Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2733▼ 589 respecto a la semana anterior
Críticas / altas1313▼ 190 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)294▼ 216 respecto a la semana anterior
243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.5) | 0.39% | — | Keycloak-httpd-client-install Project Keycloak-httpd-client-install | 20/1/2018 | 17/6/2026 | keycloak-httpd-client-install versions before 0.8 insecurely creates temporary file allowing local attackers to overwrite other files via symbolic link. | |
| Modificada | Media (4.3) | 0.95% | — | Oracle Siebel Engineering-installer AND Deployment | 18/1/2018 | 17/6/2026 | Vulnerability in the Siebel Engineering - Installer and Deployment component of Oracle Siebel CRM (subcomponent: Siebel Approval Manager). Supported versions that are affected are 16.0 and 17.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Siebel… | |
| Modificada | Baja (3.7) | 0.61% | — | Install Norton Security | 22/11/2017 | 17/6/2026 | Prior to v 7.6, the Install Norton Security (INS) product can be susceptible to a certificate spoofing vulnerability, which is a type of attack whereby a maliciously procured certificate binds the public key of an attacker to the domain name of the target. | |
| Modificada | Alta (7) | 0.38% | — | Norton Remove & Reinstall | 28/9/2017 | 17/6/2026 | Norton Remove & Reinstall can be susceptible to a DLL preloading vulnerability. These types of issues occur when an application looks to call a DLL for execution and an attacker provides a malicious DLL to use instead. Depending on how the application is configured, it will generally follow a specific search path to… | |
| Modificada | Alta (7.8) | 1.8% | — | DAJ I-filter Installer | 15/9/2017 | 17/6/2026 | Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.1% | — | DAJ I-filter Installer | 15/9/2017 | 17/6/2026 | Untrusted search path vulnerability in "i-filter 6.0 installer" timestamp of code signing is before 23 Aug 2017 (JST) allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.1% | — | DAJ I-filter Installer | 15/9/2017 | 17/6/2026 | Untrusted search path vulnerability in "i-filter 6.0 install program" file version 1.0.8.1 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 1.1% | — | NTT Flets Install Tool | 29/8/2017 | 17/6/2026 | Untrusted search path vulnerability in Flets Install Tool all versions distributed through the website till 2017 August 8 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.99% | — | Sandboxie Installer | 6/8/2017 | 17/6/2026 | Sandboxie installer 5071703 has a DLL Hijacking or Unsafe DLL Loading Vulnerability via a Trojan horse dwmapi.dll or profapi.dll file in an AppData\Local\Temp directory. | |
| Modificada | Alta (7.8) | 1.1% | — | Sony NFC Port FirmwareSony Pc/sc Activator FOR Type BSony Sfcard Viewer 2Sony NFC NET Installer | 2/8/2017 | 17/6/2026 | Untrusted search path vulnerability in NFC Port Software Version 5.5.0.6 and earlier (for RC-S310, RC-S320, RC-S330, RC-S370, RC-S380, RC-S380/S), NFC Port Software Version 5.3.6.7 and earlier (for RC-S320, RC-S310/J1C, RC-S310/ED4C), PC/SC Activator for Type B Ver.1.2.1.0 and earlier, SFCard Viewer 2 Ver.2.5.0.0 and… | |
| Modificada | Alta (7.8) | 1.4% | — | Acquisition Technology AND Logistics Agency Installer OF Electronic Tendering | 7/7/2017 | 17/6/2026 | Untrusted search path vulnerability in Installer of Electronic tendering and bid opening system available prior to June 12, 2017 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Alta (7) | 0.26% | — | Fedoraproject ARM Installer | 26/6/2017 | 17/6/2026 | fedora-arm-installer up to and including 1.99.16 is vulnerable to local privilege escalation due to lack of checking the error condition of mount operation failure on unsafely created temporary directories. | |
| Modificada | Alta (7.5) | 0.73% | — | Lenovo Advanced Settings UtilityLenovo Toolscenter Dynamic System AnalysisLenovo Updatexpress System Pack Installer | 20/6/2017 | 17/6/2026 | If multiple users are concurrently logged into a single system where one user is sending a command via the Lenovo ToolsCenter Advanced Settings Utility (ASU), UpdateXpress System Pack Installer (UXSPI) or Dynamic System Analysis (DSA) to a second machine, the other users may be able to see the user ID and clear text… | |
