Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2633▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)58▼ 469 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.8)0.42%—Microsoft Autoupdate9/9/202517/6/2026
Improper link resolution before file access ('link following') in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)0.39%—Microsoft Autoupdate10/6/202517/6/2026
Improper input validation in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)1.1%—Microsoft Autoupdate8/4/202517/6/2026
Incorrect default permissions in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.8)1.1%—Microsoft Autoupdate8/4/202517/6/2026
Improper privilege management in Microsoft AutoUpdate (MAU) allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7)0.37%—Microsoft Autoupdate11/2/202517/6/2026
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)0.45%—Microsoft Autoupdate14/1/202517/6/2026
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)0.48%—Microsoft Autoupdate10/9/202410/8/2026
Microsoft AutoUpdate (MAU) Elevation of Privilege Vulnerability
AplazadaCrítica (9.8)0.67%—Helloshop DeliveryorderautoupdateAI29/4/202417/6/2026
SQL Injection vulnerability in Helloshop deliveryorderautoupdate v.2.8.1 and before allows an attacker to run arbitrary SQL commands via the DeliveryorderautoupdateOrdersModuleFrontController::initContent function.
ModificadaAlta (7.8)1.0%—Microsoft Autoupdate15/4/202017/6/2026
An elevation of privilege vulnerability exists when the Microsoft AutoUpdate (MAU) application for Mac improperly validates updates before executing them, aka 'Microsoft (MAU) Office Elevation of Privilege Vulnerability'.
ModificadaCrítica (9.8)2.3%—Rbsoft Autoupdater.net23/3/202017/6/2026
AutoUpdater.cs in AutoUpdater.NET before 1.5.8 allows XXE.
ModificadaAlta (10)4.6%—Creative Autoupdate Engine Activex ControlCreative Autoupdate15/6/201016/6/2026
Stack-based buffer overflow in Creative Software AutoUpdate Engine ActiveX Control 2.0.12.0, as used in Creative Software AutoUpdate 1.40.01, allows remote attackers to execute arbitrary code via vectors related to the BrowseFolder method.
ModificadaAlta (9.3)41%—Creative Software Autoupdate Engine29/5/200816/6/2026
Stack-based buffer overflow in the Creative Software AutoUpdate Engine ActiveX control in CTSUEng.ocx allows remote attackers to execute arbitrary code via a long CacheFolder property value.