Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

388 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.18%—Intel Advisor FOR OneapiIntel CPU Runtime FOR Opencl ApplicationsIntel Distribution FOR Python Programming LanguageIntel Dpc++ Compatibility Tool+2511/8/202317/6/2026
Improper access control in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.1.493 may allow a privileged user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.3)0.88%—Nullsoft Scriptable Install System3/7/202317/6/2026
Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory.
ModificadaAlta (7.8)0.60%—Mrpack-install Project Mrpack-install26/6/202317/6/2026
nothub mrpack-install <= v0.16.2 is vulnerable to Directory Traversal.
ModificadaAlta (7.8)0.22%—Autodesk Installer23/6/202317/6/2026
A maliciously crafted DLL file can be forced to write beyond allocated boundaries in the Autodesk installer when parsing the DLL files and could lead to a Privilege Escalation vulnerability.
ModificadaAlta (7.5)0.57%—Enphase Installer Toolkit20/6/202317/6/2026
Enphase Installer Toolkit versions 3.27.0 has hard coded credentials embedded in binary code in the Android application. An attacker can exploit this and gain access to sensitive information.
ModificadaAlta (7.8)0.28%—HP Softpaq Installer9/6/202317/6/2026
A potential security vulnerability has been identified with a version of the HP Softpaq installer that can lead to arbitrary code execution.
ModificadaAlta (7.8)0.24%—Wacom Tablet Driver Installer25/5/202317/6/2026
Wacom Tablet Driver installer prior to 6.4.2-1 (for macOS) contains an improper link resolution before file access vulnerability. When a user is tricked to execute a small malicious script before executing the affected version of the installer, arbitrary code may be executed with the root privilege.
ModificadaAlta (7.8)0.21%—Intel AdvisorIntel CPU RuntimeIntel Distribution FOR PythonIntel Dpc++ Compatibility Tool+2510/5/202317/6/2026
Uncontrolled search path in some Intel(R) oneAPI Toolkit and component software installers before version 4.3.0.251 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (6.7)0.19%—Schneider-electric Easergy Builder Installer18/4/202317/6/2026
A CWE-427 - Uncontrolled Search Path Element vulnerability exists that could allow an attacker with a local privileged account to place a specially crafted file on the target machine, which may give the attacker the ability to execute arbitrary code during the installation process initiated by a valid user. Affected…
ModificadaAlta (7.8)0.28%—Flexera Revenera Installshield29/3/202317/6/2026
A vulnerability has been reported in the windows installer (MSI) built with InstallScript custom action. This vulnerability may allow privilege escalation when invoked ‘repair’ of the MSI which has an InstallScript custom action.
ModificadaMedia (5.5)0.25%—Redhat Openshift Assisted InstallerRedhat Openshift Container Platform24/3/202317/6/2026
A vulnerability was found in OpenShift Assisted Installer. During generation of the Discovery ISO, image pull secrets were leaked as plaintext in the installation logs. An authenticated user could exploit this by re-using the image pull secret to pull container images from the registry as the associated user.
ModificadaAlta (7.5)0.66%💥 PoCModoboa Installer16/2/202317/6/2026
Improper Restriction of Excessive Authentication Attempts in GitHub repository modoboa/modoboa-installer prior to 2.0.4.
ModificadaAlta (7.8)0.21%—Caphyon Advanced Installer8/2/202317/6/2026
Privilege escalation in the MSI repair functionality in Caphyon Advanced Installer 20.0 and below allows attackers to access and manipulate system files.
ModificadaMedia (4.7)0.39%—Ghinstallation Project Ghinstallation20/12/202217/6/2026
ghinstallation provides transport, which implements http.RoundTripper to provide authentication as an installation for GitHub Apps. In ghinstallation version 1, when the request to refresh an installation token failed, the HTTP request and response would be returned for debugging. The request contained the bearer JWT…
ModificadaAlta (8.8)0.19%—Ixpdata Easyinstall1/12/202217/6/2026
IXPdata EasyInstall 6.6.14725 contains an access control issue.
ModificadaAlta (7.3)0.22%—Installbuilder18/11/202217/6/2026
InstallBuilder Qt installers built with versions previous to 22.10 try to load DLLs from the installer binary parent directory when displaying popups. This may allow an attacker to plant a malicious DLL in the installer parent directory to allow executing code with the privileges of the installer (when the popup…
ModificadaAlta (7.8)0.18%—Intel NUC KIT Wireless Adapter Driver Installer11/11/202217/6/2026
Path traversal in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.3)0.17%—Intel NUC KIT Wireless Adapter Driver Installer11/11/202217/6/2026
Unquoted search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.3)0.17%—Intel NUC KIT Wireless Adapter Driver Installer11/11/202217/6/2026
Uncontrolled search path in the installer software for some Intel(r) NUC Kit Wireless Adapter drivers for Windows 10 before version 22.40 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaAlta (7.8)0.14%—Intel NUC KIT Wireless Adapter Driver Installer11/11/202217/6/2026
Insecure inherited permissions in some Intel(R) Wireless Adapter Driver installation software for Intel(R) NUC Kits & Mini PCs before version 22.190.0.3 for Windows may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.3)0.50%—Avdorcis Crystal Quality13/9/202217/6/2026
Avdor CIS - crystal quality Credentials Management Errors. The product is phone call recorder, you can hear all the recorded calls without authenticate to the system. Attacker sends crafted URL to the system: ip:port//V=2;ChannellD=number;Ext=number;Command=startLM;Client=number;Request=number;R=number number - id of…
ModificadaAlta (8.8)1.2%—Rubyinstaller230/8/202217/6/2026
Incorrect access control in the install directory (C:\RailsInstaller) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
ModificadaAlta (8.8)1.2%—Rubyinstaller230/8/202217/6/2026
Incorrect access control in the install directory (C:\Ruby31-x64) of Rubyinstaller2 v3.1.2 and below allows authenticated attackers to execute arbitrary code via overwriting binaries located in the directory.
ModificadaMedia (5.5)0.23%—Redhat Coreos-installer23/8/202217/6/2026
A flaw was found in the coreos-installer, where it writes the Ignition config to the target system with world-readable access permissions. This flaw allows a local attacker to have read access to potentially sensitive data. The highest threat from this vulnerability is to confidentiality.
ModificadaAlta (7.8)0.27%—Oracle Crystal Ball19/7/202217/6/2026
Vulnerability in the Oracle Crystal Ball product of Oracle Construction and Engineering (component: Installation). Supported versions that are affected are 11.1.2.0.000-11.1.2.4.900. Difficult to exploit vulnerability allows low privileged attacker with logon to the infrastructure where Oracle Crystal Ball executes to…
Orbitaley — Vulnerabilidades