Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
481 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.5) | 0.18% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an information disclosure vulnerability in DirectIo64.sys that allows unauthenticated local attackers to dump complete physical memory contents by supplying a caller-controlled file path… | |
| Pendiente de análisis | Alta (8.4) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an unauthenticated physical memory disclosure in DirectIo64.sys, reachable by unprivileged local users through a single IOCTL with no caller-identity check. The handler writes a… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to issue arbitrary IN and OUT instructions to any x86 I/O port due to missing allowlist or port validation on… | |
| Pendiente de análisis | Alta (8.5) | 0.17% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to modify hardware configuration by exploiting exposed IOCTLs with no validation on device selection,… | |
| Pendiente de análisis | Media (6.9) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 14/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation and denial-of-service vulnerability in DirectIo64.sys that allows local attackers to read arbitrary Model-Specific Registers or write zero to any MSR through exposed… | |
| Pendiente de análisis | Alta (8.5) | 0.19% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a hard-coded credentials vulnerability in DirectIo64.sys that allows local attackers to perform arbitrary physical memory writes by extracting an 8-byte key embedded as a hardcoded literal… | |
| Pendiente de análisis | Media (6.9) | 0.16% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 10/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain a privilege escalation vulnerability in DirectIo64.sys that allows local users to clear arbitrary bits at any physical memory address due to missing validation of the physical address… | |
| Pendiente de análisis | Alta (8.5) | 0.15% | — | Passmark PerformancetestAIPassmark BurnintestAIPassmark OsforensicsAI | 4/9/2026 | 8/9/2026 | PassMark PerformanceTest before 11.1 build 1012, BurnInTest before 11.1 build 1000, and OSForensics before 11.1 build 1016 contain an improper access control vulnerability in the DirectIo64.sys kernel driver that allows unprivileged local users to perform privileged hardware operations by opening a handle to the… | |
| Analizada | Media (6.5) | 0.32% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has operations that are performed without validating bucket ownership using the ExpectedBucketOwner parameter. This omission may allow a remote attacker to exploit misconfigurations or naming collisions to redirect application requests to an unintended S3 bucket… | |
| Analizada | Media (5.9) | 0.18% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Media (4.3) | 0.29% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 could allow an unauthorized user to inject data into log messages due to improper neutralization of special elements when written to log files. | |
| Analizada | Media (5.9) | 0.20% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 does not validate or improperly validates TLS certificate validation, which could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Analizada | Alta (7.5) | 0.39% | — | IBM Netezza Performance Server | 3/9/2026 | 10/9/2026 | IBM Netezza Software 11.3.0.3 through Interim Fix 002 has credentials that are hardcoded in the application source code, allowing unauthorized access to the container registry. The exposed secret enables attackers to pull private container images, potentially revealing proprietary code, configuration details, and… | |
| Pendiente de análisis | Alta (8.8) | 0.64% | — | Jenkins PerformanceAI | 2/9/2026 | 3/9/2026 | Jenkins Performance Plugin 1015.v09ca_52b_3370e and earlier does not restrict the classes that can be instantiated when deserializing cached performance reports stored in the build directory on the Jenkins controller, allowing attackers with Item/Configure permission to execute arbitrary code on the Jenkins controller. | |
| En análisis | Media (5.4) | 0.12% | — | Intel Performance Counter MonitorAI | 11/8/2026 | 12/8/2026 | Untrusted search path for some Intel(R) Performance Counter Monitor (Intel(R) PCM) before version tag 202604 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege. This… | |
| Pendiente de análisis | Media (5.6) | 0.39% | — | Solarwinds Database Performance AnalyzerAI | 30/6/2026 | 2/7/2026 | SolarWinds Database Performance Analyzer was found to be affected by a stored cross-site scripting vulnerability, which when exploited, can lead to unintended script execution. | |
| Analizada | Crítica (9.1) | 0.45% | — | Oracle Application Performance Management | 17/6/2026 | 18/6/2026 | Vulnerability in the APM - Application Performance Management product of Oracle Enterprise Manager (component: JADM, JVM Diagnostics). Supported versions that are affected are 13.5 and 24.1. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise APM - Application… | |
| Analizada | Media (6.5) | 0.42% | — | IBM Cloud Application Performance Managemen | 27/5/2026 | 17/6/2026 | IBM Cloud APM, Base Private 8.1.4 and IBM Cloud APM, Advanced Private 8.1.4 IBM Db2 for Linux, UNIX and Windows (includes DB2 Connect Server) could allow an authenticated user to cause a denial of service due to improper neutralization of special elements in the data query logic of the Fenced environment. | |
| Analizada | Alta (7.8) | 0.16% | — | IBM Netezza Performance Server Replication Services | 27/5/2026 | 17/6/2026 | IBM Netezza Performance Server Replication Services 3.0.2.0 through 3.0.5.0 allows an attacker with low‑privileged access to escalate their privileges to root. By exploiting this flaw, the attacker can execute root‑level commands, obtain a root shell, and change the root user’s password. Successful exploitation also… | |
| Analizada | Media (5.4) | 0.09% | — | Intel Connectivity Performance Suite | 12/5/2026 | 21/7/2026 | Uncontrolled search path for some Intel(R) Connectivity Performance Suite software installers before version 50.25.1121.193 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Pendiente de análisis | Alta (7.8) | 0.11% | — | Passmark BurnintestAIPassmark OsforensicsAIPassmark PerformancetestAI | 1/5/2026 | 17/6/2026 | An issue in the component DirectIo64.sys of PassMark BurnInTest v11.0 Build 1011, OSForensics v11.1 Build 1007, and PerformanceTest v11.1 Build 1004 allows attackers to access kernel memory and escalate privileges via a crafted IOCTL 0x8011E044 call. | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Aplazada | Media (5.8) | 0.32% | — | Performance MonitorAI | 31/3/2026 | 17/6/2026 | The Performance Monitor WordPress plugin through 1.0.6 does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attacks | |
| Analizada | Alta (8.5) | 0.34% | — | Gigabyte Performance Library | 30/3/2026 | 17/6/2026 | The Performance Library component of Gigabyte Control Center has an Insecure Deserialization vulnerability. Authenticated local attackers can send a malicious serialized payload to the EasyTune Engine service, resulting in privilege escalation. | |
| Aplazada | Alta (7.2) | 0.37% | — | Performance MonitorAI | 21/3/2026 | 17/6/2026 | The Performance Monitor plugin for WordPress is vulnerable to Server-Side Request Forgery in all versions up to, and including, 1.0.6. This is due to insufficient validation of the 'url' parameter in the '/wp-json/performance-monitor/v1/curl_data' REST API endpoint. This makes it possible for unauthenticated attackers… |