Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.42% | — | Microsoft Autoupdate | 9/9/2025 | 17/6/2026 | Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 0.39% | — | Microsoft Autoupdate | 10/6/2025 | 17/6/2026 | Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 1.1% | — | Microsoft Autoupdate | 8/4/2025 | 17/6/2026 | Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.8) | 1.1% | — | Microsoft Autoupdate | 8/4/2025 | 17/6/2026 | Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7) | 0.37% | — | Microsoft Autoupdate | 11/2/2025 | 17/6/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 0.45% | — | Microsoft Autoupdate | 14/1/2025 | 17/6/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 0.48% | — | Microsoft Autoupdate | 10/9/2024 | 10/8/2026 | Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability | |
| Aplazada | Crítica (9.8) | 0.67% | — | Helloshop DeliveryorderautoupdateAI | 29/4/2024 | 17/6/2026 | SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function. | |
| Modificada | Alta (7.8) | 1.0% | — | Microsoft Autoupdate | 15/4/2020 | 17/6/2026 | An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'. | |
| Modificada | Crítica (9.8) | 2.3% | — | Rbsoft Autoupdater.net | 23/3/2020 | 17/6/2026 | AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE. | |
| Modificada | Alta (10) | 4.6% | — | Creative Autoupdate Engine Activex ControlCreative Autoupdate | 15/6/2010 | 16/6/2026 | Stack-based buffer overflow in Creative Software AutoUpdate Engine ActiveX Control 2.0.12.0, as used in Creative Software AutoUpdate 1.40.01, allows remote attackers to execute arbitrary code via vectors related to the BrowseFolder method. | |
| Modificada | Alta (9.3) | 41% | — | Creative Software Autoupdate Engine | 29/5/2008 | 16/6/2026 | Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value. |