Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.8)0.18%—SapsetupAI14/1/202517/6/2026
Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high…
ModificadaAlta (8.8)0.92%💥 PoCAntonhoelstad WP Quick Setup18/11/202417/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0.
AplazadaAlta (8.8)1.9%—Pypa SetuptoolsAI15/7/202417/6/2026
A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these…
AplazadaMedia (5)0.15%—Motorola SetupAI3/5/202417/6/2026
A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information.
AplazadaAlta (8.8)0.64%—Coderevolution WP Setup WizardAI25/4/202417/6/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1.
ModificadaMedia (5.5)0.22%—Samsung Easysetup7/11/202317/6/2026
Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetooth address of user device.
ModificadaAlta (7.8)0.20%—Asus Armoury CrateSetupasusservices26/7/20239/7/2026
ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges.
ModificadaAlta (7.8)0.15%—Intel Setup AND Configuration Software10/5/202317/6/2026
Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.5)0.16%—Intel Setup AND Configuration Software10/5/202317/6/2026
Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access.
ModificadaMedia (6.7)0.18%—Sapsetup11/4/202317/6/2026
A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very same Windows PC. A successful attack depends on various preconditions beyond the attackers control.
ModificadaAlta (7)0.36%—Microsoft Azure Setup Kubectl6/3/202317/6/2026
Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows other actors on the Actions runner to replace the Kubectl binary created by this action because it is world writable. This Kubectl tool installer…
ModificadaAlta (7.5)0.52%—Oracle Isetup18/1/202317/6/2026
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSetup. Successful…
ModificadaMedia (5.9)2.5%—Python Setuptools23/12/202217/6/2026
Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py.
ModificadaMedia (4.3)0.31%—Cryptsetup Project Cryptsetup24/8/202217/6/2026
It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium.
ModificadaCrítica (9.3)1.3%—Setupbox Project Setupbox11/7/202217/6/2026
The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely.
RechazadaSin puntuar0.75%—Jrsoftware Inno Setup16/6/202230/9/2026
Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The sole source documents PE-format conformance defects in innosetup-5.5.9.exe with no exploit, attack path, or…
ModificadaAlta (8.8)1.2%—Schneider-electric Powerlogic ION Setup Firmware2/6/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior)
ModificadaCrítica (9.8)1.2%—Bettinivideo Sgsetup4/4/202217/6/2026
Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software.
ModificadaAlta (8.8)0.63%—Core Tweaks WP Setup Project Core Tweaks WP Setup28/2/202217/6/2026
The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create another admin account and takeover the…
ModificadaMedia (4.6)0.25%—Intel Active Management Technology Software Development KITIntel Setup AND Configuration SoftwareIntel Management Engine Bios ExtensionIntel Core I3 Firmware+1769/2/202217/6/2026
Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical…
ModificadaAlta (8.1)0.99%—Oracle Isetup22/4/202117/6/2026
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup.…
ModificadaAlta (7.5)0.23%—SAP Setup14/4/202117/6/2026
An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is performed when an executable file is registered. This could further lead to complete compromise of confidentiality, Integrity and Availability.
ModificadaMedia (5.3)1.5%—Zope Products.genericsetup9/3/202117/6/2026
Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSetup before version 2.1.1 there is an information disclosure vulnerability - anonymous visitors may view log and snapshot files generated by the Generic Setup Tool. The…
ModificadaAlta (7.8)0.88%—Epsonnet SetupmanagerEpson Offirio Synergyware Printdirector24/12/202017/6/2026
Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.2%—Cryptsetup Project CryptsetupRedhat Enterprise LinuxCanonical Ubuntu LinuxFedoraproject Fedora16/9/202017/6/2026
A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file 'lib/luks2/luks2_json_metadata.c' in function…
Orbitaley — Vulnerabilidades