Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.18% | — | Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+25 | 11/8/2023 | 17/6/2026 | Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 0.88% | — | Nullsoft Scriptable Install System | 3/7/2023 | 17/6/2026 | Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory. | |
| Modificada | Alta (7.8) | 0.60% | — | Mrpack-install Project Mrpack-install | 26/6/2023 | 17/6/2026 | nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal. | |
| Modificada | Alta (7.8) | 0.22% | — | Autodesk Installer | 23/6/2023 | 17/6/2026 | A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability. | |
| Modificada | Alta (7.5) | 0.57% | — | Enphase Installer Toolkit | 20/6/2023 | 17/6/2026 | Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information. | |
| Modificada | Alta (7.8) | 0.28% | — | HP Softpaq Installer | 9/6/2023 | 17/6/2026 | A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution. | |
| Modificada | Alta (7.8) | 0.24% | — | Wacom Tablet Driver Installer | 25/5/2023 | 17/6/2026 | Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the installer, arbitrary code may be executed with the root privilege. | |
| Modificada | Alta (7.8) | 0.21% | — | Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+25 | 10/5/2023 | 17/6/2026 | Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (6.7) | 0.19% | — | Schneider-electric Easergy Builder Installer | 18/4/2023 | 17/6/2026 | A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected… | |
| Modificada | Alta (7.8) | 0.28% | — | Flexera Revenera Installshield | 29/3/2023 | 17/6/2026 | A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action. | |
| Modificada | Media (5.5) | 0.25% | — | Redhat Openshift Assisted InstallerRedhat Openshift Container Platform | 24/3/2023 | 17/6/2026 | A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user. | |
| Modificada | Alta (7.5) | 0.66% | 💥 PoC | Modoboa Installer | 16/2/2023 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4. | |
| Modificada | Alta (7.8) | 0.21% | — | Caphyon Advanced Installer | 8/2/2023 | 17/6/2026 | Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to access and manipulate system files. | |
| Modificada | Media (4.7) | 0.39% | — | Ghinstallation Project Ghinstallation | 20/12/2022 | 17/6/2026 | ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT… | |
| Modificada | Alta (8.8) | 0.19% | — | Ixpdata Easyinstall | 1/12/2022 | 17/6/2026 | IXPdata EasyInstall 6.6.14725 contains an access control issue. | |
| Modificada | Alta (7.3) | 0.22% | — | Installbuilder | 18/11/2022 | 17/6/2026 | InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displaying popups. This may allow an attacker to plant a malicious DLL in the installer parent directory to allow executing code with the privileges of the installer (when the popup… | |
| Modificada | Alta (7.8) | 0.18% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.3) | 0.17% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (7.8) | 0.14% | — | Intel NUC KIT Wireless Adapter Driver Installer | 11/11/2022 | 17/6/2026 | Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Media (5.3) | 0.50% | — | Avdorcis Crystal Quality | 13/9/2022 | 17/6/2026 | Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authenticate to the system. Attacker sends crafted URL to the system: ip:port//V=2;ChannellD=number;Ext=number;Command=startLM;Client=number;Request=number;R=number number - id of… | |
| Modificada | Alta (8.8) | 1.2% | — | Rubyinstaller2 | 30/8/2022 | 17/6/2026 | Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory. | |
| Modificada | Alta (8.8) | 1.2% | — | Rubyinstaller2 | 30/8/2022 | 17/6/2026 | Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory. | |
| Modificada | Media (5.5) | 0.23% | — | Redhat Coreos-installer | 23/8/2022 | 17/6/2026 | A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality. | |
| Modificada | Alta (7.8) | 0.27% | — | Oracle Crystal Ball | 19/7/2022 | 17/6/2026 | Vulnerability in the Oracle Crystal Ball product of Oracle Construction and Engineering (component: Installation). Supported versions that are affected are 11.1.2.0.000-11.1.2.4.900. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Crystal Ball executes to… |