Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.12% | — | Server Firmware Update Utility SysfwupdtAI | 10/2/2026 | 17/6/2026 | Improper input validation for some Server Firmware Update Utility(SysFwUpdt) before version 16.0.12 within Ring 3: User Applications may allow an escalation of privilege. System software adversary with a privileged user combined with a high complexity attack may enable local code execution. This result may potentially… | |
| Analizada | Alta (7.8) | 0.17% | — | Avanquest PC Helpsoft Driver Updater | 3/2/2026 | 17/6/2026 | Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component. | |
| Analizada | Media (4.7) | 0.24% | — | Theupdateframework Go-tuf | 27/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). go-tuf's TAP 4 Multirepo Client uses the map file repository name string (`repoName`) as a filesystem path component when selecting the local metadata cache directory. Starting in version 2.0.0 and prior to version 2.4.1, if an application accepts a map file… | |
| Analizada | Alta (7.5) | 0.22% | — | Theupdateframework Go-tuf | 22/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, a compromised or misconfigured TUF repository can have the configured value of signature thresholds set to 0, which effectively disables signature verification. This can lead to unauthorized modification… | |
| Analizada | Alta (7.5) | 0.59% | — | Theupdateframework Go-tuf | 22/1/2026 | 17/6/2026 | go-tuf is a Go implementation of The Update Framework (TUF). Starting in version 2.0.0 and prior to version 2.3.1, if the TUF repository (or any of its mirrors) returns invalid TUF metadata JSON (valid JSON but not well formed TUF metadata), the client will panic during parsing, causing a denial of service. The panic… | |
| Aplazada | Alta (8.5) | 0.18% | — | Acer Updater ServiceAI | 16/1/2026 | 17/6/2026 | Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during… | |
| Aplazada | Alta (8.5) | 0.19% | — | Splashtop Software UpdaterAI | 13/1/2026 | 17/6/2026 | Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and… | |
| Analizada | Crítica (9.3) | 1.2% | ⚠ Explotación activa | Asus Live Update | 17/12/2025 | 25/9/2026 | "UNSUPPORTED WHEN ASSIGNED" Certain versions of the ASUS Live Update client were distributed with unauthorized modifications introduced through a supply chain compromise. The modified builds could cause devices meeting specific targeting conditions to perform unintended actions. Only devices that met these conditions… | |
| Aplazada | Media (5.4) | 0.10% | — | Intel ONE Boot Flash UpdateAI | 11/11/2025 | 17/6/2026 | Incorrect default permissions for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of… | |
| Aplazada | Media (5.4) | 0.12% | — | Intel ONE Boot Flash UpdateAI | 11/11/2025 | 17/6/2026 | Uncontrolled search path for some Intel(R) One Boot Flash Update (Intel(R) OFU) software before version 14.1.31 within Ring 3: User Applications may allow an escalation of privilege. Unprivileged software adversary with an authenticated user combined with a high complexity attack may enable escalation of privilege.… | |
| Aplazada | Media (5.4) | 0.13% | — | Intel Server Configuration UtilityAIIntel Server Firmware Update UtilityAI | 11/11/2025 | 17/6/2026 | Improper link resolution before file access ('link following') for some Intel(R) Server Configuration Utility software and Intel(R) Server Firmware Update Utility software before version 16.0.12. within Ring 3: User Applications may allow an escalation of privilege. System software adversary with an authenticated user… | |
| Analizada | Alta (7.3) | 0.28% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was discovered in the X.Org X server’s X Keyboard (Xkb) extension when handling client resource cleanup. The software frees certain data structures without properly detaching related resources, leading to a use-after-free condition. This can cause memory corruption or a crash when affected clients disconnect. | |
| Analizada | Alta (7.3) | 0.30% | — | X.org X ServerX.org XwaylandIBM ViosIBM AIX+7 | 30/10/2025 | 1/7/2026 | A flaw was identified in the X.Org X server’s X Keyboard (Xkb) extension where improper bounds checking in the XkbSetCompatMap() function can cause an unsigned short overflow. If an attacker sends specially crafted input data, the value calculation may overflow, leading to memory corruption or a crash. | |
| Aplazada | Baja (3.8) | 0.13% | — | Github Workflow UpdaterAIMicrosoft VS CodeAI | 28/10/2025 | 17/6/2026 | GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure "securestorage" api. An attacker with… | |
| Aplazada | Media (4.3) | 0.25% | — | Joby Joseph SEO Meta Description UpdaterAI | 27/10/2025 | 17/6/2026 | Missing Authorization vulnerability in Joby Joseph SEO Meta Description Updater seo-meta-description-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Meta Description Updater: from n/a through <= 1.2.0. | |
| Aplazada | Media (4.3) | 0.14% | — | Mayo Moriyama Force Update TranslationsAI | 22/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Mayo Moriyama Force Update Translations force-update-translations allows Cross Site Request Forgery.This issue affects Force Update Translations: from n/a through <= 0.5. | |
| Aplazada | Media (6.5) | 0.21% | — | Luke Mlsna Last-updated-shortcodeAI | 22/9/2025 | 30/9/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Luke Mlsna Last Updated Shortcode last-updated-shortcode allows Stored XSS.This issue affects Last Updated Shortcode: from n/a through <= 1.0.1. | |
| Aplazada | Media (4.3) | 0.13% | — | Plugin Updates BlockerAI | 11/9/2025 | 17/6/2026 | The Plugin updates blocker plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 0.2. This is due to missing or incorrect nonce validation on the pub_save action handler. This makes it possible for unauthenticated attackers to disable or enable plugin updates via a… | |
| Aplazada | Alta (8.8) | 0.12% | — | Altiris Core Agent UpdaterAI | 11/9/2025 | 30/9/2026 | The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking. | |
| Analizada | Alta (7.8) | 0.42% | — | Microsoft Autoupdate | 9/9/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Media (6.5) | 0.17% | — | Ablancodev Woocommerce Notify Updated ProductAI | 5/9/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ablancodev Woocommerce Notify Updated Product woocommerce-notify-updated-product allows Stored XSS.This issue affects Woocommerce Notify Updated Product: from n/a through <= 1.6. | |
| Analizada | Alta (8.8) | 1.6% | ⚠ Explotación activa💥 PoC | Apple SafariApple IpadosApple Iphone OSApple Macos+11 | 29/7/2025 | 21/9/2026 | The issue was addressed with improved memory handling. This issue is fixed in Safari 18.6, iOS 18.6 and iPadOS 18.6, macOS Sequoia 15.6, tvOS 18.6, visionOS 2.6, watchOS 11.6. Processing maliciously crafted web content may lead to memory corruption. | |
| Aplazada | Media (5.5) | 0.27% | — | Codeermeneer Companion Auto UpdateAI | 15/7/2025 | 17/6/2026 | The Companion Auto Update plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the ‘update_delay_days’ parameter in all versions up to, and including, 3.9.2 due to insufficient input sanitization and output escaping. This makes it possible for authenticated attackers, with administrator-level access,… | |
| Analizada | Alta (8.1) | 0.40% | — | Updategadh Real Estate Management | 18/6/2025 | 17/6/2026 | Real Estate Management 1.0 is vulnerable to Cross Site Scripting (XSS) in /store/index.php. | |
| Modificada | Alta (7.5) | 1.4% | — | Xmlsoft Libxml2Redhat Jboss Core ServicesRedhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64+16 | 12/6/2025 | 18/9/2026 | A flaw was found in libxml2's xmlBuildQName function, where integer overflows in buffer size calculations can lead to a stack-based buffer overflow. This issue can result in memory corruption or a denial of service when processing crafted input. |