Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5) | 0.18% | — | SAP GUI FOR WindowsAISAP GuixtAI | 10/3/2026 | 17/6/2026 | SAP GUI for Windows allows DLL files to be loaded from arbitrary directories within the application. An unauthenticated attacker could exploit this vulnerability by persuading a victim to place a malicious DLL within one of these directories. The malicious command is executed in the victim user's context provided… | |
| Aplazada | Media (5.7) | 0.14% | — | GNU GuixAI | 15/9/2025 | 17/6/2026 | In guix-daemon in GNU Guix before 1618ca7, a content-addressed-mirrors file can be written to create a setuid program that allows a regular user to gain the privileges of the build user that runs it (even after the build has ended). | |
| Aplazada | Media (5.6) | 0.14% | — | GuixtAISAP GUI FOR WindowsAI | 8/7/2025 | 17/6/2026 | The GuiXT application, which is integrated with SAP GUI for Windows, uses obfuscation algorithms instead of secure symmetric ciphers for storing the credentials of an RFC user on the client PC. This leads to a high impact on confidentiality because any attacker who gains access to the user hive of this user�s windows… | |
| Aplazada | Media (5.6) | 0.14% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | A race condition in the Nix, Lix, and Guix package managers enables changing the ownership of arbitrary files to the UID and GID of the build user (e.g., nixbld* or guixbuild*). This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Aplazada | Baja (3.2) | 0.17% | — | Nixos NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers fail to properly set permissions when a derivation build fails. This may allow arbitrary processes to modify the content of a store outside of the build sandbox. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before… | |
| Aplazada | Baja (3.2) | 0.17% | — | Nixos NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers default to using temporary build directories in a world-readable and world-writable location. This allows standard users to deceive the package manager into using directories with pre-existing content, potentially leading to unauthorized actions or data manipulation. This… | |
| Aplazada | Baja (2.9) | 0.18% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | The Nix, Lix, and Guix package managers allow a bypass of build isolation in which a user can elevate their privileges to the build user account (e.g., nixbld or guixbuild). This affects Nix through 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix through 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Aplazada | Baja (3.2) | 0.14% | — | NIXAILIXAIGNU GuixAI | 27/6/2025 | 17/6/2026 | A race condition in the Nix, Lix, and Guix package managers allows the removal of content from arbitrary folders. This affects Nix before 2.24.15, 2.26.4, 2.28.4, and 2.29.1; Lix before 2.91.2, 2.92.2, and 2.93.1; and Guix before 1.4.0-38.0e79d5b. | |
| Aplazada | Media (4.3) | 0.18% | — | SAP GUI FOR WindowsAIGuixtAI | 13/5/2025 | 17/6/2026 | SAP GUI for Windows allows an unauthenticated attacker to exploit insecure obfuscation algorithms used by the GuiXT application to store user credentials. While this issue does not impact the Integrity or Availability of the application, it may have a Low impact on the Confidentiality of data. | |
| Aplazada | Alta (8.1) | 0.23% | — | GNU GuixAI | 17/11/2024 | 17/6/2026 | guix-daemon in GNU Guix before 5ab3c4c allows privilege escalation because build outputs are accessible by local users before file metadata concerns (e.g., for setuid and setgid programs) are properly addressed. The vulnerability can be remediated within the product via certain pull, reconfigure, and restart actions.… | |
| Modificada | Alta (7.8) | 0.76% | — | Microsoft Azure Rtos Guix Studio | 10/10/2023 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.80% | — | Microsoft Azure Rtos Guix Studio | 9/11/2022 | 10/8/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.98% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.88% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.83% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 0.83% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.93% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | |
| Modificada | Media (5.5) | 0.93% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 1.00% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 1.2% | — | Microsoft Azure Real Time Operating System Guix Studio | 9/8/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.2% | — | Microsoft Azure Real Time Operating System Guix Studio | 15/6/2022 | 17/6/2026 | Azure RTOS GUIX Studio Information Disclosure Vulnerability | |
| Modificada | Alta (7.8) | 2.5% | — | Microsoft Azure Real Time Operating System Guix Studio | 15/6/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.2% | — | Microsoft Azure Real Time Operating System Guix Studio | 15/6/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Alta (7.8) | 2.2% | — | Microsoft Azure Real Time Operating System Guix Studio | 15/6/2022 | 17/6/2026 | Azure RTOS GUIX Studio Remote Code Execution Vulnerability | |
| Modificada | Media (5.5) | 0.33% | — | GNU Guix | 26/4/2021 | 17/6/2026 | A security vulnerability that can lead to local privilege escalation has been found in ’guix-daemon’. It affects multi-user setups in which ’guix-daemon’ runs locally. The attack consists in having an unprivileged user spawn a build process, for instance with `guix build`, that makes its build directory… |