Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7) | 0.28% | — | Schneider-electric Enterprise Server Installer | 19/11/2020 | 17/6/2026 | A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path,… | |
| Modificada | Alta (7.8) | 0.34% | — | Capasystems Capainstaller | 9/11/2020 | 17/6/2026 | CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts to edit registry values, allowing an attacker to escalate privileges. | |
| Modificada | Media (4.7) | 1.0% | — | Oracle Installed Base | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: APIs). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful… | |
| Modificada | Alta (7.8) | 0.38% | — | Installbuilder | 18/9/2020 | 17/6/2026 | InstallBuilder for Qt Windows (versions prior to 20.7.0) installers look for plugins at a predictable location at initialization time, writable by non-admin users. While those plugins are not required, they are loaded if present, which could allow an attacker to plant a malicious library which could result in code… | |
| Modificada | Alta (7.8) | 0.54% | — | Canonical Checkinstall | 31/8/2020 | 17/6/2026 | checkinstall 1.6.2, when used to create a package that contains a symlink, may trigger the creation of a mode 0777 executable file. | |
| Modificada | Media (6.1) | 1.2% | — | Managedinstalls Project Managedinstalls | 23/7/2020 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability in the managedinstalls module before 2.6 for MunkiReport allows remote attackers to inject arbitrary web script or HTML via the last two URL parameters (through which installed packages names and versions are reported). | |
| Modificada | Crítica (9.8) | 0.73% | — | Eyesurfer Bflyinstallerx.ocx | 17/7/2020 | 17/6/2026 | EyeSurfer BflyInstallerX.ocx v1.0.0.16 and earlier versions contain a vulnerability that could allow remote files to be download by setting the arguments to the vulnerable method. This can be leveraged for code execution. When the vulnerable method is called, they fail to properly check the parameters that are passed… | |
| Modificada | Alta (7.2) | 1.1% | — | Cymiinstaller322 Activex Project Cymiinstaller322 Activex | 30/6/2020 | 17/6/2026 | CyMiInstaller322 ActiveX which runs MIPLATFORM downloads files required to run applications. A vulnerability in downloading files by CyMiInstaller322 ActiveX caused by an attacker to download randomly generated DLL files and MIPLATFORM to load those DLLs due to insufficient verification. | |
| Modificada | Alta (7) | 0.79% | 💥 PoC | Pulsesecure Pulse Secure Desktop ClientPulsesecure Pulse Secure Installer Service | 16/6/2020 | 17/6/2026 | A time-of-check time-of-use vulnerability in PulseSecureService.exe in Pulse Secure Client versions prior to 9.1.6 down to 5.3 R70 for Windows (which runs as NT AUTHORITY/SYSTEM) allows unprivileged users to run a Microsoft Installer executable with elevated privileges. | |
| Modificada | Alta (7.3) | 0.28% | — | Lenovo Installation Package | 9/6/2020 | 17/6/2026 | A symbolic link vulnerability in some Lenovo installation packages, prior to version 1.2.9.3, could allow privileged file operations during file extraction and installation. | |
| Modificada | Media (6.5) | 0.32% | — | Lenovo Installation Package | 9/6/2020 | 17/6/2026 | A DLL search path vulnerability could allow privilege escalation in some Lenovo installation packages, prior to version 1.2.9.3, during installation if an attacker already has administrative privileges. | |
| Modificada | Crítica (9.1) | 1.1% | — | Naver Whale Browser Installer | 20/5/2020 | 17/6/2026 | Whale Browser Installer before 1.2.0.5 versions don't support signature verification for Flash installer. | |
| Modificada | Alta (8.1) | 1.5% | — | Zoom IT Installer | 4/5/2020 | 17/6/2026 | The Zoom IT installer for Windows (ZoomInstallerFull.msi) prior to version 4.6.10 deletes files located in %APPDATA%\Zoom before installing an updated version of the client. Standard users are able to write to this directory, and can write links to other directories on the machine. As the installer runs with SYSTEM… | |
