Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

29 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.1)0.58%—Themerex TuningAI5/3/202617/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in ThemeREX Tuning tuning allows PHP Local File Inclusion.This issue affects Tuning: from n/a through <= 1.3.
AnalizadaCrítica (9.8)0.36%—Hitachi Tuning Manager6/8/202417/6/2026
Expression Language Injection vulnerability in Hitachi Tuning Manager on Windows, Linux, Solaris allows Code Injection.This issue affects Hitachi Tuning Manager: before 8.8.7-00.
ModificadaAlta (7.8)0.16%—Intel Extreme Tuning Utility16/5/202417/6/2026
Insecure inherited permissions in some Intel(R) XTU software before version 7.14.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel Extreme Tuning Utility14/2/202417/6/2026
Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel Extreme Tuning Utility14/2/202417/6/2026
Improper access control in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.19%—Intel Extreme Tuning Utility14/2/202417/6/2026
Uncontrolled search path in some Intel(R) XTU software before version 7.12.0.29 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.1)0.14%—Hitachi Tuning Manager16/1/202417/6/2026
Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Windows (Hitachi Tuning Manager server component) allows local users to read and write specific files.This issue affects Hitachi Tuning Manager: before 8.8.5-04.
ModificadaAlta (7.8)0.24%—Intel Extreme Tuning Utility14/11/202317/6/2026
Uncontrolled search path element in some Intel(R) XTU software before version 7.12.0.15 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.16%—Intel Dynamic Tuning Technology11/8/202317/6/2026
Improper access control in the Intel® DTT Software before version 8.7.10400.15482 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.16%—Hitachi Compute Systems ManagerHitachi Device ManagerHitachi Replication ManagerHitachi Tiered Storage Manager+118/7/202317/6/2026
Incorrect Default Permissions vulnerability in Hitachi Device Manager on Linux (Device Manager Server component), Hitachi Tiered Storage Manager on Linux, Hitachi Replication Manager on Linux, Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning…
ModificadaAlta (7.1)0.15%—Hitachi Tuning Manager17/1/202317/6/2026
Incorrect Default Permissions vulnerability in Hitachi Tuning Manager on Linux (Hitachi Tuning Manager server, Hitachi Tuning Manager - Agent for RAID, Hitachi Tuning Manager - Agent for NAS, Hitachi Tuning Manager - Agent for SAN Switch components) allows local users to read and write specific files.This issue…
ModificadaAlta (7.3)0.25%—Intel Extreme Tuning Utility12/5/202217/6/2026
Uncontrolled search path in the Intel(R) XTU software before version 7.3.0.33 may allow an authenticated user to potentially enable escalation of privilege via local access.
AnalizadaCrítica (10)100%⚠ Explotación activaSiemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+13910/12/202111/8/2026
Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can…
ModificadaMedia (4.4)0.54%—Intel Extreme Tuning Utility17/2/202117/6/2026
Out-of-bounds write in the Intel(R) XTU before version 6.5.3.25 may allow a privileged user to potentially enable denial of service via local access.
ModificadaAlta (7.8)0.33%—Intel Extreme Tuning Utility12/11/202017/6/2026
Improper access control in the Intel(R) XTU before version 6.5.1.360 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.5)0.84%—Hitachi Device ManagerHitachi Compute Systems ManagerHitachi Automation DirectorHitachi Tiered Storage Manager+414/2/202017/6/2026
A vulnerability in Hitachi Command Suite prior to 8.6.2-00, Hitachi Automation Director prior to 8.6.2-00 and Hitachi Infrastructure Analytics Advisor prior to 4.2.0-00 allow authenticated remote users to load an arbitrary Cascading Style Sheets (CSS) token sequence. Hitachi Command Suite includes Hitachi Device…
ModificadaAlta (7.5)1.3%—Hitachi Device ManagerHitachi Replication ManagerHitachi Tiered Storage ManagerHitachi Infrastructure Analytics Advisor+112/11/201917/6/2026
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.7.0-00 allows an unauthenticated remote user to trigger a denial of service (DoS) condition because of Uncontrolled Resource Consumption.
ModificadaAlta (7.5)1.4%—Hitachi Device ManagerHitachi Tiered Storage ManagerHitachi Replication ManagerHitachi Tuning Manager+112/11/201917/6/2026
A vulnerability in Hitachi Command Suite 7.x and 8.x before 8.6.5-00 allows an unauthenticated remote user to read internal information.
ModificadaAlta (7.8)1.3%—Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read/write data from/to IO ports. This could be leveraged in a number of ways to ultimately run code with elevated…
ModificadaAlta (7.8)1.5%—Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write Machine Specific Registers (MSRs). This could be leveraged to execute arbitrary ring-0 code.
ModificadaAlta (7.1)0.98%—Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write arbitrary physical memory. This could be leveraged by a local attacker to elevate privileges.
ModificadaAlta (7.8)1.2%—Asrock A-tuningAsrock F-streamAsrock Restart TO UefiAsrock Rgbled30/10/201817/6/2026
The AsrDrv101.sys and AsrDrv102.sys low-level drivers in ASRock RGBLED before v1.0.35.1, A-Tuning before v3.0.210, F-Stream before v3.0.210, and RestartToUEFI before v1.0.6.2 expose functionality to read and write CR register values. This could be leveraged in a number of ways to ultimately run code with elevated…
ModificadaMedia (5.5)0.28%—Intel Extreme Tuning Utility12/9/201817/6/2026
Buffer overflow in installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially cause a buffer overflow potentially leading to a denial of service via local access.
ModificadaMedia (6.7)0.38%—Intel Extreme Tuning Utility12/9/201817/6/2026
Escalation of privilege in Installer for Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially execute code or disclose information as administrator via local access.
ModificadaMedia (5.5)0.28%—Intel Extreme Tuning Utility12/9/201817/6/2026
Buffer overflow in input handling in Intel Extreme Tuning Utility before 6.4.1.21 may allow an authenticated user to potentially deny service to the application via local access.