Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.5)0.26%—Redhat Update Infrastructure4/11/201916/6/2026
RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates
AnalizadaAlta (7.5)8.8%—ISC DhcpdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+151/11/201917/6/2026
There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC…
ModificadaMedia (6.7)0.40%—Avira Software Updater10/10/201917/6/2026
Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges
ModificadaAlta (7.8)1.3%—Microsoft Windows 10 Update Assistant10/10/201917/6/2026
An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege Vulnerability'.
ModificadaAlta (7.5)1.7%—Lenovo System Update26/9/201917/6/2026
A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations.
ModificadaMedia (6.7)0.46%—Dell Update Package Framework24/9/201917/6/2026
An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to 3.8.3.67 used in Dell Client Platforms.…
ModificadaMedia (4.4)0.51%—Systemd Project SystemdFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+104/9/201917/6/2026
In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be…
ModificadaAlta (7.8)0.57%—Avira Free Security SuiteAvira Software Updater29/8/201917/6/2026
An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM…
ModificadaMedia (4.3)0.89%—Easyupdatesmanager Easy Updates Manager27/8/201917/6/2026
The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error.
ModificadaMedia (6.1)1.4%💥 ExploitBestwebsoft Updater21/8/201917/6/2026
The updater plugin before 1.35 for WordPress has multiple XSS issues.
ModificadaCrítica (9.8)2.0%—Codeermeneer Companion Auto Update16/8/201917/6/2026
The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion.
ModificadaAlta (8.8)0.65%—Codeermeneer Companion Auto Update16/8/201917/6/2026
The companion-auto-update plugin before 3.2.1 for WordPress has CSRF.
ModificadaAlta (7.5)0.43%—Sony Vaio Update5/7/201917/6/2026
Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point. A successful exploitation may result in a malicious file being downloaded/executed.
ModificadaAlta (7.8)0.94%—Sony Vaio Update5/7/201917/6/2026
Improper authorization vulnerability in VAIO Update 7.3.0.03150 and earlier allows an attackers to execute arbitrary executable file with administrative privilege via unspecified vectors.
ModificadaAlta (7.5)0.84%—Lenovo System Update26/6/201917/6/2026
A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to non-standard locations.
ModificadaCrítica (9.8)1.4%—HPE Smart Update Manager5/6/201917/6/2026
A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5.
ModificadaAlta (7.8)0.32%—HPE Smart Update Manager5/6/201917/6/2026
A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of privilege.
ModificadaMedia (6.1)0.98%—Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway23/4/201917/6/2026
Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful…
AnalizadaAlta (7.8)65%⚠ Explotación activa💥 ExploitApache Http ServerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+238/4/201917/6/2026
In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating…
ModificadaAlta (8.8)1.3%—Jenkins Jira Issue Updater4/4/201917/6/2026
Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system.
ModificadaMedia (5.5)2.0%—Systemd Project SystemdOpensuse LeapNetapp Active IQ Performance Analytics ServicesDebian Linux+1821/3/201917/6/2026
An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the…
ModificadaBaja (3.3)1.1%—Systemd Project SystemdDebian LinuxCanonical Ubuntu LinuxNetapp Active IQ Performance Analytics Services+1711/1/201917/6/2026
An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable.
ModificadaAlta (7.8)0.36%—Ntt-west Fall Creators Update9/1/201917/6/2026
Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measures tool allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)2.8%—Schneider-electric Software Update Utility2/11/201817/6/2026
A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file.
ModificadaAlta (7.5)0.99%—Dateme Project Dateme5/7/201817/6/2026
The sell function of a smart contract implementation for DateMe (DMX) (Contract Name: ProgressiveToken), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets.
Orbitaley — Vulnerabilidades