Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.18% | — | SapsetupAI | 14/1/2025 | 17/6/2026 | Due to DLL injection vulnerability in SAPSetup, an attacker with either local user privileges or with access to a compromised corporate user�s Windows account could gain higher privileges. With this, he could move laterally within the network and further compromise the active directory of a company. This leads to high… | |
| Modificada | Alta (8.8) | 0.92% | 💥 PoC | Antonhoelstad WP Quick Setup | 18/11/2024 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in AntonHoelstad WP Quick Setup wp-quick-setup allows Upload a Web Shell to a Web Server.This issue affects WP Quick Setup: from n/a through <= 2.0. | |
| Aplazada | Alta (8.8) | 1.9% | — | Pypa SetuptoolsAI | 15/7/2024 | 17/6/2026 | A vulnerability in the package_index module of pypa/setuptools versions up to 69.1.1 allows for remote code execution via its download functions. These functions, which are used to download packages from URLs provided by users or retrieved from package index servers, are susceptible to code injection. If these… | |
| Aplazada | Media (5) | 0.15% | — | Motorola SetupAI | 3/5/2024 | 17/6/2026 | A an improper export vulnerability was reported in the Motorola Setup application that could allow a local attacker to read sensitive user information. | |
| Aplazada | Alta (8.8) | 0.64% | — | Coderevolution WP Setup WizardAI | 25/4/2024 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in CodeRevolution WP Setup Wizard.This issue affects WP Setup Wizard: from n/a through 1.0.8.1. | |
| Modificada | Media (5.5) | 0.22% | — | Samsung Easysetup | 7/11/2023 | 17/6/2026 | Use of implicit intent for sensitive communication vulnerability in EasySetup prior to version 11.1.13 allows attackers to get the bluetooth address of user device. | |
| Modificada | Alta (7.8) | 0.20% | — | Asus Armoury CrateSetupasusservices | 26/7/2023 | 9/7/2026 | ASUS SetupAsusServices v1.0.5.1 in Asus Armoury Crate v5.3.4.0 contains an unquoted service path vulnerability which allows local users to launch processes with elevated privileges. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Setup AND Configuration Software | 10/5/2023 | 17/6/2026 | Incorrect default permissions in the Intel(R) SCS Add-on software installer for Microsoft SCCM all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.5) | 0.16% | — | Intel Setup AND Configuration Software | 10/5/2023 | 17/6/2026 | Improper authorization in the Intel(R) SCS software all versions may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Sapsetup | 11/4/2023 | 17/6/2026 | A Windows user with basic user authorization can exploit a DLL hijacking attack in SapSetup (Software Installation Program) - version 9.0, resulting in a privilege escalation running code as administrator of the very same Windows PC. A successful attack depends on various preconditions beyond the attackers control. | |
| Modificada | Alta (7) | 0.36% | — | Microsoft Azure Setup Kubectl | 6/3/2023 | 17/6/2026 | Azure/setup-kubectl is a GitHub Action for installing Kubectl. This vulnerability only impacts versions before version 3. An insecure temporary creation of a file allows other actors on the Actions runner to replace the Kubectl binary created by this action because it is world writable. This Kubectl tool installer… | |
| Modificada | Alta (7.5) | 0.52% | — | Oracle Isetup | 18/1/2023 | 17/6/2026 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.12. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle iSetup. Successful… | |
| Modificada | Media (5.9) | 2.5% | — | Python Setuptools | 23/12/2022 | 17/6/2026 | Python Packaging Authority (PyPA) setuptools before 65.5.1 allows remote attackers to cause a denial of service via HTML in a crafted package or custom PackageIndex page. There is a Regular Expression Denial of Service (ReDoS) in package_index.py. | |
| Modificada | Media (4.3) | 0.31% | — | Cryptsetup Project Cryptsetup | 24/8/2022 | 17/6/2026 | It was found that a specially crafted LUKS header could trick cryptsetup into disabling encryption during the recovery of the device. An attacker with physical access to the medium, such as a flash disk, could use this flaw to force a user into permanently disabling the encryption layer of that medium. | |
