Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2528▼ 418 respecto a la semana anterior
Críticas / altas1311▲ 21 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
–

80 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.2)0.51%—Snowflake DriversAI8/9/202610/9/2026
In affected Snowflake drivers, WORKLOAD_IDENTITY authentication requests a cloud workload-identity token and attaches it to the login request without verifying that the configured host is a Snowflake endpoint. An attacker who can modify the connection configuration can cause the driver to mint a fresh attestation and…
AplazadaAlta (7.1)0.25%—Local Delivery Drivers FOR WoocommerceAI13/8/202614/8/2026
Unauthenticated Cross Site Scripting (XSS) in Local Delivery Drivers for WooCommerce <= 3.0.0 versions.
AplazadaCrítica (9.4)0.16%—XEN Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI9/7/202629/9/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons,…
AplazadaCrítica (9.4)0.16%—Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI9/7/202629/9/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are: 1. XenCons,…
AplazadaCrítica (9.4)0.16%—XEN Windows PV DriversAIXenconsoleAIXenifaceAIXenbusAI9/7/202629/9/2026
[This CNA information record relates to multiple CVEs; the text explains which aspects/vulnerabilities correspond to which CVE.] The Windows PV drivers expose various facilities to userspace. Several of these have no security descriptor, and are therefore fully accessible to unprivileged users. These are:
AplazadaAlta (8.5)0.18%—Ricoh Printer DriversAIKonicaminolta Printer DriversAI15/6/202624/7/2026
Multiple printer drivers provided by Ricoh Company, Ltd. and KONICA MINOLTA JAPAN, INC. contain a privilege escalation vulnerability. If this vulnerability is exploited, an attacker who can log in to a computer running an affected printer driver could elevate privileges by using a specially crafted driver.
Pendiente de análisisAlta (8.4)0.21%—Dynabook Bluetooth Acpi DriversAI13/4/202617/6/2026
Bluetooth ACPI Drivers provided by Dynabook Inc. contain a stack-based buffer overflow vulnerability. An attacker may execute arbitrary code by modifying certain registry values.
AplazadaMedia (5.7)0.09%—Intel NPU DriversAI10/2/202617/6/2026
Improper conditions check in some firmware for some Intel(R) NPU Drivers within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable denial of service. This result may potentially occur via local access when…
AplazadaMedia (5.1)0.12%—Intel NPU DriversAI11/11/202517/6/2026
Improper control of dynamically-managed code resources for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local…
AplazadaMedia (6.8)0.13%—Intel NPU DriversAI11/11/202517/6/2026
Protection mechanism failure for some Intel(R) NPU Drivers within Ring 3: User Applications may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially occur via local access when attack…
AplazadaBaja (2)0.12%—Intel Graphics DriversAIIntel LTS KernelAI11/11/202517/6/2026
Improper input validation in some firmware for some Intel(R) Graphics Drivers and Intel LTS kernels within Ring 1: Device Drivers may allow a denial of service. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may potentially…
AplazadaBaja (2)0.13%—Intel NPU DriversAI11/11/202517/6/2026
Sensitive information uncleared in resource before release for reuse for some Intel(R) NPU Drivers for Windows before version 32.0.100.4023 within Ring 3: User Applications may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack may enable…
AplazadaAlta (8.2)0.15%—Lexmark Printer DriversAI19/8/202517/6/2026
Improper Restriction of XML External Entity Reference in various Lexmark printer drivers for Windows allows attacker to disclose sensitive information to an arbitrary URL.
AplazadaMedia (6.8)0.14%—Intel Graphics DriversAI12/8/202517/6/2026
NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.9)0.17%—Intel Graphics DriversAI13/5/202517/6/2026
Out-of-bounds read for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable information disclosure or denial of service via local access.
AplazadaMedia (6.8)0.16%—Intel Graphics DriversAI13/5/202517/6/2026
NULL pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.8)0.16%—Intel Graphics DriversAI13/5/202517/6/2026
Improper input validation for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.9)0.15%—Intel Graphics DriversAI13/5/202517/6/2026
Untrusted pointer dereference for some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaAlta (8.4)0.21%—Seiko Epson Printer DriversAI28/4/202517/6/2026
Multiple SEIKO EPSON printer drivers for Windows OS are configured with an improper access permission settings when installed or used in a language other than English. If a user is directed to place a crafted DLL file in a location of an attacker's choosing, the attacker may execute arbitrary code with SYSTEM…
AplazadaAlta (7.8)0.35%—Synaptics Audio DriversAI11/3/202517/6/2026
** UNSUPPORTED WHEN ASSIGNED ** A privilege escalation vulnerability in CxUIUSvc64.exe and CxUIUSvc32.exe of Synaptics audio drivers allows a local authorized attacker to load a DLL in a privileged process. Out of an abundance of caution, this CVE ID is being assigned to better serve our customers and ensure all who…
AplazadaMedia (6.8)0.20%—Intel Graphics DriversAI12/2/202517/6/2026
Improper input validation in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (5.7)0.19%—Intel Ethernet Connection I219 Series DriversAI12/2/202517/6/2026
Improper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.9)0.17%—Intel Graphics DriversAI13/11/202417/6/2026
Out-of-bounds write in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (6.9)0.18%—Intel Graphics DriversAI13/11/202417/6/2026
Improper buffer restrictions in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable denial of service via local access.
AplazadaMedia (6.9)0.18%—Intel Graphics DriversAI13/11/202417/6/2026
Untrusted pointer dereference in some Intel(R) Graphics Drivers may allow an authenticated user to potentially enable escalation of privilege via local access.