Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
444 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.37% | — | Microsoft Autoupdate | 11/2/2025 | 17/6/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Analizada | Media (5.4) | 0.19% | — | Dell Update Manager Plugin | 7/2/2025 | 17/6/2026 | Dell Update Manager Plugin, version(s) 1.5.0 through 1.6.0, contain(s) an Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability. A low privileged attacker with remote access could potentially exploit this vulnerability, leading to Information exposure. | |
| Aplazada | Crítica (9) | 0.64% | — | Veeam UpdaterAI | 5/2/2025 | 17/6/2026 | A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate. | |
| Aplazada | Media (6.5) | 0.30% | — | Freebsd EtcupdateAI | 30/1/2025 | 17/6/2026 | When etcupdate encounters conflicts while merging files, it saves a version containing conflict markers in /var/db/etcupdate/conflicts. This version does not preserve the mode of the input file, and is world-readable. This applies to files that would normally have restricted visibility, such as /etc/master.passwd. An… | |
| Aplazada | Alta (7.1) | 0.22% | — | UpdatecliAI | 24/1/2025 | 17/6/2026 | Updatecli is a tool used to apply file update strategies. Prior to version 0.93.0, private maven repository credentials may be leaked in application logs in case of unsuccessful retrieval operation. During the execution of an updatecli pipeline which contains a `maven` source configured with basic auth credentials,… | |
| Analizada | Alta (7.4) | 0.68% | — | Microsoft Edge Update | 17/1/2025 | 17/6/2026 | Microsoft Edge (Chromium-based) Update Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 0.45% | — | Microsoft Autoupdate | 14/1/2025 | 17/6/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 4.7% | — | Samba RsyncRedhat DiscoveryRedhat Openshift Container PlatformRedhat Enterprise Linux+16 | 14/1/2025 | 30/6/2026 | A flaw was found in rsync. When using the `--safe-links` option, the rsync client fails to properly verify if a symbolic link destination sent from the server contains another symbolic link within it. This results in a path traversal vulnerability, which may lead to arbitrary file write outside the desired directory. | |
| Modificada | Alta (7.5) | 2.3% | — | Samba RsyncAlmalinuxArchlinux Arch LinuxGentoo Linux+14 | 14/1/2025 | 30/6/2026 | A path traversal vulnerability exists in rsync. It stems from behavior enabled by the `--inc-recursive` option, a default-enabled option for many client options and can be enabled by the server even if not explicitly enabled by the client. When using the `--inc-recursive` option, a lack of proper symlink verification… | |
| Modificada | Alta (7.5) | 8.8% | 💥 PoC | Samba RsyncRedhat OpenshiftRedhat Openshift Container PlatformRedhat Enterprise Linux+18 | 14/1/2025 | 21/9/2026 | A flaw was found in rsync which could be triggered when rsync compares file checksums. This flaw allows an attacker to manipulate the checksum length (s2length) to cause a comparison between a checksum and uninitialized memory and leak one byte of uninitialized stack data at a time. | |
| Analizada | Alta (7.8) | 0.19% | — | Dell Update Package Framework | 7/1/2025 | 17/6/2026 | Dell Update Package Framework, versions prior to 22.01.02, contain(s) a Local Privilege Escalation Vulnerability. A local low privileged attacker could potentially exploit this vulnerability, leading to the execution of arbitrary remote scripts on the server. Exploitation may lead to a denial of service by an attacker. | |
| Aplazada | Alta (7.1) | 0.26% | — | Irshad A Khan Services Updates FOR CustomersAI | 2/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Irshad A.Khan Services updates for customers service-updates-for-customers allows Reflected XSS.This issue affects Services updates for customers: from n/a through <= 1.0. | |
| Aplazada | Media (5.3) | 0.50% | — | Apasionados Comment Blacklist UpdaterAI | 13/12/2024 | 17/6/2026 | Missing Authorization vulnerability in apasionados Comment Blacklist Updater comment-blacklist-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comment Blacklist Updater: from n/a through <= 1.1.0. | |
