Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

444 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.45%—Avira Software Updater5/5/202017/6/2026
An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling file hard links. This allows local users to obtain take control of arbitrary files.
ModificadaCrítica (9.8)80%💥 ExploitHPE Smart Update Manager30/4/202017/6/2026
A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at…
ModificadaAlta (7.8)1.0%—Microsoft Autoupdate15/4/202017/6/2026
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'.
ModificadaAlta (7.5)0.59%—Lenovo System Update27/3/202017/6/2026
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed.
ModificadaAlta (7)0.23%—Lenovo System Update27/3/202017/6/2026
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code with elevated privileges.
ModificadaAlta (7.8)0.36%—Lenovo System Update27/3/202017/6/2026
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type COMMAND type could allow a user to execute arbitrary code…
ModificadaAlta (7.8)0.35%—Lenovo System Update27/3/202017/6/2026
MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a…
ModificadaCrítica (9.8)2.3%—Rbsoft Autoupdater.net23/3/202017/6/2026
AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE.
ModificadaCrítica (9.8)0.99%—Linuxfoundation THE Update Framework5/2/202017/6/2026
TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature.
ModificadaMedia (5.3)1.8%—Linuxfoundation THE Update Framework14/1/202017/6/2026
TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption.
ModificadaAlta (7.5)8.0%—Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+1519/12/201917/6/2026
cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl.
ModificadaMedia (5.5)0.32%—Dell Command Update3/12/201917/6/2026
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs…
ModificadaMedia (5.5)0.32%—Dell Command Update3/12/201917/6/2026
Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any…
ModificadaMedia (5.5)0.26%—Redhat Update Infrastructure4/11/201916/6/2026
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
AnalizadaAlta (7.5)8.8%—ISC DhcpdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+151/11/201917/6/2026
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC…
ModificadaMedia (6.7)0.40%—Avira Software Updater10/10/201917/6/2026
Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges
ModificadaAlta (7.8)1.3%—Microsoft Windows 10 Update Assistant10/10/201917/6/2026
An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege Vulnerability'.
ModificadaAlta (7.5)1.7%—Lenovo System Update26/9/201917/6/2026
A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations.
ModificadaMedia (6.7)0.46%—Dell Update Package Framework24/9/201917/6/2026
An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to 3.8.3.67 used in Dell Client Platforms.…
ModificadaMedia (4.4)0.51%—Systemd Project SystemdFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+104/9/201917/6/2026
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be…
ModificadaAlta (7.8)0.57%—Avira Free Security SuiteAvira Software Updater29/8/201917/6/2026
An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM…
ModificadaMedia (4.3)0.89%—Easyupdatesmanager Easy Updates Manager27/8/201917/6/2026
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
ModificadaMedia (6.1)1.4%💥 ExploitBestwebsoft Updater21/8/201917/6/2026
The updater plugin before 1.35 for WordPress has multiple XSS issues.
ModificadaCrítica (9.8)2.0%—Codeermeneer Companion Auto Update16/8/201917/6/2026
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.
ModificadaAlta (8.8)0.65%—Codeermeneer Companion Auto Update16/8/201917/6/2026
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
Orbitaley — Vulnerabilidades