Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.19% | — | Schneider-electric Easergy Builder Installer | 18/4/2023 | 17/6/2026 | A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected… | |
| Modificada | Media (5.5) | 0.25% | — | Redhat Openshift Assisted InstallerRedhat Openshift Container Platform | 24/3/2023 | 17/6/2026 | A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user. | |
| Modificada | Alta (7.5) | 0.66% | 💥 PoC | Modoboa Installer | 16/2/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4. | |
| Modificada | Alta (7.8) | 0.21% | — | Caphyon Advanced Installer | 8/2/2023 | 17/6/2026 | Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to access and manipulate system files. | |
| Modificada | Alta (7.8) | 0.18% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.8) | 1.2% | — | Rubyinstaller2 | 30/8/2022 | 17/6/2026 | Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory. | |
| Modificada | Alta (8.8) | 1.2% | — | Rubyinstaller2 | 30/8/2022 | 17/6/2026 | Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory. | |
| Modificada | Media (5.5) | 0.23% | — | Redhat Coreos-installer | 23/8/2022 | 17/6/2026 | A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Emcosoftware MSI Package BuilderEmcosoftware Network InventoryEmcosoftware Network Software ScannerEmcosoftware Ping Monitor+4 | 23/5/2022 | 9/7/2026 | Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows… | |
| Modificada | Media (5.5) | 0.20% | — | Lenovo Thin Installer | 22/4/2022 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash. | |
| Modificada | Alta (7.8) | 0.35% | — | Samsung Android USB Driver Windows Installer | 11/4/2022 | 17/6/2026 | Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.52% | — | Redhat Coreos-installer | 4/3/2022 | 17/6/2026 | An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary… | |
| Modificada | Alta (7.8) | 0.29% | — | Netgear Genie Installer | 30/12/2021 | 17/6/2026 | All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which the software is going to be installed may… | |
| Modificada | Alta (7.8) | 0.29% | — | Thalesgroup Sentinel Protection Installer | 20/12/2021 | 17/6/2026 | Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. | |
| Modificada | Media (6.7) | 0.22% | — | Thalesgroup Sentinel Protection Installer | 20/12/2021 | 17/6/2026 | Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. | |
| Analizada | Alta (7.1) | 10% | ⚠ Explotación activa | Microsoft APP Installer | 15/12/2021 | 6/8/2026 | We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a… | |
| Modificada | Media (5.4) | 0.60% | — | Tibco Webfocus ClientTibco Webfocus InstallerTibco Webfocus Reporting Server | 14/9/2021 | 17/6/2026 | The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a… | |
| Modificada | Alta (8.1) | 1.8% | — | Redhat Openshift Installer | 23/2/2021 | 17/6/2026 | A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during… | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7) | 0.28% | — | Schneider-electric Enterprise Server Installer | 19/11/2020 | 17/6/2026 | A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path,… | |
| Modificada | Alta (7.8) | 0.34% | — | Capasystems Capainstaller | 9/11/2020 | 17/6/2026 | CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts to edit registry values, allowing an attacker to escalate privileges. |