenScape 4000 Assistant and Unify OpenScape 4000 Manager (8 before R2.22.18, 10 before 0.28.13, and 10 R1 before R1.34.4) that may allow an unauthenticated attacker to upload arbitrary files and achieve administrative access to the system. | |
| Modificada | Alta (7.8) | 2.8% | — | HP FusionHP Support Assistant | 12/12/2022 | 17/6/2026 | HP Support Assistant uses HP Performance Tune-up as a diagnostic tool. HP Support Assistant uses Fusion to launch HP Performance Tune-up. It is possible for an attacker to exploit the DLL hijacking vulnerability and elevate privileges when Fusion launches the HP Performance Tune-up. | |
| Modificada | Media (5.3) | 0.58% | — | Davidlingren Media Library Assistant | 18/11/2022 | 17/6/2026 | Unauthenticated Error Log Disclosure vulnerability in Media Library Assistant plugin <= 3.00 on WordPress. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Endpoint Management Assistant | 11/11/2022 | 17/6/2026 | Cross-site scripting in the Intel(R) EMA software before version 1.8.0 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 0.47% | — | Intel Active Management Technology Software Development KITIntel Endpoint Management AssistantIntel Manageability Commander | 11/11/2022 | 17/6/2026 | Insufficiently protected credentials in software in Intel(R) AMT SDK before version 16.0.4.1, Intel(R) EMA before version 1.7.1 and Intel(R) MC before version 2.3.2 may allow an authenticated user to potentially enable escalation of privilege via network access. | |
| Modificada | Alta (8) | 0.39% | — | Intel Driver & Support Assistant | 18/8/2022 | 17/6/2026 | Improper access control in the Intel(R) DSA software for before version 22.2.14 may allow an authenticated user to potentially enable escalation of privilege via adjacent access. | |
| Modificada | Media (6.5) | 0.37% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force Id: 208310. | |
| Modificada | Media (6.5) | 0.86% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) could allow an authenticated user to obtain sensitive information due to improper client side validation. IBM X-Force ID: 203738. | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Media (5.4) | 0.50% | — | IBM Engineering Requirements Quality Assistant On-premises | 18/7/2022 | 17/6/2026 | IBM Engineering Requirements Quality Assistant On-Premises (All versions) is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force… | |
| Modificada | Crítica (9.3) | 1.3% | — | Barry Voice Assistant Project Barry Voice Assistant | 11/7/2022 | 17/6/2026 | The lyubolp/Barry-Voice-Assistant repository through 2021-01-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Media (6.5) | 0.85% | — | SAP Contributor License Agreement Assistant | 6/6/2022 | 17/6/2026 | Due to improper error handling an authenticated user can crash CLA assistant instance. This could impact the availability of the application. |