Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2950▲ 8 respecto a la semana anterior
Críticas / altas1450▲ 184 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
231 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.6) | 8.6% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+221 | 10/7/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis. | |
| Modificada | Alta (7.8) | 0.35% | — | Intel Processor Diagnostic Tool | 10/7/2018 | 17/6/2026 | Unquoted service paths in Intel Processor Diagnostic Tool (IPDT) before version 4.1.0.27 allows a local attacker to potentially execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.37% | — | Intel Processor Diagnostic Tool | 10/7/2018 | 17/6/2026 | Installation tool IPDT (Intel Processor Diagnostic Tool) 4.1.0.24 sets permissions of installed files incorrectly, allowing for execution of arbitrary code and potential privilege escalation. | |
| Modificada | Alta (7.8) | 0.47% | — | Linux KernelSuse Linux Enterprise Module FOR Public CloudSuse Linux Enterprise ServerCanonical Ubuntu Linux+8 | 30/3/2018 | 17/6/2026 | The Linux kernel 4.15 has a Buffer Overflow via an SNDRV_SEQ_IOCTL_SET_CLIENT_POOL ioctl write operation to /dev/snd/seq by a local user. | |
| Modificada | Alta (7.5) | 16% | — | Openbsd OpensshDebian LinuxCanonical Ubuntu LinuxNetapp Cloud Backup+8 | 21/1/2018 | 17/6/2026 | sshd in OpenSSH before 7.4 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via an out-of-sequence NEWKEYS message, as demonstrated by Honggfuzz, related to kex.c and packet.c. | |
| Modificada | Alta (7.5) | 40% | — | OpensslDebian LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+41 | 13/11/2017 | 17/6/2026 | A denial of service flaw was found in OpenSSL 0.9.8, 1.0.1, 1.0.2 through 1.0.2h, and 1.1.0 in the way the TLS/SSL protocol defined processing of ALERT packets during a connection handshake. A remote attacker could use this flaw to make a TLS/SSL server consume an excessive amount of CPU and fail to accept connections… | |
| Modificada | Media (6.1) | 0.64% | — | Wso2 Application ServerWso2 Business Process ServerWso2 Business Rules ServerWso2 Complex Event Processor+4 | 4/10/2017 | 17/6/2026 | The Management Console in WSO2 Application Server 5.3.0, WSO2 Business Process Server 3.6.0, WSO2 Business Rules Server 2.2.0, WSO2 Complex Event Processor 4.2.0, WSO2 Dashboard Server 2.0.0, WSO2 Data Analytics Server 3.1.0, WSO2 Data Services Server 3.5.1, and WSO2 Machine Learner 1.2.0 is affected by stored XSS. | |
| Modificada | Media (4.8) | 3.8% | — | Wso2 API ManagerWso2 APP ManagerWso2 Application ServerWso2 Business Process Server+13 | 21/9/2017 | 17/6/2026 | WSO2 Data Analytics Server 3.1.0 has XSS in carbon/resources/add_collection_ajaxprocessor.jsp via the collectionName or parentPath parameter. | |
| Modificada | Alta (7.8) | 2.5% | — | Hancom Hangul Word Processor | 25/7/2017 | 17/6/2026 | hwpapp.dll in Hangul Word Processor allows remote attackers to execute arbitrary code via a crafted heap spray, and by leveraging a "type confusion" via an HWPX file containing a crafted para text tag. | |
| Modificada | Alta (7.8) | 1.7% | — | Hancom Hangul Word ProcessorHancom Thinkfree Office NEO | 24/5/2017 | 17/6/2026 | An exploitable heap-based buffer overflow exists in the Hangul Word Processor component (version 9.6.1.4350) of Hancom Thinkfree Office NEO 9.6.1.4902. A specially crafted document stream can cause an integer underflow resulting in a buffer overflow which can lead to code execution under the context of the… | |
| Modificada | Alta (7.5) | 55% | — | OpensslOracle Agile Engineering Data ManagementOracle Communications Application Session ControllerOracle Communications Eagle LNP Application Processor+3 | 4/5/2017 | 17/6/2026 | In OpenSSL 1.1.0 before 1.1.0d, if a malicious server supplies bad parameters for a DHE or ECDHE key exchange then this can result in the client attempting to dereference a NULL pointer leading to a client crash. This could be exploited in a Denial of Service attack. | |
| Modificada | Alta (7.3) | 2.5% | — | Apache Formatting Objects Processor | 18/4/2017 | 17/6/2026 | In Apache FOP before 2.2, files lying on the filesystem of the server which uses FOP can be revealed to arbitrary users who send maliciously formed SVG files. The file types that can be shown depend on the user context in which the exploitable application is running. If the user is root a full compromise of the server… | |
