Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

608 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.6)0.59%—HP Software Update29/9/201517/6/2026
Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors.
ModificadaMedia (4.3)0.95%—Drupaldise CMS Updater21/9/201517/6/2026
Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page.
ModificadaMedia (4.9)0.83%—Drupaldise CMS Updater21/9/201517/6/2026
The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission.
ModificadaMedia (6.9)1.6%💥 ExploitQemuLinux KernelArista EOSDebian Linux+1531/8/201517/6/2026
The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index.
ModificadaAlta (9.3)13%—XENFedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+2012/8/201517/6/2026
The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors.
ModificadaMedia (6.9)0.27%—Lenovo System Update12/5/201517/6/2026
Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated.
ModificadaAlta (8.3)0.40%—Lenovo System Update12/5/201517/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate.
ModificadaAlta (7.2)4.1%💥 ExploitLenovo System Update12/5/201517/6/2026
Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe.
ModificadaBaja (2.1)0.31%—IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer17/1/201517/6/2026
IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file.
ModificadaAlta (7.2)0.39%—HPE Smart Update Manager10/12/201417/6/2026
Unspecified vulnerability in HP Smart Update Manager 6.x before 6.4.1 on Windows, and 6.2.x through 6.4.x before 6.4.1 on Linux, allows local users to obtain sensitive information, and consequently gain privileges, via unknown vectors.
ModificadaMedia (6.8)2.4%💥 ExploitSkalfa Skadate LiteOxwall26/11/201417/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks or possibly have other unspecified impact via the (1)…
ModificadaMedia (4.6)0.46%—Estsoft Alupdate3/11/201417/6/2026
ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local users to gain privileges via a Trojan horse file.
ModificadaBaja (3.5)1.4%—Date Project Date20/10/201417/6/2026
Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users with the permission to create a date field to inject arbitrary web script or HTML via the date field title.
ModificadaMedia (5.4)0.27%—Nextgenupdate23/9/201417/6/2026
The NextGenUpdate (aka com.tapatalk.nextgenupdatecomforums) application 3.1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (4.3)1.6%—Yahoo! Updates FOR Wordpress Plugin Project Yahoo! Updates FOR Wordpress Plugin2/7/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter.
ModificadaMedia (4.3)1.6%—Validated Plugin Project Validated Plugin1/7/201417/6/2026
Cross-site scripting (XSS) vulnerability in check.php in the Validated plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter.
ModificadaAlta (7.6)3.6%—Justsystems IchitaroJustsystems Just Online Update16/6/201417/6/2026
JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature.
ModificadaMedia (6.8)3.2%💥 ExploitMail ON Update Project Mail ON Update23/5/201416/6/2026
Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change the "List of alternative recipients" via the mailonupdate_mailto parameter in the mail-on-update page to…
ModificadaMedia (6.4)2.3%—Canonical Update-managerCanonical Ubuntu Linux27/4/201416/6/2026
DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows…
ModificadaBaja (1.9)0.33%—Canonical Update-managerCanonical Ubuntu Linux17/4/201416/6/2026
DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a…
ModificadaAlta (7.5)1.4%—Symantec Liveupdate Administrator29/3/201417/6/2026
SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.5)2.7%—Symantec Liveupdate Administrator29/3/201417/6/2026
The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to reset arbitrary passwords by providing the e-mail address associated with a user account.
ModificadaAlta (7.2)0.64%—HP Smart Update Manager16/3/201417/6/2026
Unspecified vulnerability in HP Smart Update Manager 5.3.5 before build 70 on Linux allows local users to gain privileges via unknown vectors.
ModificadaAlta (9.3)2.9%—Schneider-electric Software Update Utility21/1/201316/6/2026
The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80.
ModificadaMedia (6)1.1%—Karen Stevenson Date20/9/201216/6/2026
SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors.
Orbitaley — Vulnerabilidades