Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

27 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (5)0.18%—SAP GUI FOR WindowsAISAP GuixtAI10/3/202617/6/2026
SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided…
AplazadaMedia (5.7)0.14%—GNU GuixAI15/9/202517/6/2026
In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended).
AplazadaMedia (5.6)0.14%—GuixtAISAP GUI FOR WindowsAI8/7/202517/6/2026
The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows…
AplazadaMedia (5.6)0.14%—NIXAILIXAIGNU GuixAI27/6/202517/6/2026
A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
AplazadaBaja (3.2)0.17%—Nixos NIXAILIXAIGNU GuixAI27/6/202517/6/2026
The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before…
AplazadaBaja (3.2)0.17%—Nixos NIXAILIXAIGNU GuixAI27/6/202517/6/2026
The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This…
AplazadaBaja (2.9)0.18%—NIXAILIXAIGNU GuixAI27/6/202517/6/2026
The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
AplazadaBaja (3.2)0.14%—NIXAILIXAIGNU GuixAI27/6/202517/6/2026
A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b.
AplazadaMedia (4.3)0.18%—SAP GUI FOR WindowsAIGuixtAI13/5/202517/6/2026
SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT application to store user credentials. While this issue does not impact the Integrity or Availability of the application, it may have a Low impact on the Confidentiality of data.
AplazadaAlta (8.1)0.23%—GNU GuixAI17/11/202417/6/2026
guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, and restart actions.…
ModificadaAlta (7.8)0.76%—Microsoft Azure Rtos Guix Studio10/10/202317/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.80%—Microsoft Azure Rtos Guix Studio9/11/202210/8/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.98%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.88%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.83%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)0.83%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.93%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaMedia (5.5)0.93%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaAlta (7.8)1.00%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)1.2%—Microsoft Azure Real Time Operating System Guix Studio9/8/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)2.2%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Information Disclosure Vulnerability
ModificadaAlta (7.8)2.5%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)2.2%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaAlta (7.8)2.2%—Microsoft Azure Real Time Operating System Guix Studio15/6/202217/6/2026
Azure RTOS GUIX Studio Remote Code Execution Vulnerability
ModificadaMedia (5.5)0.33%—GNU Guix26/4/202117/6/2026
A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance with `guix build`, that makes its build directory…