| Modificada | Crítica (9.3) | 1.3% | — | Setupbox Project Setupbox | 11/7/2022 | 17/6/2026 | The maxtortime/SetupBox repository through 1.0 on GitHub allows absolute path traversal because the Flask send_file function is used unsafely. | |
| Rechazada | Sin puntuar | 0.75% | — | Jrsoftware Inno Setup | 16/6/2022 | 30/9/2026 | Rejected reason: ** REJECT ** DO NOT USE THIS CANDIDATE NUMBER. ConsultIDs: none. Reason: This candidate was withdrawn by its CNA. Further investigation showed that it was not a security issue. Notes: The sole source documents PE-format conformance defects in innosetup-5.5.9.exe with no exploit, attack path, or… | |
| Modificada | Alta (8.8) | 1.2% | — | Schneider-electric Powerlogic ION Setup Firmware | 2/6/2022 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists that could cause potential remote code execution when an attacker is able to intercept and modify a request on the same network or has configuration access to an ION device on the network. Affected Products: Wiser Smart, EER21000 & EER21001 (V4.5 and prior) | |
| Modificada | Crítica (9.8) | 1.2% | — | Bettinivideo Sgsetup | 4/4/2022 | 17/6/2026 | Bettini Srl GAMS Product Line v4.3.0 was discovered to re-use static SSH keys across installations, allowing unauthenticated attackers to login as root users via extracting a key from the software. | |
| Modificada | Alta (8.8) | 0.63% | — | Core Tweaks WP Setup Project Core Tweaks WP Setup | 28/2/2022 | 17/6/2026 | The Core Tweaks WP Setup WordPress plugin through 4.1 allows to bulk-set many settings in WordPress, including the admin email, as well as creating a new admin account. There is no CSRF protection in place, allowing an attacker to arbitrary change the admin email or create another admin account and takeover the… | |
| Modificada | Media (4.6) | 0.25% | — | Intel Active Management Technology Software Development KITIntel Setup AND Configuration SoftwareIntel Management Engine Bios ExtensionIntel Core I3 Firmware+176 | 9/2/2022 | 17/6/2026 | Insufficiently protected credentials in USB provisioning for Intel(R) AMT SDK before version 16.0.3, Intel(R) SCS before version 12.2 and Intel(R) MEBx before versions 11.0.0.0012, 12.0.0.0011, 14.0.0.0004 and 15.0.0.0004 may allow an unauthenticated user to potentially enable information disclosure via physical… | |
| Modificada | Alta (8.1) | 0.99% | — | Oracle Isetup | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.1.3 and 12.2.3-12.2.10. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup.… | |
| Modificada | Alta (7.5) | 0.23% | — | SAP Setup | 14/4/2021 | 17/6/2026 | An unquoted service path in SAPSetup, version - 9.0, could lead to privilege escalation during the installation process that is performed when an executable file is registered. This could further lead to complete compromise of confidentiality, Integrity and Availability. | |
| Modificada | Media (5.3) | 1.5% | — | Zope Products.genericsetup | 9/3/2021 | 17/6/2026 | Products.GenericSetup is a mini-framework for expressing the configured state of a Zope Site as a set of filesystem artifacts. In Products.GenericSetup before version 2.1.1 there is an information disclosure vulnerability - anonymous visitors may view log and snapshot files generated by the Generic Setup Tool. The… | |
| Modificada | Alta (7.8) | 0.88% | — | Epsonnet SetupmanagerEpson Offirio Synergyware Printdirector | 24/12/2020 | 17/6/2026 | Untrusted search path vulnerability in self-extracting files created by EpsonNet SetupManager versions 2.2.14 and earlier, and Offirio SynergyWare PrintDirector versions 1.6x/1.6y and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.2% | — | Cryptsetup Project CryptsetupRedhat Enterprise LinuxCanonical Ubuntu LinuxFedoraproject Fedora | 16/9/2020 | 17/6/2026 | A vulnerability was found in upstream release cryptsetup-2.2.0 where, there's a bug in LUKS2 format validation code, that is effectively invoked on every device/image presenting itself as LUKS2 container. The bug is in segments validation code in file 'lib/luks2/luks2_json_metadata.c' in function… |