Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.1% | — | Santeikohyo Installer OF Houkokusyo Sakusei Shien Tool | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in the installer of Houkokusyo Sakusei Shien Tool ver3.0.2 (For the first installation) (The version which was available on the website from 2017 April 4 to 2017 May 18) and ver2.0 and later (For the first installation) (The versions which were available on the website prior to 2017… | |
| Modificada | Alta (7.8) | 1.1% | — | Sharp Rw-5100 Driver Installer FOR Windows 7Sharp Rw-5100 Driver Installer FOR Windows 8.1 | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 2.5% | — | Vivaldi Installer FOR Windows | 28/4/2017 | 17/6/2026 | Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (4.6) | 0.42% | — | Redhat Quickstart Cloud Installer | 14/4/2017 | 17/6/2026 | The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display. | |
| Modificada | Alta (8.2) | 1.6% | — | Oracle Installed Base | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Installed Base component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base.… | |
| Modificada | Alta (8.4) | 0.39% | — | Redhat Quickstart Cloud Installer | 22/9/2016 | 17/6/2026 | The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack. | |
| Modificada | Alta (8.4) | 0.39% | — | Redhat Quickstart Cloud Installer | 22/9/2016 | 17/6/2026 | Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file. | |
| Modificada | Crítica (9.8) | 71% | 💥 Exploit | Netgear Readynas SurveillanceNuuo CrystalNuuo NvrsoloNuuo Nvrmini 2 | 31/8/2016 | 17/6/2026 | handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter. | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Transport Gateway Installation Software | 22/8/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug IDs CSCva40650 and CSCva40817. | |
| Modificada | Alta (7.8) | 0.39% | — | Pulsesecure Odyssey Access ClientPulsesecure Pulse Secure DesktopPulsesecure Pulse Secure SecurityPulsesecure Standalone Pulse Installer Service | 2/8/2016 | 17/6/2026 | Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors. | |
| Modificada | Media (4.7) | 2.0% | — | Oracle Installed Base | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Installed Base component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Engineering Change Order. NOTE: the previous information is from the July 2016 CPU. Oracle has not commented… | |
| Modificada | Media (5.7) | 1.8% | — | Oracle Siebel Engineering-installer AND Deployment | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Siebel Engineering - Installer and Deployment component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Web Server. | |
| Modificada | Alta (7.8) | 0.38% | — | Linecorp LineLinecorp Line Installer | 12/7/2016 | 17/6/2026 | Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.54% | — | Flexerasoftware Installanywhere | 2/7/2016 | 17/6/2026 | Untrusted search path vulnerability in Flexera InstallAnywhere allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file. | |
| Modificada | Alta (7.8) | 0.50% | — | Flexera Installshield | 24/2/2016 | 17/6/2026 | Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file. | |
| Modificada | Alta (7) | 0.42% | — | IBM Installation ManagerIBM Packaging Utility | 2/1/2016 | 17/6/2026 | consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value. | |
| Modificada | Baja (1.2) | 0.33% | — | IBM Installation ManagerIBM Rational Clearcase | 25/3/2015 | 17/6/2026 | IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation… | |
| Modificada | Alta (7.5) | 2.2% | — | Vastal Phpvid | 20/3/2015 | 17/6/2026 | SQL injection vulnerability in groups.php in Vastal I-Tech phpVID 0.9.9 and 1.2.3 allows remote attackers to execute arbitrary SQL commands via the order_by parameter. NOTE: The cat parameter vector is already covered by CVE-2008-4157. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer | 17/1/2015 | 17/6/2026 | IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.2) | 0.95% | — | Realnetworks Realarcade Installer | 12/1/2015 | 16/6/2026 | RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory tree, which allows local users to gain privileges via a Trojan horse DLL in an individual game's directory, as demonstrated by DDRAW.DLL in… | |
| Modificada | Alta (10) | 4.2% | — | Realnetworks Realarcade Installer | 12/1/2015 | 16/6/2026 | The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.481 performs unexpected type conversions for invalid parameter types, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted arguments to the… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Installatron Gatequest File Manager | 2/1/2015 | 17/6/2026 | SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to execute arbitrary SQL commands via the create parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks by creating a file that generates an error. NOTE: this issue was… | |
| Modificada | Media (5.4) | 0.27% | — | Trafficgate Rakuten Install | 4/10/2014 | 17/6/2026 | The Rakuten Install (aka co.jp.rakuten.installapp) application 1.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.2) | 0.39% | — | Juniper Installer Service ClientJuniper Junos Pulse Client | 29/9/2014 | 17/6/2026 | Juniper Installer Service (JIS) Client 7.x before 7.4R6 for Windows and Junos Pulse Client before 4.0R6 allows local users to gain privileges via unspecified vectors. |