Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.1% | — | Sony NFC Port FirmwareSony Pc/sc Activator FOR Type BSony Sfcard Viewer 2Sony NFC NET Installer | 2/8/2017 | 17/6/2026 | Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for RC-S320, RC-S310/J1C, RC-S310/ED4C), PC/SC Activator for Type B Ver.1.2.1.0 and earlier, SFCard Viewer 2 Ver.2.5.0.0 and… | |
| Modificada | Alta (7.8) | 1.4% | — | Acquisition Technology AND Logistics Agency Installer OF Electronic Tendering | 7/7/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer of Electronic tendering and bid opening system available prior to June 12, 2017 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Alta (7) | 0.26% | — | Fedoraproject ARM Installer | 26/6/2017 | 17/6/2026 | fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories. | |
| Modificada | Alta (7.5) | 0.73% | — | Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer | 20/6/2017 | 17/6/2026 | If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text… | |
| Modificada | Crítica (9.8) | 2.3% | — | Redhat Quickstart Cloud Installer | 13/6/2017 | 17/6/2026 | /var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system. | |
| Modificada | Alta (7.8) | 1.1% | — | Santeikohyo Installer OF Houkokusyo Sakusei Shien Tool | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in the installer of Houkokusyo Sakusei Shien Tool ver3.0.2 (For the first installation) (The version which was available on the website from 2017 April 4 to 2017 May 18) and ver2.0 and later (For the first installation) (The versions which were available on the website prior to 2017… | |
| Modificada | Alta (7.8) | 1.1% | — | Sharp Rw-5100 Driver Installer FOR Windows 7Sharp Rw-5100 Driver Installer FOR Windows 8.1 | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 2.5% | — | Vivaldi Installer FOR Windows | 28/4/2017 | 17/6/2026 | Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Media (4.6) | 0.42% | — | Redhat Quickstart Cloud Installer | 14/4/2017 | 17/6/2026 | The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display. | |
| Modificada | Alta (8.4) | 0.39% | — | Redhat Quickstart Cloud Installer | 22/9/2016 | 17/6/2026 | The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack. | |
| Modificada | Alta (8.4) | 0.39% | — | Redhat Quickstart Cloud Installer | 22/9/2016 | 17/6/2026 | Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file. | |
| Modificada | Alta (7.8) | 0.39% | — | Pulsesecure Odyssey Access ClientPulsesecure Pulse Secure DesktopPulsesecure Pulse Secure SecurityPulsesecure Standalone Pulse Installer Service | 2/8/2016 | 17/6/2026 | Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors. | |
| Modificada | Media (5.7) | 1.8% | — | Oracle Siebel Engineering-installer AND Deployment | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Siebel Engineering - Installer and Deployment component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Web Server. | |
| Modificada | Alta (7.8) | 0.38% | — | Linecorp LineLinecorp Line Installer | 12/7/2016 | 17/6/2026 | Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Baja (2.1) | 0.31% | — | IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer | 17/1/2015 | 17/6/2026 | IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.2) | 0.95% | — | Realnetworks Realarcade Installer | 12/1/2015 | 16/6/2026 | RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory tree, which allows local users to gain privileges via a Trojan horse DLL in an individual game's directory, as demonstrated by DDRAW.DLL in… | |
| Modificada | Alta (10) | 4.2% | — | Realnetworks Realarcade Installer | 12/1/2015 | 16/6/2026 | The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.481 performs unexpected type conversions for invalid parameter types, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted arguments to the… | |
| Modificada | Alta (7.2) | 0.39% | — | Juniper Installer Service ClientJuniper Junos Pulse Client | 29/9/2014 | 17/6/2026 | Juniper Installer Service (JIS) Client 7.x before 7.4R6 for Windows and Junos Pulse Client before 4.0R6 allows local users to gain privileges via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.46% | — | Katello Installer | 14/5/2014 | 16/6/2026 | Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file. | |
| Modificada | Media (4.3) | 1.3% | — | Apple InstallerApple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server. | |
| Modificada | Alta (9.3) | 4.8% | — | Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control | 3/11/2010 | 16/6/2026 | Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method. | |
| Modificada | Media (6.8) | 0.94% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968. | |
| Modificada | Media (4.6) | 0.47% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data, and consequently gain privileges, via unknown vectors. | |
| Modificada | Media (6.8) | 0.94% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971. | |
| Modificada | Baja (3.6) | 0.47% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data via unknown vectors. |