Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

243 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.3)0.17%—Intel NUC KIT Wireless Adapter Driver Installer11/11/202217/6/2026
Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.3)0.17%—Intel NUC KIT Wireless Adapter Driver Installer11/11/202217/6/2026
Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.14%—Intel NUC KIT Wireless Adapter Driver Installer11/11/202217/6/2026
Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (8.8)1.2%—Rubyinstaller230/8/202217/6/2026
Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
ModificadaAlta (8.8)1.2%—Rubyinstaller230/8/202217/6/2026
Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
ModificadaMedia (5.5)0.23%—Redhat Coreos-installer23/8/202217/6/2026
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaAlta (8.8)1.5%💥 PoCEmcosoftware MSI Package BuilderEmcosoftware Network InventoryEmcosoftware Network Software ScannerEmcosoftware Ping Monitor+423/5/20229/7/2026
Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows…
ModificadaMedia (5.5)0.20%—Lenovo Thin Installer22/4/202217/6/2026
A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash.
ModificadaAlta (7.8)0.35%—Samsung Android USB Driver Windows Installer11/4/202217/6/2026
Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code.
ModificadaAlta (7.8)0.52%—Redhat Coreos-installer4/3/202217/6/2026
An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary…
ModificadaAlta (7.5)1.3%—Oracle Installed Base19/1/202217/6/2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Instance Main). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of…
ModificadaAlta (7.8)0.29%—Netgear Genie Installer30/12/202117/6/2026
All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which the software is going to be installed may…
ModificadaAlta (7.8)0.29%—Thalesgroup Sentinel Protection Installer20/12/202117/6/2026
Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code.
ModificadaMedia (6.7)0.22%—Thalesgroup Sentinel Protection Installer20/12/202117/6/2026
Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges.
AnalizadaAlta (7.1)10%⚠ Explotación activaMicrosoft APP Installer15/12/20216/8/2026
We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a…
ModificadaAlta (8.8)0.99%—Vmware Installbuilder29/10/202117/6/2026
On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict access to Administrators only so a potential attacker could…
ModificadaAlta (7.8)0.29%—Vmware Installbuilder29/10/202117/6/2026
Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a binary can be identified. This makes the installer/uninstaller vulnerable to Path Interception by…
ModificadaCrítica (9.1)1.8%—Cisco IOS XECisco IOS XE Sd-wanCisco IOS XE Sd-wan 16.10.1 When Installed ON 1000 Series Integrated ServicesCisco IOS XE Sd-wan 16.10.1 When Installed ON 4000 Series Integrated Services+14223/9/202117/6/2026
A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory…
ModificadaMedia (5.4)0.60%—Tibco Webfocus ClientTibco Webfocus InstallerTibco Webfocus Reporting Server14/9/202117/6/2026
The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a…
ModificadaAlta (7.8)0.57%—Microsoft .net Education Bundle SDK Install ToolMicrosoft .net Install Tool FOR Extension Authors14/7/202110/8/2026
Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability
ModificadaAlta (8.1)0.93%—Oracle Installed Base22/4/202117/6/2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: APIs). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability…
ModificadaAlta (8.1)1.8%—Redhat Openshift Installer23/2/202117/6/2026
A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during…
ModificadaMedia (4.7)1.1%—Oracle Installed Base20/1/202117/6/2026
Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: APIs). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful…
ModificadaCrítica (9.8)0.93%—Jenkins Installation Manager Tool3/12/202017/6/2026
Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads.
Orbitaley — Vulnerabilidades