Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
334 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.9% | — | Feep LibtarOpenatom OpeneulerFedoraproject Fedora | 10/8/2022 | 17/6/2026 | The th_read() function doesn’t free a variable t->th_buf.gnu_longlink after allocating memory, which may cause a memory leak. | |
| Modificada | Alta (8.1) | 1.5% | — | Feep LibtarOpenatom OpeneulerFedoraproject Fedora | 10/8/2022 | 17/6/2026 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longname, causing an out-of-bounds read. | |
| Modificada | Crítica (9.1) | 1.8% | — | Feep LibtarOpenatom OpeneulerFedoraproject Fedora | 10/8/2022 | 23/6/2026 | An attacker who submits a crafted tar file with size in header struct being 0 may be able to trigger an calling of malloc(0) for a variable gnu_longlink, causing an out-of-bounds read. | |
| Modificada | Media (6.8) | 0.61% | — | Openatom OpeneulerLinux KernelDebian Linux | 18/7/2022 | 17/6/2026 | When setting font with malicous data by ioctl cmd PIO_FONT,kernel will write memory out of bounds. | |
| Modificada | Media (6.1) | 0.57% | — | Matomo Integration | 12/7/2022 | 17/6/2026 | The matomo_integration (aka Matomo Integration) extension before 1.3.2 for TYPO3 allows XSS. | |
| Modificada | Crítica (9.8) | 1.0% | — | Atoms183 CMS Project Atoms183 CMS | 7/7/2022 | 17/6/2026 | SQL Injection vulnerability in product_admin.php in atoms183 CMS 1.0, allows attackers to execute arbitrary commands via the Name, Fname, and ID parameters to search.php. | |
| Modificada | Crítica (9.8) | 1.8% | — | Siemens Biograph Horizon Pet/ct Systems FirmwareSiemens Magnetom Numaris X FirmwareSiemens Mammomat Revelation FirmwareSiemens Naeotom Alpha Firmware+14 | 1/6/2022 | 17/6/2026 | A vulnerability has been identified in Biograph Horizon PET/CT Systems (All VJ30 versions < VJ30C-UD01), MAGNETOM Family (NUMARIS X: VA12M, VA12S, VA10B, VA20A, VA30A, VA31A), MAMMOMAT Revelation (All VC20 versions < VC20D), NAEOTOM Alpha (All VA40 versions < VA40 SP2), SOMATOM X.cite (All versions < VA30 SP5 or VA40… | |
| Modificada | Media (6.8) | 0.28% | — | Intel Core I3-12100 FirmwareIntel Core I3-12100f FirmwareIntel Core I3-12100t FirmwareIntel Core I3-12300t Firmware+394 | 12/5/2022 | 17/6/2026 | Hardware debug modes and processor INIT setting that allow override of locks for some Intel(R) Processors in Intel(R) Boot Guard and Intel(R) TXT may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (5.5) | 0.25% | — | Intel Core Processors FirmwareIntel Pentium Processors FirmwareIntel Celeron Processors FirmwareIntel Xeon Processors Firmware+4 | 12/5/2022 | 17/6/2026 | Observable behavioral discrepancy in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Crítica (9.8) | 1.4% | — | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_navigation.php | |
| Modificada | Crítica (9.8) | 1.4% | — | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_blur-save.php | |
| Modificada | Crítica (9.8) | 1.4% | — | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | AtomCMS 2.0 is vulnerabie to SQL Injection via Atom.CMS_admin_ajax_list-sort.php | |
| Modificada | Crítica (9.8) | 5.3% | 💥 Exploit | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | Atom.CMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_uploads.php | |
| Modificada | Crítica (9.8) | 5.9% | 💥 Exploit | Thedigitalcraft Atomcms | 12/4/2022 | 17/6/2026 | AtomCMS 2.0 is vulnerable to SQL Injection via Atom.CMS_admin_ajax_pages.php | |
| Modificada | Media (4.8) | 0.60% | — | Humananatomyillustrations Interactive Medical Drawing OF Human Body | 28/3/2022 | 17/6/2026 | The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (5.4) | 1.5% | 💥 Exploit | Thedigitalcraft Atomcms | 15/3/2022 | 17/6/2026 | Atom CMS v2.0 was discovered to contain a reflected cross-site scripting (XSS) vulnerability via the "A" parameter in /widgets/debug.php. | |
| Modificada | Crítica (9.8) | 7.1% | 💥 Exploit | Thedigitalcraft Atomcms | 15/3/2022 | 17/6/2026 | Atom CMS v2.0 was discovered to contain a SQL injection vulnerability via the id parameter in /admin/ajax/avatar.php. | |
| Modificada | Crítica (9.8) | 54% | 💥 Exploit | Thedigitalcraft Atomcms | 15/3/2022 | 17/6/2026 | Atom CMS v2.0 was discovered to contain a remote code execution (RCE) vulnerability via /admin/uploads.php. | |
| Modificada | Media (6.5) | 0.45% | — | Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+500 | 11/3/2022 | 17/6/2026 | Non-transparent sharing of branch predictor within a context in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.5) | 0.51% | 💥 PoC | Intel Atom P5921bIntel Atom P5931bIntel Atom P5942bIntel Atom P5962b+454 | 11/3/2022 | 17/6/2026 | Non-transparent sharing of branch predictor selectors between contexts in some Intel(R) Processors may allow an authorized user to potentially enable information disclosure via local access. | |
| Modificada | Media (6.8) | 0.35% | — | Intel Atom C2308Intel Atom C2316Intel Atom C2338Intel Atom C2350+415 | 11/3/2022 | 17/6/2026 | Hardware allows activation of test or debug logic at runtime for some Intel(R) Trace Hub instances which may allow an unauthenticated user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (5.4) | 0.95% | — | Intel Atom P5942b FirmwareIntel Atom P5931b FirmwareIntel Atom P5962b FirmwareIntel Atom P5921b Firmware+21 | 9/2/2022 | 17/6/2026 | Out of bounds read under complex microarchitectural condition in memory subsystem for some Intel Atom(R) Processors may allow authenticated user to potentially enable information disclosure or cause denial of service via network access. | |
| Modificada | Alta (7.8) | 0.30% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+676 | 9/2/2022 | 17/6/2026 | Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (6.6) | 0.30% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+677 | 9/2/2022 | 17/6/2026 | Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. | |
| Modificada | Media (6.6) | 0.32% | — | Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+677 | 9/2/2022 | 17/6/2026 | Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access. |