Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 76 respecto a la semana anterior
Críticas / altas1446▲ 304 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

15 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.5)0.17%—MSI Feature ManagerAIMSI Kerncorelib64AI7/7/202610/7/2026
MSI Feature Manager contains a local privilege escalation vulnerability in the KernCoreLib64.sys kernel driver that allows any locally logged-on user to perform arbitrary physical memory read/write and unrestricted I/O port operations by accessing exposed IOCTL handlers without administrator privileges. Attackers can…
AnalizadaMedia (5.7)0.20%—Sencore Decoder-ccv2 FirmwareSencore Smp100 FirmwareSencore En2sdi-2hd Firmware18/11/202517/6/2026
The Sencore SMP100 SMP Media Platform (firmware versions V4.2.160, V60.1.4, V60.1.29) is vulnerable to session hijacking due to improper session management on the /UserManagement.html endpoint. Attackers who are on the same network as the victim and have access to the target's logged-in session can access the endpoint…
AplazadaMedia (6.5)0.44%—Asna RegistrarAIAsna Datagate FOR SQL ServerAIAsna Datagate Component SuiteAIAsna Datagate MonitorAI+133/7/202517/6/2026
ASNA Assist and ASNA Registrar before 2025-03-31 allow deserialization attacks against .NET remoting. These are Windows system services that support license key management and deprecated Windows network authentication. The services are implemented with .NET remoting and can be exploited via well-known deserialization…
ModificadaAlta (7.5)0.54%—Philips Encoreanywhere9/11/202317/6/2026
The HTTP header in Philips EncoreAnywhere contains data an attacker may be able to use to gain sensitive information.
ModificadaCrítica (9.8)2.8%—Techreborn Reborncore31/5/202117/6/2026
The RebornCore library before 4.7.3 allows remote code execution because it deserializes untrusted data in ObjectInputStream.readObject as part of reborncore.common.network.ExtendedPacketBuffer. An attacker can instantiate any class on the classpath with any data. A class usable for exploitation might or might not be…
ModificadaMedia (4.6)0.32%—Medtronic Carelink 2090 Programmer FirmwareMedtronic Carelink 9790 Programmer FirmwareMedtronic 29901 Encore Programmer Firmware14/12/201817/6/2026
Medtronic CareLink and Encore Programmers do not encrypt or do not sufficiently encrypt sensitive PII and PHI information while at rest .
ModificadaMedia (5)2.3%—III Encore Discovery Solution29/8/201417/6/2026
Innovative Interfaces Encore Discovery Solution 4.3 places a session token in the URI, which might allow remote attackers to obtain sensitive information via unspecified vectors.
ModificadaMedia (5.8)2.1%—III Encore Discovery Solution29/8/201417/6/2026
Open redirect vulnerability in Innovative Interfaces Encore Discovery Solution 4.3 allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in an unspecified parameter.
ModificadaBaja (2.1)0.33%—Apple MAC OS XApple CarboncoreApple MAC OS X Server23/3/201116/6/2026
The FSFindFolder API in CarbonCore in Apple Mac OS X before 10.6.7 provides a world-readable directory in response to a call with the kTemporaryFolderType flag, which allows local users to obtain potentially sensitive information by accessing this directory.
ModificadaBaja (2.1)0.32%—Intrinsic Swimage Encore19/2/200916/6/2026
Conductor.exe in Intrinsic Swimage Encore before 5.0.1.21 contains a hardcoded password, which might allow local users to decrypt certain .bin files. NOTE: it is not clear whether this issue crosses privilege boundaries.
ModificadaMedia (6.8)2.2%—Android Opencore11/2/200916/6/2026
Integer underflow in the Huffman decoding functionality (pvmp3_huffman_parsing.cpp) in OpenCORE 2.0 and earlier allows remote attackers to cause a denial of service (process crash) and possibly execute arbitrary code via a crafted MP3 file that triggers heap corruption.
ModificadaAlta (9.3)3.8%—Apple Carboncore4/8/200816/6/2026
Stack-based buffer overflow in CarbonCore in Apple Mac OS X 10.4.11 and 10.5.4, iPhone OS 1.0 through 2.2.1, and iPhone OS for iPod touch 1.1 through 2.2.1 allows context-dependent attackers to execute arbitrary code or cause a denial of service (application crash) via a long filename to the file management API.
ModificadaBaja (2.6)0.92%—Ncipher Dse200 Document Sealing EngineNcipher NcoreNcipher NforceNcipher Securedb+49/3/200616/6/2026
nCipher firmware before V10, as used by (1) nShield, (2) nForce, (3) netHSM, (4) payShield, (5) SecureDB, (6) DSE200 Document Sealing Engine, (7) Time Source Master Clock (TSMC), and possibly other products, contains certain options that were only intended for testing and not production, which might allow remote…
ModificadaMedia (5)1.6%—Ncipher Ncore9/3/200616/6/2026
The CBC-MAC integrity functions in the nCipher nCore API before 2.18 transmit the initialization vector IV as part of a message when the implementation uses a non-zero IV, which allows remote attackers to bypass integrity checks and modify messages without being detected.
ModificadaAlta (7.5)9.3%—Aborior Encore WEB Forum31/12/200416/6/2026
display.cgi in Aborior Encore WebForum allows remote to execute arbitrary commands via shell metacharacters in the file variable.