| Modificada | Media (6.4) | 1.4% | — | Oracle Communications Eagle Application Processor | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Communications EAGLE Application Processor component in Oracle Communications Applications 16.0 allows remote authenticated users to affect confidentiality and integrity via vectors related to APPL. | |
| Modificada | Media (4) | 1.2% | — | HP 3par Service Processor SP | 12/10/2015 | 17/6/2026 | HP 3PAR Service Processor SP 4.2.0.GA-29 (GA) SPOCC, SP 4.3.0.GA-17 (GA) SPOCC, and SP 4.3.0-GA-24 (MU1) SPOCC allows remote authenticated users to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (6.5) | 2.7% | — | Linux-pamOracle Sparc-opl Service Processor | 24/8/2015 | 17/6/2026 | The _unix_run_helper_binary function in the pam_unix module in Linux-PAM (aka pam) before 1.2.1, when unable to directly access passwords, allows local users to enumerate usernames or cause a denial of service (hang) via a large password. | |
| Modificada | Alta (7.5) | 76% | — | OpensslOracle Sparc-opl Service Processor | 12/6/2015 | 17/6/2026 | The X509_cmp_time function in crypto/x509/x509_vfy.c in OpenSSL before 0.9.8zg, 1.0.0 before 1.0.0s, 1.0.1 before 1.0.1n, and 1.0.2 before 1.0.2b allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via a crafted length field in ASN1_TIME data, as demonstrated by an attack… | |
| Modificada | Baja (3.7) | 100% | — | OpensslCanonical Ubuntu LinuxHp-uxIBM Content Manager+21 | 21/5/2015 | 17/6/2026 | The TLS protocol 1.2 and earlier, when a DHE_EXPORT ciphersuite is enabled on a server but not on a client, does not properly convey a DHE_EXPORT choice, which allows man-in-the-middle attackers to conduct cipher-downgrade attacks by rewriting a ClientHello with DHE replaced by DHE_EXPORT and then rewriting a… | |
| Modificada | Alta (10) | 95% | — | GNU GlibcOracle Communications Application Session ControllerOracle Communications Eagle Application ProcessorOracle Communications Eagle LNP Application Processor+14 | 28/1/2015 | 17/6/2026 | Heap-based buffer overflow in the __nss_hostname_digits_dots function in glibc 2.2, and other 2.x versions before 2.18, allows context-dependent attackers to execute arbitrary code via vectors related to the (1) gethostbyname or (2) gethostbyname2 function, aka "GHOST." | |
| Modificada | Media (4.7) | 0.59% | — | AMD 16H Model Processor FirmwareAMD 16H Model 00H ProcessorAMD 16H Model 0FH Processor | 29/11/2013 | 17/6/2026 | The microcode on AMD 16h 00h through 0Fh processors does not properly handle the interaction between locked instructions and write-combined memory types, which allows local users to cause a denial of service (system hang) via a crafted application, aka the errata 793 issue. | |
| Modificada | Alta (7.1) | 3.1% | — | HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+11 | 6/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote authenticated users to execute arbitrary code or obtain sensitive information via unknown vectors. | |
| Modificada | Alta (10) | 10% | — | HP 3com Baseline Plus SwitchHP 3com RouterHP 3com SwitchHP 3com Switch TAA Compliant+11 | 6/7/2013 | 16/6/2026 | Unspecified vulnerability on the HP ProCurve JC###A, JC###B, JD###A, JD###B, JE###A, JF###A, JF###B, JF###C, JG###A, 658250-B21, and 658247-B21; HP 3COM routers and switches; and HP H3C routers and switches allows remote attackers to execute arbitrary code or obtain sensitive information via unknown vectors. | |
| Modificada | Alta (7.8) | 2.2% | — | Cisco IOS XRCisco ASR 9000 Rsp440 RouterCisco CRS Performance Route Processor | 31/5/2012 | 16/6/2026 | Cisco IOS XR before 4.2.1 on ASR 9000 series devices and CRS series devices allows remote attackers to cause a denial of service (packet transmission outage) via a crafted packet, aka Bug IDs CSCty94537 and CSCtz62593. | |
| Modificada | Media (4) | 1.6% | — | HP Directories Support FOR Proliant Management Processors | 16/11/2011 | 16/6/2026 | Unspecified vulnerability in HP Directories Support for ProLiant Management Processors 3.10 and 3.20 for Integrated Lights-Out iLO2 and iLO3 allows remote authenticated users to obtain sensitive information via unknown vectors. | |
| Modificada | Alta (7.5) | 0.94% | — | Paymentprocessorscript Ppscript | 18/3/2010 | 16/6/2026 | SQL injection vulnerability in shop.htm in PaymentProcessorScript.net PPScript allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 2.5% | — | Xigla Absolute Form Processor.net | 14/7/2009 | 16/6/2026 | Xigla Software Absolute Form Processor .NET 4.0 allows remote attackers to bypass authentication and gain administrative access by setting a cookie to a certain value. |