Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.69% | — | Ixpdata Easyinstall | 19/10/2023 | 17/6/2026 | An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG. | |
| Modificada | Alta (7.9) | 0.34% | — | Oracle Mysql Installer | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Installer product of Oracle MySQL (component: Installer: General). Supported versions that are affected are Prior to 1.6.8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Installer executes to compromise MySQL Installer.… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Structurizr On-premises Installation | 12/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.8) | 0.41% | — | Caphyon Advanced Installer | 30/9/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Media (5.5) | 0.20% | — | Samsung Packageinstallerchn | 6/9/2023 | 17/6/2026 | Intent redirection vulnerability in PackageInstallerCHN prior to version 13.1.03.00 allows local attacker to access arbitrary file. This vulnerability requires user interaction. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Ispc Software Installer | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) ISPC software installers before version 1.19.0 may allow an authenticated user to potentially enable escalation of privileges via local access. | |
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 0.88% | — | Nullsoft Scriptable Install System | 3/7/2023 | 17/6/2026 | Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory. | |
| Modificada | Alta (7.8) | 0.60% | — | Mrpack-install Project Mrpack-install | 26/6/2023 | 17/6/2026 | nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal. | |
| Modificada | Alta (7.8) | 0.22% | — | Autodesk Installer | 23/6/2023 | 17/6/2026 | A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability. | |
| Modificada | Alta (7.5) | 0.57% | — | Enphase Installer Toolkit | 20/6/2023 | 17/6/2026 | Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information. | |
| Modificada | Alta (7.8) | 0.28% | — | HP Softpaq Installer | 9/6/2023 | 17/6/2026 | A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.24% | — | Wacom Tablet Driver Installer | 25/5/2023 | 17/6/2026 | Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the installer, arbitrary code may be executed with the root privilege. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Schneider-electric Easergy Builder Installer | 18/4/2023 | 17/6/2026 | A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected… | |
| Modificada | Alta (7.8) | 0.28% | — | Flexera Revenera Installshield | 29/3/2023 | 17/6/2026 | A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action. | |
| Modificada | Media (5.5) | 0.25% | — | Redhat Openshift Assisted InstallerRedhat Openshift Container Platform | 24/3/2023 | 17/6/2026 | A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user. | |
| Modificada | Alta (7.5) | 0.66% | 💥 PoC | Modoboa Installer | 16/2/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4. | |
| Modificada | Alta (7.8) | 0.21% | — | Caphyon Advanced Installer | 8/2/2023 | 17/6/2026 | Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to access and manipulate system files. | |
| Modificada | Media (4.7) | 0.39% | — | Ghinstallation Project Ghinstallation | 20/12/2022 | 17/6/2026 | ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT… | |
| Modificada | Alta (8.8) | 0.19% | — | Ixpdata Easyinstall | 1/12/2022 | 17/6/2026 | IXPdata EasyInstall 6.6.14725 contains an access control issue. | |
| Modificada | Alta (7.3) | 0.22% | — | Installbuilder | 18/11/2022 | 17/6/2026 | InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displaying popups. This may allow an attacker to plant a malicious DLL in the installer parent directory to allow executing code with the privileges of the installer (when the popup… | |
| Modificada | Alta (7.8) | 0.18% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. |