Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7) | 0.22% | — | Lenovo System Update | 15/9/2020 | 17/6/2026 | A race condition vulnerability was reported in Lenovo System Update prior to version 5.07.0106 that could allow escalation of privilege. | |
| Modificada | Alta (8.2) | 0.67% | — | Linuxfoundation THE Update Framework | 9/9/2020 | 17/6/2026 | Python TUF (The Update Framework) reference implementation before version 0.12 it will incorrectly trust a previously downloaded root metadata file which failed verification at download time. This allows an attacker who is able to serve multiple new versions of root metadata (i.e. by a person-in-the-middle attack)… | |
| Modificada | Alta (7.5) | 89% | — | Apache Http ServerOracle Communications Element ManagerOracle Communications Session Report ManagerOracle Communications Session Route Manager+21 | 7/8/2020 | 17/6/2026 | Apache HTTP Server versions 2.4.20 to 2.4.43. A specially crafted value for the 'Cache-Digest' header in a HTTP/2 request would result in a crash when the server actually tries to HTTP/2 PUSH a resource afterwards. Configuring the HTTP/2 feature via "H2Push off" will mitigate this vulnerability for unpatched servers. | |
| Modificada | Alta (7.5) | 1.0% | — | Simpleledger Slp-validate | 30/7/2020 | 17/6/2026 | In SLP Validate (npm package slp-validate) before version 1.2.2, there is a vulnerability to false-positive validation outcomes for the NFT1 Child Genesis transaction type. A poorly implemented SLP wallet or opportunistic attacker could create a seemingly valid NFT1 child token without burning any of the NFT1 Group… | |
| Modificada | Media (4.7) | 0.93% | — | Schneider-electric Software Update Utility | 23/7/2020 | 17/6/2026 | A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering… | |
| Modificada | Alta (8.8) | 1.3% | — | Softwareupdate Project Softwareupdate | 23/7/2020 | 17/6/2026 | A SQL injection vulnerability in softwareupdate_controller.php in the Software Update module before 1.6 for MunkiReport allows attackers to execute arbitrary SQL commands via the last URL parameter of the /module/softwareupdate/get_tab_data/ endpoint. | |
| Modificada | Media (5.4) | 0.77% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 15/7/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS product of Oracle PeopleSoft (component: Time and Labor). The supported version that is affected is 9.2. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful attacks of this… | |
| Modificada | Media (6.6) | 0.55% | — | Splashtop Software UpdaterSplashtop Streamer | 21/5/2020 | 17/6/2026 | A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking.… | |
| Modificada | Alta (8.6) | 1.0% | — | Simpleledger Slp-validate | 12/5/2020 | 17/6/2026 | In SLP Validate (npm package slp-validate) before version 1.2.1, users could experience false-negative validation outcomes for MINT transaction operations. A poorly implemented SLP wallet could allow spending of the affected tokens which would result in the destruction of a user's minting baton. This has been fixed in… | |
| Modificada | Alta (7.8) | 0.45% | — | Avira Software Updater | 5/5/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling file hard links. This allows local users to obtain take control of arbitrary files. | |
| Modificada | Crítica (9.8) | 80% | 💥 Exploit | HPE Smart Update Manager | 30/4/2020 | 17/6/2026 | A security vulnerability in HPE Smart Update Manager (SUM) prior to version 8.5.6 could allow remote unauthorized access. Hewlett Packard Enterprise has provided a software update to resolve this vulnerability in HPE Smart Update Manager (SUM) prior to 8.5.6. Please visit the HPE Support Center at… | |
| Modificada | Alta (7.8) | 1.0% | — | Microsoft Autoupdate | 15/4/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'. | |
| Modificada | Media (6.1) | 1.0% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 15/4/2020 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS product of Oracle PeopleSoft (component: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful attacks require… | |
| Modificada | Media (5.4) | 0.71% | — | Contact-form-7-datepicker Project Contact-form-7-datepicker | 7/4/2020 | 17/6/2026 | Stored XSS in the Contact Form 7 Datepicker plugin through 2.6.0 for WordPress allows authenticated attackers with minimal permissions to save arbitrary JavaScript to the plugin's settings via the unprotected wp_ajax_cf7dp_save_settings AJAX action and the ui_theme parameter. If an administrator creates or modifies a… | |
| Modificada | Alta (7.5) | 0.59% | — | Lenovo System Update | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow the signature check of an update to be bypassed. | |
| Modificada | Alta (7) | 0.23% | — | Lenovo System Update | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A race condition was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior that could allow a user to execute arbitrary code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.36% | — | Lenovo System Update | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type COMMAND type could allow a user to execute arbitrary code… | |
| Modificada | Alta (7.8) | 0.35% | — | Lenovo System Update | 27/3/2020 | 17/6/2026 | MITRE is populating this ID because it was assigned prior to Lenovo becoming a CNA. A local privilege escalation vulnerability was reported (fixed and publicly disclosed in 2015) in Lenovo System Update version 5.07.0008 and prior where the SUService.exe /type INF and INF_BY_COMPATIBLE_ID command types could allow a… | |
| Modificada | Crítica (9.8) | 2.3% | — | Rbsoft Autoupdater.net | 23/3/2020 | 17/6/2026 | AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE. | |
| Modificada | Crítica (9.8) | 0.99% | — | Linuxfoundation THE Update Framework | 5/2/2020 | 17/6/2026 | TUF (aka The Update Framework) through 0.12.1 has Improper Verification of a Cryptographic Signature. | |
| Modificada | Media (5.3) | 1.8% | — | Linuxfoundation THE Update Framework | 14/1/2020 | 17/6/2026 | TUF (aka The Update Framework) 0.7.2 through 0.12.1 allows Uncontrolled Resource Consumption. | |
| Modificada | Alta (7.5) | 8.0% | — | Cyrusimap Cyrus-saslDebian LinuxCanonical Ubuntu LinuxFedoraproject Fedora+15 | 19/12/2019 | 17/6/2026 | cyrus-sasl (aka Cyrus SASL) 2.1.27 has an out-of-bounds write leading to unauthenticated remote denial-of-service in OpenLDAP via a malformed LDAP packet. The OpenLDAP crash is ultimately caused by an off-by-one error in _sasl_add_string in common.c in cyrus-sasl. | |
| Modificada | Media (5.5) | 0.32% | — | Dell Command Update | 3/12/2019 | 17/6/2026 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\IC\ICDebugLog.txt" to any targeted file. This issue occurs… | |
| Modificada | Media (5.5) | 0.32% | — | Dell Command Update | 3/12/2019 | 17/6/2026 | Dell Command Update versions prior to 3.1 contain an Arbitrary File Deletion Vulnerability. A local authenticated malicious user with low privileges potentially could exploit this vulnerability to delete arbitrary files by creating a symlink from the "Temp\ICProgress\Dell_InventoryCollector_Progress.xml" to any… | |
| Modificada | Media (6.1) | 0.99% | — | Simpleledger Slp-validate | 15/11/2019 | 17/6/2026 | A specially crafted Bitcoin script can cause a discrepancy between the specified SLP consensus rules and the validation result of the slp-validate@1.0.0 npm package. An attacker could create a specially crafted Bitcoin script in order to cause a hard-fork from the SLP consensus. All versions >1.0.0 have been patched. |