Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
388 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 2.0% | 💥 PoC | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (8.8) | 1.5% | 💥 PoC | Emcosoftware MSI Package BuilderEmcosoftware Network InventoryEmcosoftware Network Software ScannerEmcosoftware Ping Monitor+4 | 23/5/2022 | 9/7/2026 | Certain EMCO Software products are affected by: CWE-494: Download of Code Without Integrity Check. This affects MSI Package Builder for Windows 9.1.4 and Remote Installer for Windows 6.0.13 and Ping Monitor for Windows 8.0.18 and Remote Shutdown for Windows 7.2.2 and WakeOnLan 2.0.8 and Network Inventory for Windows… | |
| Modificada | Media (5.5) | 0.20% | — | Lenovo Thin Installer | 22/4/2022 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo Thin Installer prior to version 1.3.0039 that could trigger a system crash. | |
| Modificada | Alta (7.8) | 0.35% | — | Samsung Android USB Driver Windows Installer | 11/4/2022 | 17/6/2026 | Uncontrolled search path element vulnerability in Samsung Android USB Driver windows installer program prior to version 1.7.50 allows attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.52% | — | Redhat Coreos-installer | 4/3/2022 | 17/6/2026 | An improper signature verification vulnerability was found in coreos-installer. A specially crafted gzip installation image can bypass the image signature verification and as a consequence can lead to the installation of unsigned content. An attacker able to modify the original installation image can write arbitrary… | |
| Modificada | Media (5.4) | 0.64% | — | Beanstalk Console Project Beanstalk Console | 9/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Stored in Packagist ptrofimov/beanstalk_console prior to 1.7.14. | |
| Modificada | Media (6.1) | 0.87% | — | Beanstalk Console Project Beanstalk Console | 5/2/2022 | 17/6/2026 | Cross-site Scripting (XSS) - Reflected in Packagist ptrofimov/beanstalk_console prior to 1.7.12. | |
| Modificada | Alta (7.5) | 1.3% | — | Oracle Installed Base | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Instance Main). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of… | |
| Modificada | Alta (7.8) | 0.29% | — | Netgear Genie Installer | 30/12/2021 | 17/6/2026 | All known versions of the Netgear Genie Installer for macOS contain a local privilege escalation vulnerability. The installer of the macOS version of Netgear Genie handles certain files in an insecure way. A malicious actor who has local access to the endpoint on which the software is going to be installed may… | |
| Modificada | Alta (7.8) | 0.29% | — | Thalesgroup Sentinel Protection Installer | 20/12/2021 | 17/6/2026 | Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. | |
| Modificada | Media (6.7) | 0.22% | — | Thalesgroup Sentinel Protection Installer | 20/12/2021 | 17/6/2026 | Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. | |
| Analizada | Alta (7.1) | 10% | ⚠ Explotación activa | Microsoft APP Installer | 15/12/2021 | 6/8/2026 | We have investigated reports of a spoofing vulnerability in AppX installer that affects Microsoft Windows. Microsoft is aware of attacks that attempt to exploit this vulnerability by using specially crafted packages that include the malware family known as Emotet/Trickbot/Bazaloader. An attacker could craft a… | |
| Modificada | Alta (8.8) | 0.99% | — | Vmware Installbuilder | 29/10/2021 | 17/6/2026 | On Windows, the uninstaller binary copies itself to a fixed temporary location, which is then executed (the originally called uninstaller exits, so it does not block the installation directory). This temporary location is not randomized and does not restrict access to Administrators only so a potential attacker could… | |
| Modificada | Alta (7.8) | 0.29% | — | Vmware Installbuilder | 29/10/2021 | 17/6/2026 | Under certain circumstances, when manipulating the Windows registry, InstallBuilder uses the reg.exe system command. The full path to the command is not enforced, which results in a search in the search path until a binary can be identified. This makes the installer/uninstaller vulnerable to Path Interception by… | |
| Modificada | Crítica (9.1) | 1.8% | — | Cisco IOS XECisco IOS XE Sd-wanCisco IOS XE Sd-wan 16.10.1 When Installed ON 1000 Series Integrated ServicesCisco IOS XE Sd-wan 16.10.1 When Installed ON 4000 Series Integrated Services+142 | 23/9/2021 | 17/6/2026 | A vulnerability in the authentication, authorization, and accounting (AAA) function of Cisco IOS XE Software could allow an unauthenticated, remote attacker to bypass NETCONF or RESTCONF authentication and do either of the following: Install, manipulate, or delete the configuration of an affected device Cause memory… | |
| Modificada | Media (5.4) | 0.60% | — | Tibco Webfocus ClientTibco Webfocus InstallerTibco Webfocus Reporting Server | 14/9/2021 | 17/6/2026 | The WebFOCUS Reporting Server and WebFOCUS Client components of TIBCO Software Inc.'s TIBCO WebFOCUS Client, TIBCO WebFOCUS Installer, and TIBCO WebFOCUS Reporting Server contain easily exploitable Stored and Reflected Cross Site Scripting (XSS) vulnerabilities that allow a low privileged attacker to social engineer a… | |
| Modificada | Alta (7.8) | 0.57% | — | Microsoft .net Education Bundle SDK Install ToolMicrosoft .net Install Tool FOR Extension Authors | 14/7/2021 | 10/8/2026 | Visual Studio Code .NET Runtime Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.1) | 0.93% | — | Oracle Installed Base | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: APIs). The supported version that is affected is 12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of this vulnerability… | |
| Modificada | Alta (8.1) | 1.8% | — | Redhat Openshift Installer | 23/2/2021 | 17/6/2026 | A flaw was found in the OpenShift Installer before version v0.9.0-master.0.20210125200451-95101da940b0. During installation of OpenShift Container Platform 4 clusters, bootstrap nodes are provisioned with anonymous authentication enabled on kubelet port 10250. A remote attacker able to reach this port during… | |
| Modificada | Media (4.7) | 1.1% | — | Oracle Installed Base | 20/1/2021 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: APIs). Supported versions that are affected are 12.1.1-12.1.3 and 12.2.3-12.2.9. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful… | |
| Modificada | Crítica (9.8) | 0.93% | — | Jenkins Installation Manager Tool | 3/12/2020 | 17/6/2026 | Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads. | |
| Modificada | Alta (7.8) | 0.34% | — | Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+29 | 24/11/2020 | 17/6/2026 | Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7) | 0.28% | — | Schneider-electric Enterprise Server Installer | 19/11/2020 | 17/6/2026 | A CWE-428 Windows Unquoted Search Path vulnerability exists in EcoStruxure Building Operation Enterprise Server installer V1.9 - V3.1 and Enterprise Central installer V2.0 - V3.1 that could cause any local Windows user who has write permission on at least one of the subfolders of the Connect Agent service binary path,… | |
| Modificada | Alta (7.8) | 0.34% | — | Capasystems Capainstaller | 9/11/2020 | 17/6/2026 | CapaSystems CapaInstaller before 6.0.101 does not properly assign, modify, or check privileges for an actor who attempts to edit registry values, allowing an attacker to escalate privileges. | |
| Modificada | Media (4.7) | 1.0% | — | Oracle Installed Base | 21/10/2020 | 17/6/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: APIs). Supported versions that are affected are 12.1.1 - 12.1.3 and 12.2.3 - 12.2.10. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base. Successful… |