Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

481 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.5)0.18%—Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI4/9/20268/9/2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path…
Pendiente de análisisAlta (8.4)0.17%—Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI4/9/202610/9/2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a…
Pendiente de análisisMedia (6.9)0.16%—Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI4/9/20268/9/2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on…
Pendiente de análisisAlta (8.5)0.17%—Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI4/9/20268/9/2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection,…
Pendiente de análisisMedia (6.9)0.15%—Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI4/9/202614/9/2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed…
Pendiente de análisisAlta (8.5)0.19%—Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI4/9/20268/9/2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal…
Pendiente de análisisMedia (6.9)0.16%—Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI4/9/202610/9/2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address…
Pendiente de análisisAlta (8.5)0.15%—Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI4/9/20268/9/2026
PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the…
AnalizadaMedia (6.5)0.32%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket…
AnalizadaMedia (5.9)0.18%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
AnalizadaMedia (4.3)0.29%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files.
AnalizadaMedia (5.9)0.20%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques.
AnalizadaAlta (7.5)0.39%—IBM Netezza Performance Server3/9/202610/9/2026
IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and…
Pendiente de análisisAlta (8.8)0.64%—Jenkins PerformanceAI2/9/20263/9/2026
Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller.
En análisisMedia (5.4)0.12%—Intel Performance Counter MonitorAI11/8/202612/8/2026
Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This…
Pendiente de análisisMedia (5.6)0.39%—Solarwinds Database Performance AnalyzerAI30/6/20262/7/2026
SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution.
AnalizadaCrítica (9.1)0.45%—Oracle Application Performance Management17/6/202618/6/2026
Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application…
AnalizadaMedia (6.5)0.42%—IBM Cloud Application Performance Managemen27/5/202617/6/2026
IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment.
AnalizadaAlta (7.8)0.16%—IBM Netezza Performance Server Replication Services27/5/202617/6/2026
IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker can execute root‑level commands, obtain a root shell, and change the root user’s password. Successful exploitation also…
AnalizadaMedia (5.4)0.09%—Intel Connectivity Performance Suite12/5/202621/7/2026
Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of…
Pendiente de análisisAlta (7.8)0.11%—Passmark BurnintestAIPassmark OsforensicsAIPassmark PerformancetestAI1/5/202617/6/2026
An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 allows attackers to access kernel memory and escalate privileges via a crafted IOCTL 0x8011E044 call.
AnalizadaAlta (7.8)3.4%⚠ Explotación activaLinux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+4422/4/20268/9/2026
In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different…
AplazadaMedia (5.8)0.32%—Performance MonitorAI31/3/202617/6/2026
The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attacks
AnalizadaAlta (8.5)0.34%—Gigabyte Performance Library30/3/202617/6/2026
The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation.
AplazadaAlta (7.2)0.37%—Performance MonitorAI21/3/202617/6/2026
The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers…