Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
608 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (4.6) | 0.59% | — | HP Software Update | 29/9/2015 | 17/6/2026 | Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors. | |
| Modificada | Media (4.3) | 0.95% | — | Drupaldise CMS Updater | 21/9/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors involving the configuration page. | |
| Modificada | Media (4.9) | 0.83% | — | Drupaldise CMS Updater | 21/9/2015 | 17/6/2026 | The CMS Updater module 7.x-1.x before 7.x-1.3 for Drupal does not properly check access permissions, which allows remote authenticated users to access and change settings by leveraging the "access administration pages" permission. | |
| Modificada | Media (6.9) | 1.6% | 💥 Exploit | QemuLinux KernelArista EOSDebian Linux+15 | 31/8/2015 | 17/6/2026 | The pit_ioport_read in i8254.c in the Linux kernel before 2.6.33 and QEMU before 2.3.1 does not distinguish between read lengths and write lengths, which might allow guest OS users to execute arbitrary code on the host OS by triggering use of an invalid index. | |
| Modificada | Alta (9.3) | 13% | — | XENFedoraproject FedoraSuse Linux Enterprise DebuginfoSuse Linux Enterprise Server+20 | 12/8/2015 | 17/6/2026 | The C+ mode offload emulation in the RTL8139 network card device model in QEMU, as used in Xen 4.5.x and earlier, allows remote attackers to read process heap memory via unspecified vectors. | |
| Modificada | Media (6.9) | 0.27% | — | Lenovo System Update | 12/5/2015 | 17/6/2026 | Race condition in Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses world-writable permissions for the update files directory, which allows local users to gain privileges by writing to an update file after the signature is validated. | |
| Modificada | Alta (8.3) | 0.40% | — | Lenovo System Update | 12/5/2015 | 17/6/2026 | Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 does not properly validate CA chains during signature validation, which allows man-in-the-middle attackers to upload and execute arbitrary files via a crafted certificate. | |
| Modificada | Alta (7.2) | 4.1% | 💥 Exploit | Lenovo System Update | 12/5/2015 | 17/6/2026 | Lenovo System Update (formerly ThinkVantage System Update) before 5.06.0034 uses predictable security tokens, which allows local users to gain privileges by sending a valid token with a command to the System Update service (SUService.exe) through an unspecified named pipe. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer | 17/1/2015 | 17/6/2026 | IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.2) | 0.39% | — | HPE Smart Update Manager | 10/12/2014 | 17/6/2026 | Unspecified vulnerability in HP Smart Update Manager 6.x before 6.4.1 on Windows, and 6.2.x through 6.4.x before 6.4.1 on Linux, allows local users to obtain sensitive information, and consequently gain privileges, via unknown vectors. | |
| Modificada | Media (6.8) | 2.4% | 💥 Exploit | Skalfa Skadate LiteOxwall | 26/11/2014 | 17/6/2026 | Multiple cross-site request forgery (CSRF) vulnerabilities in Oxwall 1.7.0 (build 7907 and 7906) and SkaDate Lite 2.0 (build 7651) allow remote attackers to hijack the authentication of administrators for requests that conduct cross-site scripting (XSS) attacks or possibly have other unspecified impact via the (1)… | |
| Modificada | Media (4.6) | 0.46% | — | Estsoft Alupdate | 3/11/2014 | 17/6/2026 | ESTsoft ALUpdate 8.5.1.0.0 uses weak permissions (Users: Full Control) for the (1) AlUpdate folder and (2) AlUpdate.exe, which allows local users to gain privileges via a Trojan horse file. | |
| Modificada | Baja (3.5) | 1.4% | — | Date Project Date | 20/10/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Date module before 7.x-2.8 for Drupal allows remote authenticated users with the permission to create a date field to inject arbitrary web script or HTML via the date field title. | |
| Modificada | Media (5.4) | 0.27% | — | Nextgenupdate | 23/9/2014 | 17/6/2026 | The NextGenUpdate (aka com.tapatalk.nextgenupdatecomforums) application 3.1.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (4.3) | 1.6% | — | Yahoo! Updates FOR Wordpress Plugin Project Yahoo! Updates FOR Wordpress Plugin | 2/7/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in yupdates_application.php in the Yahoo! Updates for WordPress plugin 1.0 and earlier for WordPress allow remote attackers to inject arbitrary web script or HTML via the (1) secret, (2) key, or (3) appid parameter. | |
| Modificada | Media (4.3) | 1.6% | — | Validated Plugin Project Validated Plugin | 1/7/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in check.php in the Validated plugin 1.0.2 and earlier for WordPress allows remote attackers to inject arbitrary web script or HTML via the slug parameter. | |
| Modificada | Alta (7.6) | 3.6% | — | Justsystems IchitaroJustsystems Just Online Update | 16/6/2014 | 17/6/2026 | JustSystems JUST Online Update, as used in Ichitaro through 2014 and other products, does not properly validate signatures of update modules, which allows remote attackers to spoof modules and execute arbitrary code via a crafted signature. | |
| Modificada | Media (6.8) | 3.2% | 💥 Exploit | Mail ON Update Project Mail ON Update | 23/5/2014 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Mail On Update plugin before 5.2.0 for WordPress allows remote attackers to hijack the authentication of administrators for requests that change the "List of alternative recipients" via the mailonupdate_mailto parameter in the mail-on-update page to… | |
| Modificada | Media (6.4) | 2.3% | — | Canonical Update-managerCanonical Ubuntu Linux | 27/4/2014 | 16/6/2026 | DistUpgrade/DistUpgradeFetcherCore.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 on Ubuntu 8.04 through 11.10 does not verify the GPG signature before extracting an upgrade tarball, which allows… | |
| Modificada | Baja (1.9) | 0.33% | — | Canonical Update-managerCanonical Ubuntu Linux | 17/4/2014 | 16/6/2026 | DistUpgrade/DistUpgradeViewKDE.py in Update Manager before 1:0.87.31.1, 1:0.134.x before 1:0.134.11.1, 1:0.142.x before 1:0.142.23.1, 1:0.150.x before 1:0.150.5.1, and 1:0.152.x before 1:0.152.25.5 does not properly create temporary files, which allows local users to obtain the XAUTHORITY file content for a user via a… | |
| Modificada | Alta (7.5) | 1.4% | — | Symantec Liveupdate Administrator | 29/3/2014 | 17/6/2026 | SQL injection vulnerability in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.7% | — | Symantec Liveupdate Administrator | 29/3/2014 | 17/6/2026 | The forgotten-password feature in forcepasswd.do in the management GUI in Symantec LiveUpdate Administrator (LUA) 2.x before 2.3.2.110 allows remote attackers to reset arbitrary passwords by providing the e-mail address associated with a user account. | |
| Modificada | Alta (7.2) | 0.64% | — | HP Smart Update Manager | 16/3/2014 | 17/6/2026 | Unspecified vulnerability in HP Smart Update Manager 5.3.5 before build 70 on Linux allows local users to gain privileges via unknown vectors. | |
| Modificada | Alta (9.3) | 2.9% | — | Schneider-electric Software Update Utility | 21/1/2013 | 16/6/2026 | The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80. | |
| Modificada | Media (6) | 1.1% | — | Karen Stevenson Date | 20/9/2012 | 16/6/2026 | SQL injection vulnerability in the conversion form for Events in the Date module 6.x-2.x before 6.x-2.8 for Drupal allows remote authenticated users with the "administer Date Tools" privilege to execute arbitrary SQL commands via unspecified vectors. |