Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)1.7%—Install-nw Project Install-nw29/5/201817/6/2026
install-nw is a module which quickly and robustly installs and caches NW.js. install-nw versions below 1.1.5 download binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested binary with an attacker controlled binary…
ModificadaAlta (8.8)2.5%—Pivotal Software Spring SecurityVmware Spring FrameworkOracle Agile Product Lifecycle ManagementOracle Application Testing Suite+3811/5/201825/8/2026
Spring Framework version 5.0.5 when used in combination with any versions of Spring Security contains an authorization bypass when using method security. An unauthorized malicious user can gain unauthorized access to methods that should be restricted.
ModificadaMedia (5.3)0.35%—SAP Crystal Reports Server10/4/201817/6/2026
Unquoted windows search path (directory/path traversal) vulnerability in Crystal Reports Server, OEM Edition (CRSE), 4.0, 4.10, 4.20, 4.30, startup path.
ModificadaBaja (3.3)0.21%—Docutracinc Dtisqlinstaller19/3/201817/6/2026
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contains a hard-coded cryptographic salt, "S@l+&pepper".
ModificadaCrítica (10)1.6%—Docutracinc Dtisqlinstaller19/3/201817/6/2026
Versions of DocuTrac QuicDoc and Office Therapy that ship with DTISQLInstaller.exe version 1.6.4.0 and prior contain three credentials with known passwords: QDMaster, OTMaster, and sa.
ModificadaCrítica (9.8)3.0%💥 ExploitVastal I-tech Buddy Zone Facebook Clone29/1/201817/6/2026
SQL Injection exists in Vastal I-Tech Buddy Zone Facebook Clone 2.9.9 via the /chat_im/chat_window.php request_id parameter or the /search_events.php category parameter.
ModificadaAlta (7.8)0.38%—Keycloak-httpd-client-install Project Keycloak-httpd-client-install20/1/201817/6/2026
keycloak-httpd-client-install versions before 0.8 allow users to insecurely pass password through command line, leaking it via command history and process info to other local users.
ModificadaMedia (5.5)0.39%—Keycloak-httpd-client-install Project Keycloak-httpd-client-install20/1/201817/6/2026
keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link.
ModificadaMedia (4.3)0.95%—Oracle Siebel Engineering-installer AND Deployment18/1/201817/6/2026
Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel…
ModificadaMedia (5.7)0.89%—Stalker Communigate PRO8/1/201817/6/2026
The "XML Interface to Messaging, Scheduling, and Signaling" (XIMSS) protocol implementation in CommuniGate Pro (CGP) 6.2 suffers from a Missing XIMSS Protocol Validation attack that leads to an email spoofing attack, allowing a malicious authenticated attacker to send a message from any source email address. The…
ModificadaBaja (3.7)0.61%—Install Norton Security22/11/201717/6/2026
Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain name of the target.
ModificadaCrítica (9.8)2.7%💥 ExploitVastal Agent Zone31/10/201717/6/2026
Vastal I-Tech Agent Zone (aka The Real Estate Script) allows SQL Injection in searchCommercial.php via the property_type, city, or posted_by parameter, or searchResidential.php via the property_type, city, or bedroom parameter, a different vulnerability than CVE-2008-3951, CVE-2009-3497, and CVE-2012-0982.
ModificadaCrítica (9.8)3.0%💥 ExploitVastal Dating Zone29/10/201717/6/2026
Vastal I-Tech Dating Zone 0.9.9 allows SQL Injection via the 'product_id' to add_to_cart.php, a different vulnerability than CVE-2008-4461.
ModificadaAlta (7)0.38%—Norton Remove & Reinstall28/9/201717/6/2026
Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to…
ModificadaAlta (7.8)1.8%—DAJ I-filter Installer15/9/201717/6/2026
Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.
ModificadaAlta (7.8)1.1%—DAJ I-filter Installer15/9/201717/6/2026
Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.1%—DAJ I-filter Installer15/9/201717/6/2026
Untrusted search path vulnerability in "i-filter 6.0 install program" file version 1.0.8.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.1%—NTT Flets Install Tool29/8/201717/6/2026
Untrusted search path vulnerability in Flets Install Tool all versions distributed through the website till 2017 August 8 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)0.99%—Sandboxie Installer6/8/201717/6/2026
Sandboxie installer 5071703 has a DLL Hijacking or Unsafe DLL Loading Vulnerability via a Trojan horse dwmapi.dll or profapi.dll file in an AppData\Local\Temp directory.
ModificadaAlta (7.8)1.1%—Sony NFC Port FirmwareSony Pc/sc Activator FOR Type BSony Sfcard Viewer 2Sony NFC NET Installer2/8/201717/6/2026
Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for RC-S320, RC-S310/J1C, RC-S310/ED4C), PC/SC Activator for Type B Ver.1.2.1.0 and earlier, SFCard Viewer 2 Ver.2.5.0.0 and…
ModificadaAlta (7.8)1.4%—Acquisition Technology AND Logistics Agency Installer OF Electronic Tendering7/7/201717/6/2026
Untrusted search path vulnerability in Installer of Electronic tendering and bid opening system available prior to June 12, 2017 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory.
ModificadaMedia (5.5)0.34%—Stalin Project Stalin27/6/201717/6/2026
stalin 0.11-5 allows local users to write to arbitrary files.
ModificadaAlta (7)0.26%—Fedoraproject ARM Installer26/6/201717/6/2026
fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories.
ModificadaAlta (7.5)0.73%—Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer20/6/201717/6/2026
If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text…
ModificadaCrítica (9.8)2.3%—Redhat Quickstart Cloud Installer13/6/201717/6/2026
/var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system.
Orbitaley — Vulnerabilidades