Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.19% | — | LG IpsfullhdLG UltrawideLgpcsuite SetupLG Ultra HD Driver Setup | 14/9/2020 | 17/6/2026 | A vulnerability that can hijack a DLL file that is loaded during products(LGPCSuite_Setup, IPSFULLHD, LG_ULTRAWIDE, ULTRA_HD_Driver Setup) installation into a DLL file that the hacker wants. Missing Support for Integrity Check vulnerability in ____COMPONENT____ of LG Electronics (LGPCSuite_Setup), (IPSFULLHD,… | |
| Modificada | Alta (8.2) | 0.41% | — | Getcomposer Composer-setup | 14/8/2020 | 17/6/2026 | In Composer-Setup for Windows before version 6.0.0, if the developer's computer is shared with other users, a local attacker may be able to exploit the following scenarios. 1. A local regular user may modify the existing `C:\ProgramData\ComposerSetup\bin\composer.bat` in order to get elevated command execution when… | |
| Modificada | Alta (7.8) | 0.45% | — | Westerndigital Sandiskssddashboardsetup.exeWesterndigitalssddashboardsetup.exe | 19/2/2020 | 17/6/2026 | Western Digital WesternDigitalSSDDashboardSetup.exe before 3.0.2.0 allows DLL Hijacking. | |
| Modificada | Alta (7.8) | 0.29% | — | Intel Setup AND Configuration Software Platform Discovery Utility | 16/12/2019 | 17/6/2026 | Improper permissions in the installer for the Intel(R) SCS Platform Discovery Utility, all versions, may allow an authenticated user to potentially enable escalation of privilege via local attack. | |
| Modificada | Alta (7.5) | 6.7% | — | Sennheiser HeadsetupMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+5 | 9/11/2018 | 17/6/2026 | Sennheiser HeadSetup 7.3.4903 places Certification Authority (CA) certificates into the Trusted Root CA store of the local system, and publishes the private key in the SennComCCKey.pem file within the public software distribution, which allows remote attackers to spoof arbitrary web sites or software publishers for… | |
| Modificada | Crítica (9.8) | 49% | 💥 Exploit | Trivum Webtouch Setup V9 Firmware | 17/7/2018 | 17/6/2026 | Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allow unauthorized remote attackers to reset the authentication via the "/xml/system/setAttribute.xml" URL, using the GET request "?id=0&attr=protectAccess&newValue=0" (a successful attack will allow attackers to login without… | |
| Modificada | Crítica (9.8) | 2.3% | — | Trivum Webtouch Setup V9 Firmware | 17/7/2018 | 17/6/2026 | Touchpad / Trivum WebTouch Setup V9 V2.53 build 13163 of Apr 6 2018 09:10:14 (FW 303) allows unauthorized remote attackers to reboot or execute other functions via the "/xml/system/control.xml" URL, using the GET request "?action=reboot" for example. | |
| Modificada | Media (5.3) | 0.32% | — | Redhat SetupRedhat Enterprise Linux DesktopRedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation | 3/7/2018 | 17/6/2026 | setup before version 2.11.4-1.fc28 in Fedora and Red Hat Enterprise Linux added /sbin/nologin and /usr/sbin/nologin to /etc/shells. This violates security assumptions made by pam_shells and some daemons which allow access based on a user's shell being listed in /etc/shells. Under some circumstances, users which had… | |
| Modificada | Alta (7.8) | 1.1% | — | Ntt-east Flet's Virus Clear Easy Setup & Application ToolNtt-east Flet's Virus Clear V6 Easy Setup & Application Tool | 26/6/2018 | 17/6/2026 | Untrusted search path vulnerability in the installer of FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.13.0 and earlier versions and FLET'S VIRUS CLEAR v6 Easy Setup & Application Tool ver.13.0 and earlier versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.91% | — | Ntt-east Flet's Virus Clear Easy Setup & Application ToolNtt-east Flet's Virus Clear V6 Easy Setup & Application Tool | 26/1/2018 | 17/6/2026 | Untrusted search path vulnerability in FLET'S VIRUS CLEAR Easy Setup & Application Tool ver.11 and earlier versions, FLET'S VIRUS CLEAR v6 Easy Setup & Application Tool ver.11 and earlier versions allow an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.41% | — | Ovirt-hosted-engine-setup | 24/1/2018 | 17/6/2026 | An information disclosure in ovirt-hosted-engine-setup prior to 2.2.7 reveals the root user's password in the log file. | |
