Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2584▼ 301 respecto a la semana anterior
Críticas / altas1355▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

363 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.40%—Josselynj Pcloud BackupAI1/4/202517/6/2026
Missing Authorization vulnerability in josselynj pCloud Backup pcloud-backup allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects pCloud Backup: from n/a through <= 1.0.1.
AnalizadaAlta (8.1)0.53%—Netapp Cloud BackupNetapp Ontap Select DeployF5 Nginx API Connectivity ManagerF5 Nginx Instance Manager+13/5/202317/6/2026
NGINX Management Suite may allow an authenticated attacker to gain access to configuration objects outside of their assigned environment. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (7.2)22%—Ahsay Cloud Backup Suite21/9/202217/6/2026
Ahsay AhsayCBS 9.1.4.0 allows an authenticated system user to inject arbitrary Java JVM options. Administrators that can modify the Runtime Options in the web interface can inject Java Runtime Options. These take effect after a restart. For example, an attacker can enable JMX services and consequently achieve remote…
ModificadaMedia (4.3)0.57%—Jenkins Google Cloud Backup27/7/202217/6/2026
A missing permission check in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers with Overall/Read permission to request a manual backup.
ModificadaAlta (8)0.48%—Jenkins Google Cloud Backup27/7/202217/6/2026
A cross-site request forgery (CSRF) vulnerability in Jenkins Google Cloud Backup Plugin 0.6 and earlier allows attackers to request a manual backup.
ModificadaMedia (6.5)0.84%—Intel Active Management Technology FirmwareNetapp Cloud Backup9/2/202217/6/2026
Null pointer dereference in subsystem for Intel(R) AMT before versions 15.0.35 may allow an authenticated user to potentially enable denial of service via network access.
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6769/2/202217/6/2026
Improper input validation in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.6)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.6)0.32%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.2)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Improper initialization in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via physical access.
ModificadaMedia (6.7)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Out-of-bounds read in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Pointer issues in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Netapp Cloud BackupNetapp Fas/aff BiosIntel Xeon Bronze 3206r FirmwareIntel Xeon Gold 5218r Firmware+6779/2/202217/6/2026
Out-of-bounds write in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.7)0.33%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Buffer overflow in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.30%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
NULL pointer dereference in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.7)0.30%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Unchecked return value in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.30%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Insufficient control flow management in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable an escalation of privilege via local access.
ModificadaAlta (7.8)0.30%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Insufficient control flow management in the firmware for some Intel(R) Processors may allow an authenticated user to potentially enable an escalation of privilege via local access.
ModificadaMedia (4.4)0.24%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Incorrect default permissions in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
ModificadaMedia (4.4)0.25%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Improper access control in the firmware for some Intel(R) Processors may allow a privileged user to potentially enable a denial of service via local access.
ModificadaAlta (7.8)0.33%—Intel Atom C3308Intel Atom C3336Intel Atom C3338Intel Atom C3338r+6779/2/202217/6/2026
Improper access control in the firmware for some Intel(R) Processors may allow an unauthenticated user to potentially enable an escalation of privilege via local access.
ModificadaMedia (6.6)0.32%—Intel C620a Series FirmwareIntel C620 Series FirmwareIntel C240 Series FirmwareIntel Atom P5000 Series Firmware+129/2/202217/6/2026
Insufficient compartmentalization in HECI subsystem for the Intel(R) SPS before versions SPS_E5_04.01.04.516.0, SPS_E5_04.04.04.033.0, SPS_E5_04.04.03.281.0, SPS_E5_03.01.03.116.0, SPS_E3_05.01.04.309.0, SPS_02.04.00.101.0, SPS_SoC-A_05.00.03.114.0, SPS_SoC-X_04.00.04.326.0, SPS_SoC-X_03.00.03.117.0,…
ModificadaAlta (8.8)54%—Apache ChainsawApache Log4jQOS Reload4jOracle Advanced Supply Chain Planning+2218/1/202217/6/2026
CVE-2020-9493 identified a deserialization issue that was present in Apache Chainsaw. Prior to Chainsaw V2.0 Chainsaw was a component of Apache Log4j 1.2.x where the same issue exists.
ModificadaCrítica (9.8)67%—Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+2418/1/202217/6/2026
By design, the JDBCAppender in Log4j 1.2.x accepts an SQL statement as a configuration parameter where the values to be inserted are converters from PatternLayout. The message converter, %m, is likely to always be included. This allows attackers to manipulate the SQL by entering crafted strings into input fields or…
ModificadaAlta (8.8)64%—Apache Log4jNetapp SnapmanagerBroadcom Brocade SannavQOS Reload4j+2218/1/202217/6/2026
JMSSink in all versions of Log4j 1.x is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration or if the configuration references an LDAP service the attacker has access to. The attacker can provide a TopicConnectionFactoryBindingName configuration causing JMSSink…