Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
–

243 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.14%—AMD Software InstallerAI11/2/202617/6/2026
A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution.
AplazadaAlta (8.5)0.20%—Wondershare Driver Install ServiceAI27/1/202617/6/2026
Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to…
AplazadaAlta (8.5)0.17%—Iobit UninstallerAI26/1/202617/6/2026
IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during…
AplazadaAlta (8.5)0.17%—HTC IptinstallerAI25/1/202617/6/2026
HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges.
AplazadaAlta (8.5)0.18%—Pioneer Corporation InstallerAI8/1/202617/6/2026
The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running installer.
AnalizadaMedia (6.2)0.19%—Plugin-alliance Installation Manager3/12/202517/6/2026
A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 on macOS. Due to the absence of a hardened runtime and a __RESTRICT segment, a local user may exploit the DYLD_INSERT_LIBRARIES environment variable to inject a…
AnalizadaMedia (6.2)0.21%—Plugin-alliance Installation Manager3/12/202517/6/2026
A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges.
AplazadaMedia (5.6)0.15%—Revenera InstallshieldAI7/11/202517/6/2026
Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and induce a Denial of Service as a result. The…
AnalizadaAlta (7.8)0.15%—Autodesk Installer6/11/202517/6/2026
A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM.
AplazadaAlta (7.3)0.13%—Revenera InstallshieldAI29/10/20251/10/2026
Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. When a local administrator executes a renamed Setup.exe, the MPR.dll may get loaded from an insecure location and can result in a privilege escalation. The issue has been fixed in versions 2023 R2 and…
AplazadaAlta (7.8)0.15%—Nvidia Installer FOR Nvapp FOR WindowsAINvidia Frameview SDKAI1/10/202517/6/2026
NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in the Frameview SDK directory. A successful exploit of this vulnerability might lead to escalation of privileges.
AplazadaAlta (7)0.13%—PyinstallerAI9/9/202517/6/2026
PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during the bootstrap process of a PyInstaller-frozen application, and due to the bootstrap script attempting to load an optional module for bytecode decryption while this entry…
AplazadaAlta (7)0.10%—Nvidia RUN InstallerAI2/8/202517/6/2026
NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering.
AplazadaAlta (7.8)0.17%—Nvidia Installer FOR WindowsAI2/8/202517/6/2026
NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful exploit of this vulnerability may lead to escalation of privileges, denial of service, code execution, information disclosure and data tampering.
AnalizadaAlta (7.5)4.5%⚠ Explotación activaEslint-config-prettierEslint-plugin-prettierUn-ts SynckitUn-ts Pkgr/core+319/7/202517/6/2026
eslint-config-prettier 8.10.1, 9.1.1, 10.1.6, and 10.1.7 has embedded malicious code for a supply chain compromise. Installing an affected package executes an install.js file that launches the node-gyp.dll malware on Windows.
AplazadaAlta (7.5)0.50%—Caphyon Advanced InstallerAI8/7/202517/6/2026
Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation vulnerability. When running as SYSTEM in certain configurations, Advanced Installer looks in standard-user writable locations for non-existent binaries and executes them as SYSTEM. A low-privileged attacker can place a…
AplazadaAlta (7.3)0.14%—InstallshieldAI12/6/202517/6/2026
A potential elevated privilege issue has been reported with InstallShield built Standalone MSI setups having multiple InstallScript custom actions configured. All supported versions (InstallShield 2023 R2, InstallShield 2022 R2 and InstallShield 2021 R2) are affected by this issue.
AplazadaMedia (6.9)0.13%—UpdatenaviAIUpdatenaviinstallserviceAI12/6/202517/6/2026
Improper restriction of communication channel to intended endpoints issue exists in UpdateNavi V1.4 L10 to L33 and UpdateNaviInstallService Service 1.2.0091 to 1.2.0125. If a local authenticated attacker send malicious data, an arbitrary registry value may be modified or arbitrary code may be executed.
AnalizadaAlta (7.8)0.21%—Autodesk Installer10/6/202517/6/2026
A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution.
AplazadaMedia (6.9)0.23%—Lantronix Device InstallerAI22/5/202517/6/2026
Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or…
AplazadaMedia (6.1)0.15%—PackageinstallercnAI7/5/202517/6/2026
Improper handling of insufficient permission in PackageInstallerCN prior to version 15.0.11.0 allows local attacker to bypass user interaction for requested installation.
AplazadaAlta (8.1)0.20%—Nullsoft Scriptable Install SystemAI17/4/202517/6/2026
Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because…
AplazadaMedia (5.4)0.20%—Intel Chipset Software Installation UtilityAI12/2/202517/6/2026
Uncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.4)0.17%—Intel DSA InstallerAI12/2/202517/6/2026
Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (5.3)0.17%—Intel ME Driver Pack InstallerAI12/2/202517/6/2026
Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access.