| Modificada | Alta (7.8) | 0.91% | — | Flets-w Flets Easy Setup Tool | 2/11/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer of Flets Easy Setup Tool Ver1.2.0 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.1% | — | NTT Security Setup Tool | 29/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Security Setup Tool all versions allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Media (6.5) | 0.47% | — | Siemens PCS 7Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic Automation Tool+12 | 11/5/2017 | 17/6/2026 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC Automation Tool (All versions < V3.0), SIMATIC NET PC-Software (All versions < V14 SP1), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7 V8.2 (All versions < V8.2 SP1), SIMATIC STEP 7 (TIA Portal) V13 (All versions <… | |
| Modificada | Media (6.8) | 0.71% | — | Cryptsetup Project Cryptsetup | 23/1/2017 | 17/6/2026 | The Debian initrd script for the cryptsetup package 2:1.7.3-2 and earlier allows physically proximate attackers to gain shell access via many log in attempts with an invalid password. | |
| Modificada | Media (6.4) | 0.38% | — | Siemens Primary Setup ToolSiemens Security Configuration ToolSiemens Simatic IT Production SuiteSiemens Simatic NET PC Software+14 | 15/11/2016 | 17/6/2026 | A vulnerability has been identified in Primary Setup Tool (PST) (All versions < V4.2 HF1), SIMATIC IT Production Suite (All versions < V7.0 SP1 HFX 2), SIMATIC NET PC-Software (All versions < V14), SIMATIC PCS 7 V7.1 (All versions), SIMATIC PCS 7 V8.0 (All versions), SIMATIC PCS 7 V8.1 (All versions), SIMATIC PCS 7… | |
| Modificada | Alta (8.1) | 1.9% | — | Ietf Transport Layer SecurityNetapp Clustered Data Ontap Antivirus ConnectorNetapp Data Ontap EdgeNetapp Host Agent+9 | 21/9/2016 | 17/6/2026 | The TLS protocol 1.2 and earlier supports the rsa_fixed_dh, dss_fixed_dh, rsa_fixed_ecdh, and ecdsa_fixed_ecdh values for ClientCertificateType but does not directly document the ability to compute the master secret in certain situations with a client secret key and server public key but not a server secret key, which… | |
| Modificada | Media (6.8) | 2.0% | — | Python Setuptools | 6/8/2013 | 16/6/2026 | easy_install in setuptools before 0.7 uses HTTP to retrieve packages from the PyPI repository, and does not perform integrity checks on package contents, which allows man-in-the-middle attackers to execute arbitrary code via a crafted response to the default use of the product. | |
| Modificada | Media (5.8) | 3.3% | 💥 Exploit | Wi-fi Wifi Protected Setup Protocol | 6/1/2012 | 16/6/2026 | The Wi-Fi Protected Setup (WPS) protocol, when the "external registrar" authentication method is used, does not properly inform clients about failed PIN authentication, which makes it easier for remote attackers to discover the PIN value, and consequently discover the Wi-Fi network password or reconfigure an access… | |
| Modificada | Media (5) | 2.5% | — | HP Insight Managed System Setup Wizard | 2/11/2010 | 16/6/2026 | Unspecified vulnerability in HP Insight Managed System Setup Wizard before 6.2 allows remote attackers to read arbitrary files via unknown vectors. | |
| Modificada | Alta (7.5) | 4.3% | — | Cisco Router WEB Setup | 18/7/2006 | 16/6/2026 | The default configuration of IOS HTTP server in Cisco Router Web Setup (CRWS) before 3.3.0 build 31 does not require credentials, which allows remote attackers to access the server with arbitrary privilege levels, aka bug CSCsa78190. | |
| Modificada | Alta (7.5) | 67% | 💥 Exploit | Junipersetup Control | 29/4/2006 | 16/6/2026 | Buffer overflow in JuniperSetupDLL.dll, loaded from JuniperSetup.ocx by the Juniper SSL-VPN Client when accessing a Juniper NetScreen IVE device running IVE OS before 4.2r8.1, 5.0 before 5.0r6.1, 5.1 before 5.1r8, 5.2 before 5.2r4.1, or 5.3 before 5.3r2.1, allows remote attackers to execute arbitrary code via a long… | |
| Modificada | Media (4.6) | 0.40% | — | Debian Apt-setup | 11/7/2005 | 16/6/2026 | apt-setup in Debian GNU/Linux installs the apt.conf file with insecure permissions, which allows local users to obtain sensitive information such as passwords. | |
| Modificada | Media (5) | 2.6% | — | Intel CLI Auto-configuration UtilityIntel Client System Setup UtilityIntel Server Configuration WizardIntel Server Control+18 | 31/12/2004 | 16/6/2026 | The firmware for Intelligent Platform Management Interface (IPMI) 1.5-based Intel Server Boards and Platforms is shipped with an Authentication Type Enables parameter set to an invalid None parameter, which allows remote attackers to obtain sensitive information when LAN management functionality is enabled. | |
| Modificada | Alta (7.5) | 27% | 💥 Exploit | Microsoft MSN Setup Bulletin Board Services | 24/9/1999 | 16/6/2026 | Buffer overflow in MSN Setup BBS 4.71.0.10 ActiveX control (setupbbs.ocx) allows a remote attacker to execute arbitrary commands via the methods (1) vAddNewsServer or (2) bIsNewsServerConfigured. |