Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.26% | — | Redhat Update Infrastructure | 4/11/2019 | 16/6/2026 | RHUI (Red Hat Update Infrastructure) 2.1.3 has world readable PKI entitlement certificates | |
| Analizada | Alta (7.5) | 8.8% | — | ISC DhcpdRedhat Enterprise LinuxRedhat Enterprise Linux DesktopRedhat Enterprise Linux EUS+15 | 1/11/2019 | 17/6/2026 | There had existed in one of the ISC BIND libraries a bug in a function that was used by dhcpd when operating in DHCPv6 mode. There was also a bug in dhcpd relating to the use of this function per its documentation, but the bug in the library function prevented this from causing any harm. All releases of dhcpd from ISC… | |
| Modificada | Media (6.7) | 0.40% | — | Avira Software Updater | 10/10/2019 | 17/6/2026 | Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges | |
| Modificada | Alta (7.8) | 1.3% | — | Microsoft Windows 10 Update Assistant | 10/10/2019 | 17/6/2026 | An elevation of privilege vulnerability exists in Windows 10 Update Assistant in the way it handles permissions.A locally authenticated attacker could run arbitrary code with elevated system privileges, aka 'Windows 10 Update Assistant Elevation of Privilege Vulnerability'. | |
| Modificada | Alta (7.5) | 1.7% | — | Lenovo System Update | 26/9/2019 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo System Update versions prior to 5.07.0088 that could allow configuration files to be written to non-standard locations. | |
| Modificada | Media (6.7) | 0.46% | — | Dell Update Package Framework | 24/9/2019 | 17/6/2026 | An Uncontrolled Search Path Vulnerability is applicable to the following: Dell Update Package (DUP) Framework file versions prior to 19.1.0.413, and Framework file versions prior to 103.4.6.69 used in Dell EMC Servers. Dell Update Package (DUP) Framework file versions prior to 3.8.3.67 used in Dell Client Platforms.… | |
| Modificada | Media (4.4) | 0.51% | — | Systemd Project SystemdFedoraproject FedoraRedhat Openshift Container PlatformRedhat Enterprise Linux+10 | 4/9/2019 | 17/6/2026 | In systemd 240, bus_open_system_watch_bind_with_description in shared/bus-util.c (as used by systemd-resolved to connect to the system D-Bus instance), calls sd_bus_set_trusted, which disables access controls for incoming D-Bus messages. An unprivileged user can exploit this by executing D-Bus methods that should be… | |
| Modificada | Alta (7.8) | 0.57% | — | Avira Free Security SuiteAvira Software Updater | 29/8/2019 | 17/6/2026 | An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM… | |
| Modificada | Media (4.3) | 0.89% | — | Easyupdatesmanager Easy Updates Manager | 27/8/2019 | 17/6/2026 | The stops-core-theme-and-plugin-updates plugin before 8.0.5 for WordPress has insufficient restrictions on option changes (such as disabling unattended theme updates) because of a nonce check error. | |
| Modificada | Media (6.1) | 1.4% | 💥 Exploit | Bestwebsoft Updater | 21/8/2019 | 17/6/2026 | The updater plugin before 1.35 for WordPress has multiple XSS issues. | |
| Modificada | Crítica (9.8) | 2.0% | — | Codeermeneer Companion Auto Update | 16/8/2019 | 17/6/2026 | The companion-auto-update plugin before 3.2.1 for WordPress has local file inclusion. | |
| Modificada | Alta (8.8) | 0.65% | — | Codeermeneer Companion Auto Update | 16/8/2019 | 17/6/2026 | The companion-auto-update plugin before 3.2.1 for WordPress has CSRF. | |
| Modificada | Alta (7.5) | 0.43% | — | Sony Vaio Update | 5/7/2019 | 17/6/2026 | Improper download file verification vulnerability in VAIO Update 7.3.0.03150 and earlier allows remote attackers to conduct a man-in-the-middle attack via a malicous wireless LAN access point. A successful exploitation may result in a malicious file being downloaded/executed. | |
