Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

444 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)2.2%—Microsoft Auto Updater FOR MAC20/12/201617/6/2026
Untrusted search path vulnerability in Microsoft Auto Updater for Mac allows local users to gain privileges via a Trojan horse executable file, aka "Microsoft (MAU) Office Elevation of Privilege Vulnerability."
ModificadaMedia (5.9)0.92%—Apple Software Update14/3/201617/6/2026
Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream.
ModificadaAlta (7.5)1.2%—Intel Driver Update Utility29/1/201617/6/2026
Intel Driver Update Utility before 2.4 retrieves driver updates in cleartext, which makes it easier for man-in-the-middle attackers to execute arbitrary code via a crafted file.
ModificadaMedia (4.6)0.59%—HP Software Update29/9/201517/6/2026
Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors.
ModificadaMedia (4.3)0.95%—Drupaldise CMS Updater21/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page.
ModificadaMedia (4.9)0.83%—Drupaldise CMS Updater21/9/201517/6/2026
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.
ModificadaMedia (6.9)1.6%💥 ExploitQemuLinux KernelArista EOSDebian Linux+1531/8/201517/6/2026
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
ModificadaAlta (9.3)13%—XENFedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+2012/8/201517/6/2026
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
ModificadaMedia (6.9)0.27%—Lenovo System Update12/5/201517/6/2026
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
ModificadaAlta (8.3)0.40%—Lenovo System Update12/5/201517/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.
ModificadaAlta (7.2)4.1%💥 ExploitLenovo System Update12/5/201517/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.
ModificadaBaja (2.1)0.31%—IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer17/1/201517/6/2026
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.
ModificadaAlta (7.2)0.39%—HPE Smart Update Manager10/12/201417/6/2026
Unspecified vulnerability in HP Smart Update Manager 6.x before 6.4.1 on Windows, and 6.2.x through 6.4.x before 6.4.1 on Linux, allows local users to obtain sensitive information, and consequently gain privileges, via unknown vectors.
ModificadaMedia (4.6)0.46%—Estsoft Alupdate3/11/201417/6/2026
ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local users to gain privileges via a Trojan horse file.
ModificadaMedia (5.4)0.27%—Nextgenupdate23/9/201417/6/2026
The NextGenUpdate (aka com.tapatalk.nextgenupdatecomforums) application 3.1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.6%—Yahoo! Updates FOR Wordpress Plugin Project Yahoo! Updates FOR Wordpress Plugin2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter.
ModificadaAlta (7.6)3.6%—Justsystems IchitaroJustsystems Just Online Update16/6/201417/6/2026
JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature.
ModificadaMedia (6.8)3.2%💥 ExploitMail ON Update Project Mail ON Update23/5/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change the "List of alternative recipients" via the mailonupdate_mailto parameter in the mail-on-update page to…
ModificadaMedia (6.4)2.3%—Canonical Update-managerCanonical Ubuntu Linux27/4/201416/6/2026
DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows…
ModificadaBaja (1.9)0.33%—Canonical Update-managerCanonical Ubuntu Linux17/4/201416/6/2026
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a…
ModificadaAlta (7.5)1.4%—Symantec Liveupdate Administrator29/3/201417/6/2026
SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)2.7%—Symantec Liveupdate Administrator29/3/201417/6/2026
The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to reset arbitrary passwords by providing the e-mail address associated with a user account.
ModificadaAlta (7.2)0.64%—HP Smart Update Manager16/3/201417/6/2026
Unspecified vulnerability in HP Smart Update Manager 5.3.5 before build 70 on Linux allows local users to gain privileges via unknown vectors.
ModificadaAlta (9.3)2.9%—Schneider-electric Software Update Utility21/1/201316/6/2026
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.
ModificadaMedia (6.8)0.64%—Miura Ubercart Bulk Stock Updater17/9/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in the Ubercart Bulk Stock Updater module for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors related to formAPI.
Orbitaley — Vulnerabilidades