Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.20% | — | Intel Chipset Software Installation UtilityAI | 12/2/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) Chipset Software Installation Utility before version 10.1.19867.8574 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.17% | — | Intel DSA InstallerAI | 12/2/2025 | 17/6/2026 | Incorrect default permissions for some Intel(R) DSA installer for Windows before version 24.2.19.5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.3) | 0.17% | — | Intel ME Driver Pack InstallerAI | 12/2/2025 | 17/6/2026 | Improper access control in some Intel(R) ME driver pack installer engines before version 2422.6.2.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.5) | 0.17% | — | Revenera InstallshieldAI | 30/1/2025 | 17/6/2026 | Potential privilege escalation vulnerability in Revenera InstallShield versions 2022 R2 and 2021 R2 due to adding InstallScript custom action to a Basic MSI or InstallScript MSI project extracting few binaries to a predefined writable folder during installation time. The standard user account has write access to these… | |
| Aplazada | Alta (8.6) | 0.19% | — | Silabs Cp210x VCP Windows InstallerAI | 24/1/2025 | 17/6/2026 | DLL hijacking vulnerabilities, caused by an uncontrolled search path in the CP210x VCP Windows installer can lead to privilege escalation and arbitrary code execution when running the impacted installer. | |
| Aplazada | Media (6.5) | 0.37% | — | Manny Costales Gmap ShortcodeAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Manny Costales GMap Shortcode gmap-shortcode allows DOM-Based XSS.This issue affects GMap Shortcode: from n/a through <= 2.0. | |
| Aplazada | Media (4.1) | 0.18% | — | StalldAI | 29/11/2024 | 17/6/2026 | stalld through 1.19.7 allows local users to cause a denial of service (file overwrite) via a /tmp/rtthrottle symlink attack. | |
| Aplazada | Media (6.4) | 0.53% | — | Prestalife Product DesignerAI | 21/11/2024 | 17/6/2026 | The Product Designer plugin for WordPress is vulnerable to Stored Cross-Site Scripting via SVG File uploads in all versions up to, and including, 1.0.36 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with Author-level access and above, to inject… | |
| Modificada | Alta (7.8) | 0.19% | — | Autodesk Installer | 15/11/2024 | 17/6/2026 | A maliciously crafted DLL file when placed in temporary files and folders that are leveraged by the Autodesk Installer could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to insecure privilege management. | |
| Aplazada | Media (6.3) | 0.28% | — | Naver Whale Browser InstallerAI | 25/10/2024 | 17/6/2026 | Whale browser Installer before 3.1.0.0 allows an attacker to execute a malicious DLL in the user environment due to improper permission settings. | |
| Analizada | Media (5.3) | 0.50% | — | Oracle Installed Base | 15/10/2024 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.14. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of… | |
| Analizada | Alta (7.8) | 0.86% | — | Microsoft APP Installer | 13/8/2024 | 17/6/2026 | Windows App Installer Spoofing Vulnerability | |
| Aplazada | Media (5.3) | 0.56% | — | Prestalife Product DesignerAI | 9/7/2024 | 17/6/2026 | The Product Designer plugin for WordPress is vulnerable to unauthorized loss of data due to a missing capability check on the product_designer_ajax_delete_attach_id() function in all versions up to, and including, 1.0.33. This makes it possible for unauthenticated attackers to delete arbitrary attachments.… | |
| Aplazada | Media (4.8) | 0.17% | — | Kostal Piko 1.5-1 MP Plus HMI OEMAI | 21/6/2024 | 17/6/2026 | In Kostal PIKO 1.5-1 MP plus HMI OEM p 1.0.1, the web application for the Solar Panel is vulnerable to a Stored Cross-Site Scripting (XSS) attack on /file.bootloader.upload.html. The application fails to sanitize the parameter filename, in a POST request to /file.bootloader.upload.html for a system update, thus… | |
| Modificada | Alta (7.5) | 0.70% | — | Pq-crystals Kyber | 10/6/2024 | 17/6/2026 | The Kyber reference implementation before 9b8d306, when compiled by LLVM Clang through 18.x with some common optimization options, has a timing side channel that allows attackers to recover an ML-KEM 512 secret key in minutes. This occurs because poly_frommsg in poly.c does not prevent Clang from emitting a vulnerable… | |
| Aplazada | Crítica (9.1) | 0.74% | — | Stalwart Mail ServerAI | 16/5/2024 | 17/6/2026 | Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, attackers who achieved Arbitrary Code Execution as the stalwart-mail user (including web interface admins) can gain complete root access to the system. Usually, system services are run as a separate user (not as root) to isolate an attacker… | |
| Aplazada | Media (6.8) | 0.62% | — | Stalwart Mail ServerAI | 15/5/2024 | 17/6/2026 | Stalwart Mail Server is an open-source mail server. Prior to version 0.8.0, when using `RUN_AS_USER`, the specified user (and therefore, web interface admins) can read arbitrary files as root. This issue affects admins who have set up to run stalwart with `RUN_AS_USER` who handed out admin credentials to the mail… | |
| Analizada | Alta (7.8) | 0.97% | — | Ivanti Pulse Secure Desktop ClientIvanti Pulse Secure Installer ServiceIvanti Secure Access Client | 3/5/2024 | 17/6/2026 | Pulse Secure Client SetupService Directory Traversal Local Privilege Escalation Vulnerability. This vulnerability allows local attackers to escalate privileges on affected installations of Pulse Secure Client. An attacker must first obtain the ability to execute low-privileged code on the target system in order to… | |
| Aplazada | Alta (7.2) | 0.95% | — | Recrystallize ServerAI | 30/4/2024 | 17/6/2026 | ReCrystallize Server 5.10.0.0 allows administrators to upload files to the server. The file upload is not restricted, leading to the ability to upload of malicious files. This could result in a Remote Code Execution. | |
| Aplazada | Alta (7.5) | 51% | 💥 Exploit | Recrystallize ServerAI | 30/4/2024 | 17/6/2026 | ReCrystallize Server 5.10.0.0 uses a authorization mechanism that relies on the value of a cookie, but it does not bind the cookie value to a session ID. Attackers can easily modify the cookie value, within a browser or by implementing client-side code outside of a browser. Attackers can bypass the authentication… | |
| Analizada | Media (6.1) | 0.36% | — | Oracle Installed Base | 16/4/2024 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Data Provider UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… | |
| Aplazada | Media (6.7) | 0.17% | — | Intel Csme InstallerAI | 14/3/2024 | 17/6/2026 | Improper input validation in the Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.7) | 0.14% | — | Intel Csme InstallerAI | 14/3/2024 | 17/6/2026 | Incorrect default permissions in some Intel(R) CSME installer software before version 2328.5.5.0 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.3) | 0.66% | — | Postalserver Postal | 11/3/2024 | 17/6/2026 | Postal is an open source SMTP server. Postal versions less than 3.0.0 are vulnerable to SMTP Smuggling attacks which may allow incoming e-mails to be spoofed. This, in conjunction with a cooperative outgoing SMTP service, would allow for an incoming e-mail to be received by Postal addressed from a server that a user… | |
| Analizada | Alta (8.1) | 0.31% | — | Prestalife Product Designer | 3/3/2024 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to cause a denial of service (DoS) and escalate privileges via the url parameter in the postProcess() method. |