Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

809 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.1)0.43%—Oracle Process Manufacturing Product Development15/10/202417/6/2026
Vulnerability in the Oracle Process Manufacturing Product Development product of Oracle E-Business Suite (component: Quality Manager Specification). Supported versions that are affected are 12.2.13-12.2.14. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise…
ModificadaCrítica (9.8)0.87%—Rittal IOT Interface FirmwareRittal CMC III Processing Units Firmware15/10/202417/6/2026
The devices are vulnerable to session hijacking due to insufficient entropy in its session ID generation algorithm. The session IDs are predictable, with only 32,768 possible values per user, which allows attackers to pre-generate valid session IDs, leading to unauthorized access to user sessions. This is not only due…
AplazadaCrítica (9.8)0.64%—Rittal IOT InterfaceAIRittal CMC III Processing UnitAI15/10/202417/6/2026
The firmware upgrade function in the admin web interface of the Rittal IoT Interface & CMC III Processing Unit devices checks if the patch files are signed before executing the containing run.sh script. The signing process is kind of an HMAC with a long string as key which is hard-coded in the firmware and is freely…
AnalizadaAlta (8.7)0.55%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Controllogix 5580 Process FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 Firmware+414/10/202417/6/2026
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To…
AnalizadaAlta (7.5)1.0%—Apache Formatting Objects Processor9/10/202417/6/2026
Improper Restriction of XML External Entity Reference ('XXE') vulnerability in Apache XML Graphics FOP. This issue affects Apache XML Graphics FOP: 2.9. Users are recommended to upgrade to version 2.10, which fixes the issue.
AplazadaMedia (5.6)0.18%—Intel ProcessorsAI16/9/202417/6/2026
Improper finite state machines (FSMs) in hardware logic in some Intel(R) Processors may allow an privileged user to potentially enable a denial of service via local access.
AplazadaMedia (6.8)0.15%—Intel ProcessorsAIIntel SGXAI16/9/202417/6/2026
Improper conditions check in some Intel(R) Processors with Intel(R) SGX may allow a privileged user to potentially enable information disclosure via local access.
AplazadaCrítica (9.4)0.61%—Siemens Simatic BatchAISiemens Simatic Information ServerAISiemens Simatic PCS 7AISiemens Simatic Process HistorianAI+210/9/202417/6/2026
A vulnerability has been identified in SIMATIC BATCH V9.1 (All versions), SIMATIC Information Server 2020 (All versions < V2020 SP2 Update 5), SIMATIC Information Server 2022 (All versions < V2022 SP1 Update 2), SIMATIC PCS 7 V9.1 (All versions < V9.1 SP2 UC06), SIMATIC Process Historian 2020 (All versions < V2020 SP2…
AnalizadaMedia (5.5)0.09%—Qualcomm Apq8017 FirmwareQualcomm Aqt1000 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+1992/9/202417/6/2026
Transient DOS while handling PS event when Program Service name length offset value is set to 255.
AnalizadaAlta (8.2)0.26%—Qualcomm Qcn9024 FirmwareQualcomm Qcs4490 FirmwareQualcomm Qcs5430 FirmwareQualcomm Qcs6490 Firmware+1572/9/202417/6/2026
Information disclosure while decoding Tracking Area Update Accept or Attach Accept message received from network.
AnalizadaAlta (7.5)0.26%—Qualcomm Apq8017 FirmwareQualcomm Apq8037 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 7800 Firmware+492/9/202417/6/2026
Transient DOS when registration accept OTA is received with incorrect ciphering key data IE in Modem.
ModificadaAlta (7.5)2.6%—Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Build OF KeycloakRedhat Data Grid+521/8/202424/9/2026
A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder…
AplazadaMedia (6.7)0.19%—Intel Xeon Scalable ProcessorsAI14/8/202417/6/2026
Mirrored regions with different values in 3rd Generation Intel(R) Xeon(R) Scalable Processors may allow a privileged user to potentially enable denial of service via local access.
AplazadaMedia (6.9)0.17%—Intel Xeon ProcessorsAI14/8/202417/6/2026
Protection mechanism failure in some 3rd, 4th, and 5th Generation Intel(R) Xeon(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.3)0.23%—Intel ProcessorAI14/8/202417/6/2026
Incorrect behavior order in transition between executive monitor and SMI transfer monitor (STM) in some Intel(R) Processor may allow a privileged user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.8)0.16%—Intel Xeon ProcessorsAI14/8/202417/6/2026
Insufficient control flow management for some Intel(R) Xeon Processors may allow an authenticated user to potentially enable denial of service via local access.
AplazadaAlta (7.3)0.29%—Intel ProcessorsAI14/8/202417/6/2026
Improper isolation in some Intel(R) Processors stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (7.3)0.24%—Intel Core Ultra ProcessorAI14/8/202417/6/2026
Improper isolation in the Intel(R) Core(TM) Ultra Processor stream cache mechanism may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.7)0.14%—AMD Secure ProcessorAI13/8/202417/6/2026
Improper key usage control in AMD Secure Processor (ASP) may allow an attacker with local access who has gained arbitrary code execution privilege in ASP to extract ASP cryptographic keys, potentially resulting in loss of confidentiality and integrity.
AplazadaAlta (7.3)0.18%—AMD Secure ProcessorAIAMD Secure OSAI13/8/202417/6/2026
Insufficient checking of memory buffer in AMD Secure Processor (ASP) Secure OS may allow an attacker with a malicious trusted application to read/write to the ASP Secure OS kernel virtual address space, potentially resulting in privilege escalation.
AnalizadaAlta (7.8)0.10%—Qualcomm 315 5G IOT Modem FirmwareQualcomm Aqt1000 FirmwareQualcomm Ar8031 FirmwareQualcomm C-v2x 9150 Firmware+865/8/202417/6/2026
Memory corruption can occur when arbitrary user-space app gains kernel level privilege to modify DDR memory by corrupting the GPU page table.
AnalizadaAlta (7.5)0.35%—Qualcomm Wsa8845h FirmwareQualcomm Wsa8845 FirmwareQualcomm Wsa8840 FirmwareQualcomm Wsa8835 Firmware+2455/8/202417/6/2026
Transient DOS while decoding attach reject message received by UE, when IEI is set to ESM_IEI.
ModificadaCrítica (9.3)1.4%—Perkinelmer Processplus22/7/202417/6/2026
Execution with unnecessary privileges in PerkinElmer ProcessPlus allows an attacker to spawn a remote shell on the windows system.This issue affects ProcessPlus: through 1.11.6507.0.
ModificadaCrítica (9.3)1.1%—Perkinelmer Processplus22/7/202417/6/2026
Use of hard-coded MSSQL credentials in PerkinElmer ProcessPlus on Windows allows an attacker to login remove on all prone installations.This issue affects ProcessPlus: through 1.11.6507.0.
ModificadaAlta (8.7)4.9%💥 ExploitPerkinelmer Processplus22/7/202417/6/2026
Files on the Windows system are accessible without authentication to external parties due to a local file inclusion in PerkinElmer ProcessPlus.This issue affects ProcessPlus: through 1.11.6507.0.