Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
243 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.7) | 1.8% | — | Oracle Siebel Engineering-installer AND Deployment | 21/7/2016 | 17/6/2026 | Unspecified vulnerability in the Siebel Engineering - Installer and Deployment component in Oracle Siebel CRM 8.1.1, 8.2.2, IP2014, IP2015, and IP2016 allows remote authenticated users to affect confidentiality via vectors related to Web Server. | |
| Modificada | Alta (7.8) | 0.38% | — | Linecorp LineLinecorp Line Installer | 12/7/2016 | 17/6/2026 | Untrusted search path vulnerability in LINE and LINE Installer 4.7.0 and earlier on Windows allows local users to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.54% | — | Flexerasoftware Installanywhere | 2/7/2016 | 17/6/2026 | Untrusted search path vulnerability in Flexera InstallAnywhere allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file. | |
| Modificada | Alta (7.8) | 0.50% | — | Flexera Installshield | 24/2/2016 | 17/6/2026 | Untrusted search path vulnerability in Flexera InstallShield through 2015 SP1 allows local users to gain privileges via a Trojan horse DLL in the current working directory of a setup-launcher executable file. | |
| Modificada | Alta (7) | 0.42% | — | IBM Installation ManagerIBM Packaging Utility | 2/1/2016 | 17/6/2026 | consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value. | |
| Modificada | Baja (1.2) | 0.33% | — | IBM Installation ManagerIBM Rational Clearcase | 25/3/2015 | 17/6/2026 | IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation… | |
| Modificada | Baja (2.1) | 0.31% | — | IBM ServerguideIBM Toolscenter SuiteIBM Updatexpress System Packs Installer | 17/1/2015 | 17/6/2026 | IBM ServerGuide before 9.63, UpdateXpress System Packs Installer (UXSPI) before 9.63, and ToolsCenter Suite before 9.63 place credentials in logs, which allows local users to obtain sensitive information by reading a file. | |
| Modificada | Alta (7.2) | 0.95% | — | Realnetworks Realarcade Installer | 12/1/2015 | 16/6/2026 | RealNetworks GameHouse RealArcade Installer (aka ActiveMARK Game Installer) 2.6.0.481 and 3.0.7 uses weak permissions (Create Files/Write Data) for the GameHouse Games directory tree, which allows local users to gain privileges via a Trojan horse DLL in an individual game's directory, as demonstrated by DDRAW.DLL in… | |
| Modificada | Alta (10) | 4.2% | — | Realnetworks Realarcade Installer | 12/1/2015 | 16/6/2026 | The RACInstaller.StateCtrl.1 ActiveX control in InstallerDlg.dll in RealNetworks GameHouse RealArcade Installer 2.6.0.481 performs unexpected type conversions for invalid parameter types, which allows remote attackers to execute arbitrary code or cause a denial of service (use-after-free) via crafted arguments to the… | |
| Modificada | Alta (7.5) | 1.3% | 💥 Exploit | Installatron Gatequest File Manager | 2/1/2015 | 17/6/2026 | SQL injection vulnerability in incl/create.inc.php in Installatron GQ File Manager 0.2.5 allows remote attackers to execute arbitrary SQL commands via the create parameter to index.php. NOTE: this can be leveraged for cross-site scripting (XSS) attacks by creating a file that generates an error. NOTE: this issue was… | |
| Modificada | Media (5.4) | 0.27% | — | Trafficgate Rakuten Install | 4/10/2014 | 17/6/2026 | The Rakuten Install (aka co.jp.rakuten.installapp) application 1.5.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.2) | 0.39% | — | Juniper Installer Service ClientJuniper Junos Pulse Client | 29/9/2014 | 17/6/2026 | Juniper Installer Service (JIS) Client 7.x before 7.4R6 for Windows and Junos Pulse Client before 4.0R6 allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (6.3) | 1.9% | — | Cisco Transport Gateway Installation Software | 29/8/2014 | 17/6/2026 | The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) does not validate an unspecified parameter, which allows remote authenticated users to cause a denial of service (service crash) via a crafted string, aka Bug ID CSCuq31819. | |
| Modificada | Media (5) | 2.2% | — | Cisco Transport Gateway Installation Software | 28/8/2014 | 17/6/2026 | The web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 does not properly check authorization for administrative web pages, which allows remote attackers to modify the product via a crafted URL, aka Bug ID CSCuq31503. | |
| Modificada | Media (4.3) | 2.0% | — | Cisco Transport Gateway Installation Software | 28/8/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the web framework in Cisco Transport Gateway for Smart Call Home (aka TG-SCH or Transport Gateway Installation Software) 4.0 allow remote attackers to inject arbitrary web script or HTML via unspecified parameters, aka Bug IDs CSCuq31129, CSCuq31134, CSCuq31137,… | |
| Modificada | Baja (2.1) | 0.46% | — | Katello Installer | 14/5/2014 | 16/6/2026 | Katello Installer before 0.0.18 uses world-readable permissions for /etc/pki/tls/private/katello-node.key when deploying a child Pulp node, which allows local users to obtain the private key by reading the file. | |
| Modificada | Baja (2.1) | 0.30% | — | Flexerasoftware Installshield | 19/1/2012 | 16/6/2026 | Flexera Macrovision InstallShield before 2008 sends a digital-signature password to an unintended application during certain signature operations involving .spc and .pvk files, which might allow local users to obtain sensitive information via unspecified vectors, related to an incorrect interaction between… | |
| Modificada | Alta (9.3) | 7.6% | — | Rockwellautomation RslinxRockwellautomation EDS Hardware Installation Tool | 22/6/2011 | 16/6/2026 | Buffer overflow in RSEds.dll in RSHWare.exe in the EDS Hardware Installation Tool 1.0.5.1 and earlier in Rockwell Automation RSLinx Classic before 2.58 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed .eds file. | |
| Modificada | Media (4.3) | 1.3% | — | Apple InstallerApple MAC OS XApple MAC OS X Server | 23/3/2011 | 16/6/2026 | Install Helper in Installer in Apple Mac OS X before 10.6.7 does not properly process an unspecified URL, which might allow remote attackers to track user logins by logging network traffic from an agent that was intended to send network traffic to an Apple server. | |
| Modificada | Alta (9.3) | 4.8% | — | Sonicwall Ssl-vpn End-point Interrogator/installer Activex Control | 3/11/2010 | 16/6/2026 | Stack-based buffer overflow in SonicWALL SSL-VPN End-Point Interrogator/Installer ActiveX control (Aventail.EPInstaller) before 10.5.2 and 10.0.5 hotfix 3 allows remote attackers to execute arbitrary code via long (1) CabURL and (2) Location arguments to the Install3rdPartyComponent method. | |
| Modificada | Media (6.8) | 0.94% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1968. | |
| Modificada | Media (4.6) | 0.47% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data, and consequently gain privileges, via unknown vectors. | |
| Modificada | Media (6.8) | 0.94% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in HP Insight Software Installer for Windows before 6.1 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors, a different vulnerability than CVE-2010-1971. | |
| Modificada | Baja (3.6) | 0.47% | — | HP Insight Software Installer | 15/7/2010 | 16/6/2026 | Unspecified vulnerability in HP Insight Software Installer for Windows before 6.1 allows local users to read or modify data via unknown vectors. | |
| Modificada | Alta (9.3) | 5.5% | 💥 Exploit | IBM Installation Manager | 1/10/2009 | 16/6/2026 | Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname. |