Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.45% | — | Avira Software Updater | 5/5/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling file hard links. This allows local users to obtain take control of arbitrary files. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | HPE Smart Update Manager | 30/4/2020 | 17/6/2026 | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at… | |
| Modificada | Alta (7.8) | 1.0% | — | Microsoft Autoupdate | 15/4/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'. | |
| Modificada | Alta (7.5) | 0.59% | — | Lenovo System Update | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed. | |
| Modificada | Alta (7) | 0.23% | — | Lenovo System Update | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.36% | — | Lenovo System Update | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type COMMAND type could allow a user to execute arbitrary code… | |
| Modificada | Alta (7.8) | 0.35% | — | Lenovo System Update | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a… | |
| Modificada | Crítica (9.8) | 2.3% | — | Rbsoft Autoupdater.net | 23/3/2020 | 17/6/2026 | AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE. | |
| Modificada | Crítica (9.8) | 0.99% | — | Linuxfoundation THE Update Framework | 5/2/2020 | 17/6/2026 | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. | |
| Modificada | Media (5.3) | 1.8% | — | Linuxfoundation THE Update Framework | 14/1/2020 | 17/6/2026 | TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption. | |
| Modificada | Alta (7.5) | 8.0% | — | Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+15 | 19/12/2019 | 17/6/2026 | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl. | |
| Modificada | Media (5.5) | 0.32% | — | Dell Command Update | 3/12/2019 | 17/6/2026 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs… | |
| Modificada | Media (5.5) | 0.32% | — | Dell Command Update | 3/12/2019 | 17/6/2026 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any… | |
| Modificada | Media (5.5) | 0.26% | — | Redhat Update Infrastructure | 4/11/2019 | 16/6/2026 | RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates | |
| Analizada | Alta (7.5) | 8.8% | — | ISC DhcpdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+15 | 1/11/2019 | 17/6/2026 | There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC… | |
| Modificada | Media (6.7) | 0.40% | — | Avira Software Updater | 10/10/2019 | 17/6/2026 | Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft Windows 10 Update Assistant | 10/10/2019 | 17/6/2026 | An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege Vulnerability'. | |
| Modificada | Alta (7.5) | 1.7% | — | Lenovo System Update | 26/9/2019 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations. | |
| Modificada | Media (6.7) | 0.46% | — | Dell Update Package Framework | 24/9/2019 | 17/6/2026 | An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to 3.8.3.67 used in Dell Client Platforms.… | |
| Modificada | Media (4.4) | 0.51% | — | Systemd Project SystemdFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 4/9/2019 | 17/6/2026 | In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be… | |
| Modificada | Alta (7.8) | 0.57% | — | Avira Free Security SuiteAvira Software Updater | 29/8/2019 | 17/6/2026 | An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM… | |
| Modificada | Media (4.3) | 0.89% | — | Easyupdatesmanager Easy Updates Manager | 27/8/2019 | 17/6/2026 | The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Bestwebsoft Updater | 21/8/2019 | 17/6/2026 | The updater plugin before 1.35 for WordPress has multiple XSS issues. | |
| Modificada | Crítica (9.8) | 2.0% | — | Codeermeneer Companion Auto Update | 16/8/2019 | 17/6/2026 | The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion. | |
| Modificada | Alta (8.8) | 0.65% | — | Codeermeneer Companion Auto Update | 16/8/2019 | 17/6/2026 | The companion-auto-update plugin before 3.2.1 for WordPress has CSRF. |