| Modificada | Alta (7.5) | 1.0% | — | Vmware Installbuilder | 20/4/2020 | 17/6/2026 | InstallBuilder AutoUpdate tool and regular installers enabling <checkForUpdates> built with versions earlier than 19.11 are vulnerable to Billion laughs attack (denial-of-service). | |
| Modificada | Crítica (9.8) | 4.2% | — | Install-package Project Install-package | 2/4/2020 | 17/6/2026 | install-package through 0.4.0 is vulnerable to Command Injection. It allows execution of arbitrary commands via the options argument. | |
| Modificada | Crítica (9.8) | 1.8% | — | Install-package Project Install-packageUmount Project Umount | 2/4/2020 | 17/6/2026 | umount through 1.1.6 is vulnerable to Command Injection. The argument device can be controlled by users without any sanitization. | |
| Modificada | Alta (7.8) | 0.42% | — | Schneider-electric Ulti Zigbee Installation Toolkit | 23/3/2020 | 17/6/2026 | A CWE-426: Untrusted Search Path vulnerability exists in ZigBee Installation Kit (Versions prior to 1.0.1), which could cause execution of malicious code when a malicious file is put in the search path. | |
| Modificada | Alta (7.5) | 0.71% | — | Ixpdata Easyinstall | 23/1/2020 | 17/6/2026 | In IXP EasyInstall 6.2.13723, there are cleartext credentials in network communication on TCP port 20050 when using the Administrator console remotely. | |
| Modificada | Crítica (9.8) | 5.6% | — | Ixpdata Easyinstall | 23/1/2020 | 17/6/2026 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via the Agent Service. An unauthenticated attacker can communicate with the Agent Service over TCP port 20051, and execute code in the NT AUTHORITY\SYSTEM context of the target system by using the Execute Command Line function. | |
| Modificada | Crítica (9.9) | 3.0% | — | Ixpdata Easyinstall | 23/1/2020 | 17/6/2026 | In IXP EasyInstall 6.2.13723, there is Remote Code Execution via weak permissions on the Engine Service share. The default file permissions of the IXP$ share on the server allows modification of directories and files (e.g., bat-scripts), which allows execution of code in the context of NT AUTHORITY\SYSTEM on the… | |
| Modificada | Alta (7.8) | 0.45% | — | Ixpdata Easyinstall | 23/1/2020 | 17/6/2026 | In IXP EasyInstall 6.2.13723, there is Lateral Movement (using the Agent Service) against other users on a client system. An authenticated attacker can, by modifying %SYSTEMDRIVE%\IXP\SW\[PACKAGE_CODE]\EveryLogon.bat, achieve this movement and execute code in the context of other users. | |
| Modificada | Media (5.5) | 0.30% | — | Ixpdata Easyinstall | 23/1/2020 | 17/6/2026 | In IXP EasyInstall 6.2.13723, it is possible to temporarily disable UAC by using the Agent Service on a client system. An authenticated attacker (non-admin) can disable UAC for other users by renaming and replacing %SYSTEMDRIVE%\IXP\DATA\IXPAS.IXP. | |
| Modificada | Alta (7.5) | 2.5% | — | Ixpdata Easyinstall | 23/1/2020 | 17/6/2026 | In IXP EasyInstall 6.2.13723, there is Directory Traversal on TCP port 8000 via the Engine Service by an unauthenticated attacker, who can access the server's filesystem with the access rights of NT AUTHORITY\SYSTEM. | |
| Modificada | Alta (7.5) | 89% | 💥 PoC | Vmware Spring FrameworkOracle Application Testing SuiteOracle Communications Billing AND Revenue Management Elastic Charging EngineOracle Communications Cloud Native Core Policy+29 | 17/1/2020 | 17/6/2026 | In Spring Framework, versions 5.2.x prior to 5.2.3, versions 5.1.x prior to 5.1.13, and versions 5.0.x prior to 5.0.16, an application is vulnerable to a reflected file download (RFD) attack when it sets a "Content-Disposition" header in the response where the filename attribute is derived from user supplied input. |