| Analizada | Crítica (9.8) | 1.3% | — | Microsoft Update Catalog | 12/12/2024 | 17/6/2026 | Deserialization of untrusted data in Microsoft Update Catalog allows an unauthorized attacker to elevate privileges on the website’s webserver. | |
| Analizada | Media (6.7) | 0.17% | — | Dell Dock Hd22q Firmware Update UtilityDell Dock Wd19 Firmware Update UtilityDell Dock Wd22tb4 Firmware Update Utility | 11/12/2024 | 17/6/2026 | Dell Client Platform Firmware Update Utility contains an Improper Link Resolution vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Crítica (9.8) | 23% | 💥 Exploit | WP Umbrella Update Backup Restore AND MonitoringAI | 8/12/2024 | 17/6/2026 | The WP Umbrella: Update Backup Restore & Monitoring plugin for WordPress is vulnerable to Local File Inclusion in all versions up to, and including, 2.17.0 via the 'filename' parameter of the 'umbrella-restore' action. This makes it possible for unauthenticated attackers to include and execute arbitrary files on the… | |
| Analizada | Media (4.4) | 0.21% | — | Dell Intel Management Engine Firmware Update Utility | 22/11/2024 | 17/6/2026 | Dell Edge Gateway 3200, versions prior to 15.40.30.2879, and Edge Gateway 5200, versions prior to 12.0.94.2380, contain an Exposure of Sensitive Information in Shared Microarchitectural Structures during Transient Execution vulnerability. A high privileged attacker with local access could potentially exploit this… | |
| Aplazada | Alta (7.1) | 0.21% | — | Akira1891 Update-notificationsAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in akira1891 UPDATE NOTIFICATIONS update-notifications allows Stored XSS.This issue affects UPDATE NOTIFICATIONS: from n/a through <= 0.3.4. | |
| Aplazada | Alta (7.1) | 0.19% | — | Intel Server Board S2600st Family BiosAIIntel Firmware Update SoftwareAI | 13/11/2024 | 17/6/2026 | Improper input validation in the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (5.4) | 0.18% | — | Intel Server Board S2600st Family Bios AND Firmware UpdateAI | 13/11/2024 | 17/6/2026 | Uncontrolled search path for the Intel(R) Server Board S2600ST Family BIOS and Firmware Update software all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.7) | 0.13% | — | SAP Netweaver JavaAISAP Software Update ManagerAI | 12/11/2024 | 17/6/2026 | In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to… | |
| Aplazada | Alta (7) | 0.18% | — | Macrovision Update ServiceAI | 8/11/2024 | 17/6/2026 | An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a race condition in the Elefant Update Service during the repair or update process. When using the repair function, the service queries the server for a list of files and their… | |
| Aplazada | Alta (7.8) | 2.0% | — | Elefant Software UpdaterAI | 8/11/2024 | 17/6/2026 | An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service which is running as… | |
| Modificada | Media (6.5) | 1.3% | — | Redhat Openshift Container PlatformRedhat Openshift Container Platform FOR Arm64Redhat Openshift Container Platform FOR IBM ZRedhat Openshift Container Platform FOR Linuxone+11 | 15/10/2024 | 17/6/2026 | A vulnerability was found in Podman, Buildah, and CRI-O. A symlink traversal vulnerability in the containers/storage library can cause Podman, Buildah, and CRI-O to hang and result in a denial of service via OOM kill when running a malicious image using an automatically assigned user namespace (`--userns=auto` in… | |
| Modificada | Media (4.4) | 0.39% | — | Buildah Project BuildahRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux EUS+10 | 9/10/2024 | 7/8/2026 | A vulnerability was found in Buildah. Cache mounts do not properly validate that user-specified paths for the cache are within our cache directory, allowing a `RUN` instruction in a Container file to mount an arbitrary directory from the host (read/write) into the container as long as those files can be accessed by… |