Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.24% | — | Nullsoft Scriptable Install System | 24/4/2026 | 17/6/2026 | NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references). | |
| Analizada | Alta (8.4) | 0.18% | — | Liveon Canonnwcamplugin.exeLiveon Canonnwcampluginforadmin.exeLiveon Downloader5installer.exeLiveon Downloader5installerforadmin.exe | 23/4/2026 | 17/6/2026 | The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at the same directory,… | |
| Analizada | Alta (8.6) | 0.31% | — | Adobe Photoshop Installer | 15/4/2026 | 29/7/2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation… | |
| Aplazada | Media (5.4) | 0.24% | — | Mikado-themes StalAI | 25/3/2026 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Mikado-Themes Stål stal allows Object Injection.This issue affects Stål: from n/a through < 1.7. | |
| Analizada | Alta (8.1) | 0.40% | — | Postalserver Postal | 12/3/2026 | 17/6/2026 | Postal is an open source SMTP server. Postal versions less than 3.3.5 had a HTML injection vulnerability that allowed unescaped data to be included in the admin interface. The primary way for unescaped data to be added is via the API's "send/raw" method. This could allow arbitrary HTML to be injected in to the page… | |
| Pendiente de análisis | Alta (8.8) | 0.13% | — | Microsoft Directx End-user Runtime WEB InstallerAI | 11/3/2026 | 17/6/2026 | In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process, which may result in unintended elevation of privileges. During installation, the installer runs with HIGH integrity and downloads executables and DLLs to the %TEMP%… | |
| Analizada | Media (6.6) | 0.24% | 💥 PoC | Grahampugh Erase-install | 4/3/2026 | 17/6/2026 | erase-install prior to v40.4 commit 2c31239 writes swiftDialog credential output to a hardcoded path /var/tmp/dialog.json. This allows an unauthenticated attacker to intercept admin credentials entered during reinstall/erase operations via creating a named pipe. | |
| Analizada | Media (6.5) | 0.46% | — | Stalwart | 19/2/2026 | 17/6/2026 | Stalwart is a mail and collaboration server. A denial-of-service vulnerability exists in Stalwart Mail Server versions 0.13.0 through 0.15.4 where accessing a specially crafted email containing malformed nested `message/rfc822` MIME parts via IMAP or JMAP causes excessive CPU and memory consumption, potentially… | |
| Aplazada | Alta (7.8) | 0.13% | — | Epson Printer Driver InstallerAI | 19/2/2026 | 17/6/2026 | The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorization model, exposing… | |
| Aplazada | Alta (8.7) | 0.80% | — | Crystal Live Http ServerAI | 18/2/2026 | 17/6/2026 | Crystal Live HTTP Server 6.01 contains a directory traversal vulnerability that allows remote attackers to access system files by manipulating URL path segments. Attackers can use multiple '../' sequences to navigate outside the web root and retrieve sensitive configuration files like Windows system files. | |
| Aplazada | Alta (7.8) | 0.14% | — | AMD Software InstallerAI | 11/2/2026 | 17/6/2026 | A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Aplazada | Media (6.9) | 0.60% | — | Crystal Shard Http-protectionAI | 30/1/2026 | 17/6/2026 | Crystal Shard http-protection 0.2.0 contains an IP spoofing vulnerability that allows attackers to bypass protection middleware by manipulating request headers. Attackers can hardcode consistent IP values across X-Forwarded-For, X-Client-IP, and X-Real-IP headers to circumvent security checks and gain unauthorized… | |
| Aplazada | Alta (8.5) | 0.20% | — | Wondershare Driver Install ServiceAI | 27/1/2026 | 17/6/2026 | Wondershare Driver Install Service contains an unquoted service path vulnerability in the ElevationService executable that allows local attackers to potentially inject malicious code. Attackers can exploit the unquoted path to replace the service binary with a malicious executable, enabling privilege escalation to… | |
| Aplazada | Alta (8.5) | 0.17% | — | Iobit UninstallerAI | 26/1/2026 | 17/6/2026 | IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during… | |
| Aplazada | Alta (8.5) | 0.17% | — | HTC IptinstallerAI | 25/1/2026 | 17/6/2026 | HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges. | |
| Aplazada | Media (4.4) | 0.28% | — | PostaliciousAI | 24/1/2026 | 17/6/2026 | The Postalicious plugin for WordPress is vulnerable to Stored Cross-Site Scripting via admin settings in all versions up to, and including, 3.0.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level permissions and above, to inject… | |
| Aplazada | Alta (8.5) | 0.18% | — | Pioneer Corporation InstallerAI | 8/1/2026 | 17/6/2026 | The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running installer. | |
| Modificada | Alta (8.1) | 0.53% | — | Axiomthemes Stallion | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Stallion stallion allows PHP Local File Inclusion.This issue affects Stallion: from n/a through <= 1.17. | |
| Analizada | Media (6.2) | 0.19% | — | Plugin-alliance Installation Manager | 3/12/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 on macOS. Due to the absence of a hardened runtime and a __RESTRICT segment, a local user may exploit the DYLD_INSERT_LIBRARIES environment variable to inject a… | |
| Analizada | Media (6.2) | 0.21% | — | Plugin-alliance Installation Manager | 3/12/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges. | |
| Analizada | Baja (3.5) | 0.11% | — | Freebox V5 HD FirmwareFreebox V5 Crystal FirmwareFreebox V6 Revolution FirmwareFreebox Mini 4K Firmware+1 | 17/11/2025 | 17/6/2026 | Freebox v5 HD (firmware = 1.7.20), Freebox v5 Crystal (firmware = 1.7.20), Freebox v6 Révolution r1–r3 (firmware = 4.7.x), Freebox Mini 4K (firmware = 4.7.x), and Freebox One (firmware = 4.7.x) were discovered to expose subscribers' IMSI identifiers in plaintext during the initial phase of EAP-SIM authentication over… | |
| Aplazada | Media (5.6) | 0.15% | — | Revenera InstallshieldAI | 7/11/2025 | 17/6/2026 | Potential Denial of Service issue in all supported versions of Revenera InstallShield version 2025 R1, 2024 R2, 2023 R2, and prior. When e.g., a local administrator performs an uninstall, a symlink may get followed on removal of a user writeable configuration directory and induce a Denial of Service as a result. The… | |
| Analizada | Alta (7.8) | 0.15% | — | Autodesk Installer | 6/11/2025 | 17/6/2026 | A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM. | |
| Aplazada | Alta (7.3) | 0.13% | — | Revenera InstallshieldAI | 29/10/2025 | 1/10/2026 | Potential privilege escalation issue in Revenera InstallShield version 2023 R1 running a renamed Setup.exe on Windows. When a local administrator executes a renamed Setup.exe, the MPR.dll may get loaded from an insecure location and can result in a privilege escalation. The issue has been fixed in versions 2023 R2 and… | |
| Aplazada | Alta (7.5) | 0.56% | — | StalwartAI | 2/10/2025 | 17/6/2026 | Stalwart is a mail and collaboration server. Versions 0.13.3 and below contain an unbounded memory allocation vulnerability in the IMAP protocol parser which allows remote attackers to exhaust server memory, potentially triggering the system's out-of-memory (OOM) killer and causing a denial of service. The… |