Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.34% | — | Tanium Benchmark | 5/2/2026 | 17/6/2026 | Tanium addressed an incorrect default permissions vulnerability in Benchmark. | |
| Aplazada | Media (4.3) | 0.20% | — | Anton Aleksandrov Wordpress Hosting Benchmark ToolAI | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Anton Aleksandrov WordPress Hosting Benchmark tool.This issue affects WordPress Hosting Benchmark tool: from n/a through 1.3.6. | |
| Aplazada | Media (4.3) | 0.20% | — | Coded Commerce LLC Benchmark Email LiteAI | 12/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Coded Commerce, LLC Benchmark Email Lite.This issue affects Benchmark Email Lite: from n/a through 4.1. | |
| Modificada | Media (5.4) | 0.50% | — | Jenkins Benchmark Evaluator | 12/7/2023 | 17/6/2026 | A missing permission check in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system. | |
| Modificada | Alta (8.8) | 0.49% | — | Jenkins Benchmark Evaluator | 12/7/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins Benchmark Evaluator Plugin 1.0.1 and earlier allows attackers to connect to an attacker-specified URL and to check for the existence of directories, `.csv`, and `.ycsb` files on the Jenkins controller file system. | |
| Modificada | Crítica (9.3) | 1.3% | — | Data Stream Algorithm Benchmark Project Data Stream Algorithm Benchmark | 11/7/2022 | 17/6/2026 | The DSABenchmark/DSAB repository through 2.1 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (8.6) | 1.2% | — | Data Stream Algorithm Benchmark Project Data Stream Algorithm Benchmark | 11/7/2022 | 17/6/2026 | The DSAB-local/DSAB repository through 2019-02-18 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Modificada | Alta (7.3) | 0.53% | — | Miele Benchmark Programming Tool | 27/4/2022 | 17/6/2026 | In Miele Benchmark Programming Tool with versions Prior to 1.2.71, executable files manipulated by attackers are unknowingly executed with users privileges. An attacker with low privileges may trick a user with administrative privileges to execute these binaries as admin. |