| Modificada | Alta (7.8) | 0.94% | — | Sony Vaio Update | 5/7/2019 | 17/6/2026 | Improper authorization vulnerability in VAIO Update 7.3.0.03150 and earlier allows an attackers to execute arbitrary executable file with administrative privilege via unspecified vectors. | |
| Modificada | Alta (7.5) | 0.84% | — | Lenovo System Update | 26/6/2019 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo System Update before version 5.07.0084 that could allow service log files to be written to non-standard locations. | |
| Modificada | Crítica (9.8) | 1.4% | — | HPE Smart Update Manager | 5/6/2019 | 17/6/2026 | A Remote Unauthorized Access vulnerability was identified in HPE Smart Update Manager (SUM) earlier than version 8.3.5. | |
| Modificada | Alta (7.8) | 0.32% | — | HPE Smart Update Manager | 5/6/2019 | 17/6/2026 | A security vulnerability in HPE Smart Update Manager (SUM) prior to v8.4 could allow local unauthorized elevation of privilege. | |
| Modificada | Media (6.1) | 0.98% | — | Oracle Peoplesoft Enterprise Human Capital Management Candidate Gateway | 23/4/2019 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise HRMS component of Oracle PeopleSoft Products (subcomponent: Candidate Gateway). The supported version that is affected is 9.2. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise PeopleSoft Enterprise HRMS. Successful… | |
| Analizada | Alta (7.8) | 65% | ⚠ Explotación activa💥 Exploit | Apache Http ServerFedoraproject FedoraCanonical Ubuntu LinuxDebian Linux+23 | 8/4/2019 | 17/6/2026 | In Apache HTTP Server 2.4 releases 2.4.17 to 2.4.38, with MPM event, worker or prefork, code executing in less-privileged child processes or threads (including scripts executed by an in-process scripting interpreter) could execute arbitrary code with the privileges of the parent process (usually root) by manipulating… | |
| Modificada | Alta (8.8) | 1.3% | — | Jenkins Jira Issue Updater | 4/4/2019 | 17/6/2026 | Jenkins Jira Issue Updater Plugin stores credentials unencrypted in job config.xml files on the Jenkins master where they can be viewed by users with Extended Read permission, or access to the master file system. | |
| Modificada | Media (5.5) | 2.0% | — | Systemd Project SystemdOpensuse LeapNetapp Active IQ Performance Analytics ServicesDebian Linux+18 | 21/3/2019 | 17/6/2026 | An issue was discovered in sd-bus in systemd 239. bus_process_object() in libsystemd/sd-bus/bus-objects.c allocates a variable-length stack buffer for temporarily storing the object path of incoming D-Bus messages. An unprivileged local user can exploit this by sending a specially crafted message to PID1, causing the… | |
| Modificada | Baja (3.3) | 1.1% | — | Systemd Project SystemdDebian LinuxCanonical Ubuntu LinuxNetapp Active IQ Performance Analytics Services+17 | 11/1/2019 | 17/6/2026 | An out of bounds read was discovered in systemd-journald in the way it parses log messages that terminate with a colon ':'. A local attacker can use this flaw to disclose process memory data. Versions from v221 to v239 are vulnerable. | |
| Modificada | Alta (7.8) | 0.36% | — | Ntt-west Fall Creators Update | 9/1/2019 | 17/6/2026 | Untrusted search path vulnerability in The installer of Windows 10 Fall Creators Update Modify module for Security Measures tool allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 2.8% | — | Schneider-electric Software Update Utility | 2/11/2018 | 17/6/2026 | A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file. | |
| Modificada | Alta (7.5) | 0.99% | — | Dateme Project Dateme | 5/7/2018 | 17/6/2026 | The sell function of a smart contract implementation for DateMe (DMX) (Contract Name: ProgressiveToken), an Ethereum token, has an integer overflow in which "amount * sellPrice" can be zero, consequently reducing a seller's assets. |