Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
325 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.15% | — | Acronis Cyber Protect Home Office | 7/11/2022 | 17/6/2026 | Sensitive information leak through log files. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107. | |
| Modificada | Alta (7.3) | 0.17% | — | Acronis Cyber Protect Home Office | 7/11/2022 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 40107. | |
| Modificada | Alta (7.8) | 0.20% | — | Acronis Cyber Protect Home Office | 7/11/2022 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900. | |
| Modificada | Alta (7.8) | 0.16% | — | Acronis Cyber Protect Home Office | 7/11/2022 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39900. | |
| Modificada | Media (6.1) | 0.65% | — | Gocron Project Gocron | 14/9/2022 | 17/6/2026 | Cross site scripting (XSS) vulnerability in ouqiang gocron through 1.5.3, allows attackers to execute arbitrary code via scope.row.hostname in web/vue/src/pages/taskLog/list.vue. | |
| Modificada | Media (5.3) | 1.4% | — | Evmos EthermintKavaCrypto CronosEvmos | 5/8/2022 | 17/6/2026 | Ethermint is an Ethereum library. In Ethermint running versions before `v0.17.2`, the contract `selfdestruct` invocation permanently removes the corresponding bytecode from the internal database storage. However, due to a bug in the `DeleteAccount`function, all contracts that used the identical bytecode (i.e shared… | |
| Modificada | Crítica (9.8) | 25% | — | Acrontum Filesystem-template | 5/8/2022 | 17/6/2026 | The package @acrontum/filesystem-template before 0.0.2 are vulnerable to Arbitrary Command Injection due to the fetchRepo API missing sanitization of the href field of external input. | |
| Modificada | Alta (7.5) | 0.60% | — | Acronis Cyber Protect | 18/5/2022 | 17/6/2026 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 29240 | |
| Modificada | Alta (7.5) | 0.60% | — | Acronis Cyber Protect | 18/5/2022 | 17/6/2026 | Cleartext transmission of sensitive information. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | |
| Modificada | Media (6.1) | 0.56% | — | Acronis Cyber Protect | 18/5/2022 | 17/6/2026 | Open redirect via user-controlled query parameter. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | |
| Modificada | Media (6.1) | 0.56% | — | Acronis Cyber Protect | 18/5/2022 | 17/6/2026 | HTML injection via report name. The following products are affected: Acronis Cyber Protect 15 (Linux, Windows) before build 29240 | |
| Modificada | Alta (7.5) | 0.92% | — | Acronis Cyber ProtectAcronis Agent | 18/5/2022 | 17/6/2026 | Sensitive information disclosure due to insecure folder permissions. The following products are affected: Acronis Cyber Protect 15 (Linux) before build 29240, Acronis Agent (Linux) before build 28037 | |
| Modificada | Alta (7.8) | 0.23% | — | Acronis Snap Deploy | 16/5/2022 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 | |
| Modificada | Alta (7.8) | 0.25% | — | Acronis Snap Deploy | 16/5/2022 | 17/6/2026 | Local privilege escalation due to a DLL hijacking vulnerability. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 | |
| Modificada | Alta (7.8) | 0.20% | — | Acronis Snap Deploy | 16/5/2022 | 17/6/2026 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Snap Deploy (Windows) before build 3640 | |
| Modificada | Alta (7.8) | 0.25% | — | KDE Kcron | 26/2/2022 | 17/6/2026 | KDE KCron through 21.12.2 uses a temporary file in /tmp when saving, but reuses the filename during an editing session. Thus, someone watching it be created the first time could potentially intercept the file the following time, enabling that person to run unauthorized commands. | |
| Modificada | Alta (7.8) | 0.20% | — | Acronis VSS Doctor | 11/2/2022 | 17/6/2026 | Local privilege escalation due to insecure folder permissions. The following products are affected: Acronis VSS Doctor (Windows) before build 53 | |
| Modificada | Media (4.3) | 0.65% | — | Bracketspace Advanced Cron Manager | 7/2/2022 | 17/6/2026 | The Advanced Cron Manager WordPress plugin before 2.4.2 and Advanced Cron Manager Pro WordPress plugin before 2.5.3 do not have authorisation checks in some of their AJAX actions, allowing any authenticated users, such as subscriber to call them and add or remove events as well as schedules for example | |
| Modificada | Alta (7.8) | 0.16% | — | Acronis True ImageAcronis Cyber Protect Home Office | 4/2/2022 | 17/6/2026 | Local privilege escalation due to unrestricted loading of unsigned libraries. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before build 39287 | |
| Modificada | Alta (7) | 0.15% | — | Acronis True ImageAcronis Cyber Protect Home Office | 4/2/2022 | 17/6/2026 | Local privilege escalation due to race condition on application startup. The following products are affected: Acronis Cyber Protect Home Office (macOS) before build 39605, Acronis True Image 2021 (macOS) before build 39287 | |
| Modificada | Alta (7.8) | 0.21% | — | Acronis AgentAcronis Cyber ProtectAcronis Cyber Protect Home OfficeAcronis True Image | 4/2/2022 | 17/6/2026 | Local privilege escalation due to excessive permissions assigned to child processes. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows)… | |
| Modificada | Alta (7.3) | 0.24% | — | Acronis True ImageAcronis Cyber Protect Home Office | 4/2/2022 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability in Acronis Media Builder service. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287 | |
| Modificada | Alta (7.3) | 0.24% | — | Acronis True ImageAcronis Cyber Protect Home Office | 4/2/2022 | 17/6/2026 | Local privilege escalation due to DLL hijacking vulnerability. The following products are affected: Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows) before build 39287 | |
| Modificada | Alta (7.8) | 0.20% | — | Acronis True ImageAcronis AgentAcronis Cyber ProtectAcronis Cyber Protect Home Office | 4/2/2022 | 17/6/2026 | Local privilege escalation via named pipe due to improper access control checks. The following products are affected: Acronis Cyber Protect 15 (Windows) before build 28035, Acronis Agent (Windows) before build 27147, Acronis Cyber Protect Home Office (Windows) before build 39612, Acronis True Image 2021 (Windows)… | |
| Modificada | Media (5.3) | 1.1% | — | Objectcomputing Micronaut | 18/1/2022 | 17/6/2026 | Micronaut is a JVM-based, full stack Java framework designed for building JVM web applications with support for Java, Kotlin and the Groovy language. In affected versions sending an invalid Content Type header leads to memory leak in DefaultArgumentConversionContext as this type is erroneously used in static state.… |