Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2748▲ 38 respecto a la semana anterior
Críticas / altas1479▲ 369 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
132 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.17% | — | Iobit UninstallerAI | 12/9/2026 | 14/9/2026 | A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been published and may be used. Identical… | |
| Aplazada | Media (4.8) | 0.14% | — | Iobit UninstallerAI | 31/8/2026 | 31/8/2026 | A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Handler. Executing a manipulation can lead to improper privilege management. The attack requires local access. The vendor was contacted early about this… | |
| Aplazada | Alta (7) | 0.17% | — | Electron-builderAIMicrosoft Windows InstallerAI | 30/8/2026 | 1/9/2026 | SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that… | |
| Analizada | Media (5.5) | 0.15% | — | Autodesk Installer | 12/8/2026 | 4/9/2026 | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate… | |
| Analizada | Alta (7.8) | 0.15% | — | Autodesk Installer | 12/8/2026 | 4/9/2026 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft APP Installer | 11/8/2026 | 29/8/2026 | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. | |
| Modificada | Alta (8.6) | 0.30% | — | Adobe Photoshop Installer | 28/7/2026 | 26/8/2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation… | |
| Aplazada | Alta (7.1) | 0.14% | — | VS Revo RevouninstallerAI | 15/6/2026 | 24/7/2026 | A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and… | |
| Aplazada | Alta (8.5) | 0.12% | — | Iobit UninstallerAI | 13/5/2026 | 17/6/2026 | IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to execute code with… | |
| Analizada | Alta (8.4) | 0.18% | — | Liveon Canonnwcamplugin.exeLiveon Canonnwcampluginforadmin.exeLiveon Downloader5installer.exeLiveon Downloader5installerforadmin.exe | 23/4/2026 | 17/6/2026 | The installers of LiveOn Meet Client for Windows (Downloader5Installer.exe and Downloader5InstallerForAdmin.exe) and the installers of Canon Network Camera Plugin (CanonNWCamPlugin.exe and CanonNWCamPluginForAdmin.exe) insecurely load Dynamic Link Libraries (DLLs). If a malicious DLL is placed at the same directory,… | |
| Analizada | Alta (8.6) | 0.31% | — | Adobe Photoshop Installer | 15/4/2026 | 29/7/2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation… | |
| Pendiente de análisis | Alta (8.8) | 0.13% | — | Microsoft Directx End-user Runtime WEB InstallerAI | 11/3/2026 | 17/6/2026 | In Microsoft DirectX End-User Runtime Web Installer 9.29.1974.0, a low-privilege user can replace an executable file during the installation process, which may result in unintended elevation of privileges. During installation, the installer runs with HIGH integrity and downloads executables and DLLs to the %TEMP%… | |
| Aplazada | Alta (7.8) | 0.13% | — | Epson Printer Driver InstallerAI | 19/2/2026 | 17/6/2026 | The com.epson.InstallNavi.helper tool, deployed with the EPSON printer driver installer, contains a local privilege escalation vulnerability due to multiple flaws in its implementation. It fails to properly authenticate clients over the XPC protocol and does not correctly enforce macOS’s authorization model, exposing… | |
| Aplazada | Alta (7.8) | 0.14% | — | AMD Software InstallerAI | 11/2/2026 | 17/6/2026 | A DLL hijacking vulnerability in the AMD Software Installer could allow an attacker to achieve privilege escalation potentially resulting in arbitrary code execution. | |
| Aplazada | Alta (8.5) | 0.17% | — | Iobit UninstallerAI | 26/1/2026 | 17/6/2026 | IObit Uninstaller 10 Pro contains an unquoted service path vulnerability that allows local users to potentially execute code with elevated system privileges. Attackers can exploit the unquoted service path in the IObit Uninstaller Service to insert malicious code that would execute with SYSTEM-level permissions during… | |
| Aplazada | Alta (8.5) | 0.17% | — | HTC IptinstallerAI | 25/1/2026 | 17/6/2026 | HTC IPTInstaller 4.0.9 contains an unquoted service path vulnerability in the PassThru Service configuration. Attackers can exploit the unquoted binary path to inject and execute malicious code with elevated LocalSystem privileges. | |
| Aplazada | Alta (8.5) | 0.18% | — | Pioneer Corporation InstallerAI | 8/1/2026 | 17/6/2026 | The installers for multiple products provided by PIONEER CORPORATION contain an issue with the DLL search path, which may lead to insecurely loading Dynamic Link Libraries. As a result, arbitrary code may be executed with the privileges of the running installer. | |
| Analizada | Alta (7.8) | 0.15% | — | Autodesk Installer | 6/11/2025 | 17/6/2026 | A maliciously crafted file, when executed on the victim's machine, can lead to privilege escalation to NT AUTHORITY/SYSTEM due to an insufficient validation of loaded binaries. An attacker with local and low-privilege access could exploit this to execute code as SYSTEM. | |
| Aplazada | Alta (7.8) | 0.15% | — | Nvidia Installer FOR Nvapp FOR WindowsAINvidia Frameview SDKAI | 1/10/2025 | 17/6/2026 | NVIDIA Installer for NvAPP for Windows contains a vulnerability in the FrameviewSDK installation process, where an attacker with local unprivileged access could modify files in the Frameview SDK directory. A successful exploit of this vulnerability might lead to escalation of privileges. | |
| Aplazada | Alta (7) | 0.13% | — | PyinstallerAI | 9/9/2025 | 17/6/2026 | PyInstaller bundles a Python application and all its dependencies into a single package. Due to a special entry being appended to `sys.path` during the bootstrap process of a PyInstaller-frozen application, and due to the bootstrap script attempting to load an optional module for bytecode decryption while this entry… | |
| Aplazada | Alta (7) | 0.10% | — | Nvidia RUN InstallerAI | 2/8/2025 | 17/6/2026 | NVIDIA .run Installer for Linux and Solaris contains a vulnerability where an attacker could use a race condition to escalate privileges. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, information disclosure, denial of service, or data tampering. | |
| Aplazada | Alta (7.8) | 0.17% | — | Nvidia Installer FOR WindowsAI | 2/8/2025 | 17/6/2026 | NVIDIA Installer for Windows contains a vulnerability where an attacker may be able to escalate privileges. A successful exploit of this vulnerability may lead to escalation of privileges, denial of service, code execution, information disclosure and data tampering. | |
| Aplazada | Alta (7.5) | 0.50% | — | Caphyon Advanced InstallerAI | 8/7/2025 | 17/6/2026 | Advanced Installer before 22.6 has an uncontrolled search path element local privilege escalation vulnerability. When running as SYSTEM in certain configurations, Advanced Installer looks in standard-user writable locations for non-existent binaries and executes them as SYSTEM. A low-privileged attacker can place a… | |
| Analizada | Alta (7.8) | 0.21% | — | Autodesk Installer | 10/6/2025 | 17/6/2026 | A maliciously crafted binary file when downloaded could lead to escalation of privileges to NT AUTHORITY/SYSTEM due to an untrusted search path being utilized in the Autodesk Installer application. Exploitation of this vulnerability may lead to code execution. | |
| Aplazada | Media (6.9) | 0.23% | — | Lantronix Device InstallerAI | 22/5/2025 | 17/6/2026 | Lantronix Device installer is vulnerable to XML external entity (XXE) attacks in configuration files read from the network device. An attacker could obtain credentials, access these network devices, and modify their configurations. An attacker may also gain access to the host running the Device Installer software or… |