Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

243 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.1)0.69%—Ixpdata Easyinstall19/10/202317/6/2026
An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG.
ModificadaAlta (7.9)0.34%—Oracle Mysql Installer17/10/202317/6/2026
Vulnerability in the MySQL Installer product of Oracle MySQL (component: Installer: General). Supported versions that are affected are Prior to 1.6.8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Installer executes to compromise MySQL Installer.…
ModificadaMedia (6.1)1.2%💥 ExploitStructurizr On-premises Installation12/10/202317/6/2026
Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194.
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaAlta (7.8)0.41%—Caphyon Advanced Installer30/9/202317/6/2026
A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to…
ModificadaMedia (5.5)0.20%—Samsung Packageinstallerchn6/9/202317/6/2026
Intent redirection vulnerability in PackageInstallerCHN prior to version 13.1.03.00 allows local attacker to access arbitrary file. This vulnerability requires user interaction.
ModificadaAlta (7.3)0.17%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.15%—Intel Ispc Software Installer11/8/202317/6/2026
Improper access control in some Intel(R) ISPC software installers before version 1.19.0 may allow an authenticated user to potentially enable escalation of privileges via local access.
ModificadaMedia (6.7)0.18%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.3)0.88%—Nullsoft Scriptable Install System3/7/202317/6/2026
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
ModificadaAlta (7.8)0.60%—Mrpack-install Project Mrpack-install26/6/202317/6/2026
nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
ModificadaAlta (7.8)0.22%—Autodesk Installer23/6/202317/6/2026
A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability.
ModificadaAlta (7.5)0.57%—Enphase Installer Toolkit20/6/202317/6/2026
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.
ModificadaAlta (7.8)0.28%—HP Softpaq Installer9/6/202317/6/2026
A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.
ModificadaAlta (7.8)0.24%—Wacom Tablet Driver Installer25/5/202317/6/2026
Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the installer, arbitrary code may be executed with the root privilege.
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.19%—Schneider-electric Easergy Builder Installer18/4/202317/6/2026
A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected…
ModificadaAlta (7.8)0.28%—Flexera Revenera Installshield29/3/202317/6/2026
A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.
ModificadaMedia (5.5)0.25%—Redhat Openshift Assisted InstallerRedhat Openshift Container Platform24/3/202317/6/2026
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
ModificadaAlta (7.5)0.66%💥 PoCModoboa Installer16/2/202317/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
ModificadaAlta (7.8)0.21%—Caphyon Advanced Installer8/2/202317/6/2026
Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to access and manipulate system files.
ModificadaMedia (4.7)0.39%—Ghinstallation Project Ghinstallation20/12/202217/6/2026
ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT…
ModificadaAlta (8.8)0.19%—Ixpdata Easyinstall1/12/202217/6/2026
IXPdata EasyInstall 6.6.14725 contains an access control issue.
ModificadaAlta (7.3)0.22%—Installbuilder18/11/202217/6/2026
InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displaying popups. This may allow an attacker to plant a malicious DLL in the installer parent directory to allow executing code with the privileges of the installer (when the popup…
ModificadaAlta (7.8)0.18%—Intel NUC KIT Wireless Adapter Driver Installer11/11/202217/6/2026
Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
Orbitaley — Vulnerabilidades