Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 0.93% | — | Prestalife Product Designer | 3/3/2024 | 17/6/2026 | An issue was discovered in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows remote attackers to execute arbitrary code, escalate privileges, and obtain sensitive information via the postProcess() method. | |
| Analizada | Alta (7.5) | 0.72% | — | Prestalife Product Designer | 3/3/2024 | 17/6/2026 | Path Traversal vulnerability in Tunis Soft "Product Designer" (productdesigner) module for PrestaShop before version 1.178.36, allows a remote attacker to escalate privileges and obtain sensitive information via the ajaxProcessCropImage() method. | |
| Analizada | Media (5.4) | 0.34% | — | Oracle Installed Base | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful… | |
| Modificada | Media (6.1) | 0.36% | — | Oracle Installed Base | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: HTML UI). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks require… | |
| Modificada | Media (6.1) | 0.36% | — | Oracle Installed Base | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful… | |
| Modificada | Media (6.1) | 0.17% | — | Oracle Installed Base | 17/2/2024 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful… | |
| Modificada | Media (5.5) | 0.14% | — | Flexera Installshield | 26/1/2024 | 17/6/2026 | A vulnerability has been reported in Suite Setups built with versions prior to InstallShield 2023 R2. This vulnerability may allow locally authenticated users to cause a Denial of Service (DoS) condition when handling move operations on local, temporary folders. | |
| Modificada | Media (6.1) | 0.17% | — | Oracle Installed Base | 16/1/2024 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Engineering Change Order). Supported versions that are affected are 12.2.3-12.2.13. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful… | |
| Modificada | Alta (7.8) | 0.32% | — | Pyinstaller | 9/12/2023 | 17/6/2026 | PyInstaller bundles a Python application and all its dependencies into a single package. A PyInstaller built application, elevated as a privileged process, may be tricked by an unprivileged attacker into deleting files the unprivileged user does not otherwise have access to. A user is affected if **all** the following… | |
| Modificada | Alta (7.8) | 0.25% | — | Westerndigital Sandisk Security Installer | 15/11/2023 | 17/6/2026 | Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges… | |
| Modificada | Alta (7.8) | 0.23% | — | Intel Audio Install Package | 14/11/2023 | 17/6/2026 | Path transversal in some Intel(R) NUC P14E Laptop Element Audio Install Package software before version 156 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.1) | 0.57% | — | Saat NetizenSaat Netizen Installer | 31/10/2023 | 17/6/2026 | Improper file verification vulnerability in SaAT Netizen installer ver.1.2.0.424 and earlier, and SaAT Netizen ver.1.2.0.8 (Build427) and earlier allows a remote unauthenticated attacker to conduct a man-in-the-middle attack. A successful exploitation may result in a malicious file being downloaded and executed. | |
| Modificada | Alta (7.8) | 0.17% | — | Ixpdata Easyinstall | 19/10/2023 | 17/6/2026 | An issue discovered in IXP Data EasyInstall 6.6.14907.0 allows attackers to gain escalated privileges via static Cryptographic Key. | |
| Modificada | Crítica (9.8) | 0.78% | — | Ixpdata Easyinstall | 19/10/2023 | 17/6/2026 | An issue discovered in IXP EasyInstall 6.6.14884.0 allows attackers to run arbitrary commands, gain escalated privilege, and cause other unspecified impacts via unauthenticated API calls. | |
| Modificada | Alta (7.8) | 0.21% | — | Ixpdata Easyinstall | 19/10/2023 | 17/6/2026 | An issue found in IXP Data Easy Install v.6.6.14884.0 allows a local attacker to gain privileges via a static XOR key. | |
| Modificada | Alta (7.8) | 0.21% | — | Ixpdata Easyinstall | 19/10/2023 | 17/6/2026 | An issue discovered in IXP Data Easy Install v.6.6.14884.0 allows local attackers to gain escalated privileges via weak encoding of sensitive information. | |
| Modificada | Alta (7.8) | 0.22% | — | Ixpdata Easyinstall | 19/10/2023 | 17/6/2026 | An issue found in IXP Data Easy Install v.6.6.14884.0 allows an attacker to escalate privileges via lack of permissions applied to sub directories. | |
| Modificada | Alta (8.1) | 0.69% | — | Ixpdata Easyinstall | 19/10/2023 | 17/6/2026 | An issue found in IXP Data Easy Install 6.6.148840 allows a remote attacker to escalate privileges via insecure PRNG. | |
| Modificada | Alta (7.9) | 0.34% | — | Oracle Mysql Installer | 17/10/2023 | 17/6/2026 | Vulnerability in the MySQL Installer product of Oracle MySQL (component: Installer: General). Supported versions that are affected are Prior to 1.6.8. Easily exploitable vulnerability allows low privileged attacker with logon to the infrastructure where MySQL Installer executes to compromise MySQL Installer.… | |
| Modificada | Media (6.1) | 1.2% | 💥 Exploit | Structurizr On-premises Installation | 12/10/2023 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in GitHub repository structurizr/onpremises prior to 3194. | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Alta (7.8) | 0.41% | — | Caphyon Advanced Installer | 30/9/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Caphyon Advanced Installer 19.7. This affects an unknown part of the component WinSxS DLL Handler. The manipulation leads to uncontrolled search path. Attacking locally is a requirement. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Media (5.5) | 0.20% | — | Samsung Packageinstallerchn | 6/9/2023 | 17/6/2026 | Intent redirection vulnerability in PackageInstallerCHN prior to version 13.1.03.00 allows local attacker to access arbitrary file. This vulnerability requires user interaction. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.15% | — | Intel Ispc Software Installer | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) ISPC software installers before version 1.19.0 may allow an authenticated user to potentially enable escalation of privileges via local access. |