| Modificada | Crítica (9.8) | 2.3% | — | Redhat Quickstart Cloud Installer | 13/6/2017 | 17/6/2026 | /var/lib/ovirt-engine/setup/engine-DC-config.py in Red Hat QuickStart Cloud Installer (QCI) before 1.0 GA is created world readable and contains the root password of the deployed system. | |
| Modificada | Alta (7.8) | 1.1% | — | Santeikohyo Installer OF Houkokusyo Sakusei Shien Tool | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in the installer of Houkokusyo Sakusei Shien Tool ver3.0.2 (For the first installation) (The version which was available on the website from 2017 April 4 to 2017 May 18) and ver2.0 and later (For the first installation) (The versions which were available on the website prior to 2017… | |
| Modificada | Alta (7.8) | 1.1% | — | Sharp Rw-5100 Driver Installer FOR Windows 7Sharp Rw-5100 Driver Installer FOR Windows 8.1 | 9/6/2017 | 17/6/2026 | Untrusted search path vulnerability in RW-5100 driver installer for Windows 7 version 1.0.0.9 and RW-5100 driver installer for Windows 8.1 version 1.0.1.0 allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 2.5% | — | Vivaldi Installer FOR Windows | 28/4/2017 | 17/6/2026 | Untrusted search path vulnerability in Vivaldi installer for Windows prior to version 1.7.735.48 allows an attacker to execute arbitrary code via a specially crafted executable file in an unspecified directory. | |
| Modificada | Crítica (9.8) | 90% | 💥 Exploit | Apache Log4jNetapp Oncommand API ServicesNetapp Oncommand InsightNetapp Oncommand Workflow Automation+75 | 17/4/2017 | 17/6/2026 | In Apache Log4j 2.x before 2.8.2, when using the TCP socket server or UDP socket server to receive serialized log events from another application, a specially crafted binary payload can be sent that, when deserialized, can execute arbitrary code. | |
| Modificada | Media (4.6) | 0.42% | — | Redhat Quickstart Cloud Installer | 14/4/2017 | 17/6/2026 | The web interface in Red Hat QuickStart Cloud Installer (QCI) 1.0 does not mask passwords fields, which allows physically proximate attackers to obtain sensitive password information by reading the display. | |
| Modificada | Alta (8.2) | 1.6% | — | Oracle Installed Base | 27/1/2017 | 17/6/2026 | Vulnerability in the Oracle Installed Base component of Oracle E-Business Suite (subcomponent: User Interface). Supported versions that are affected are 12.1.1, 12.1.2 and 12.1.3. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Installed Base.… | |
| Modificada | Alta (8.4) | 0.39% | — | Redhat Quickstart Cloud Installer | 22/9/2016 | 17/6/2026 | The kickstart file in Red Hat QuickStart Cloud Installer (QCI) forces use of MD5 passwords on deployed systems, which makes it easier for attackers to determine cleartext passwords via a brute-force attack. | |
| Modificada | Alta (8.4) | 0.39% | — | Redhat Quickstart Cloud Installer | 22/9/2016 | 17/6/2026 | Red Hat QuickStart Cloud Installer (QCI) uses world-readable permissions for /etc/qci/answers, which allows local users to obtain the root password for the deployed system by reading the file. | |
| Modificada | Media (6.1) | 0.77% | — | Cisco Transport Gateway Installation Software | 22/8/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Cisco Transport Gateway Installation Software 4.1(4.0) on Smart Call Home Transport Gateway devices allows remote attackers to inject arbitrary web script or HTML via a crafted value, aka Bug IDs CSCva40650 and CSCva40817. | |
| Modificada | Alta (7.8) | 0.39% | — | Pulsesecure Odyssey Access ClientPulsesecure Pulse Secure DesktopPulsesecure Pulse Secure SecurityPulsesecure Standalone Pulse Installer Service | 2/8/2016 | 17/6/2026 | Pulse Secure Desktop before 5.2R2 and Pulse Secure Installer Service before 8.2R2 and below for Windows allow restricted users to gain privileges via unspecified vectors. | |
| Modificada | Media (4.7) | 2.0% | — | Oracle Installed Base | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Oracle Installed Base component in Oracle E-Business Suite 12.1.1, 12.1.2, 12.1.3, 12.2.3, 12.2.4, and 12.2.5 allows remote attackers to affect integrity via vectors related to Engineering Change Order. NOTE: the previous information is from the July 2016 CPU. Oracle has not commented… |