Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.24% | — | Nullsoft Scriptable Install System | 24/4/2026 | 17/6/2026 | NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references). | |
| Aplazada | Alta (8.1) | 0.20% | — | Nullsoft Scriptable Install SystemAI | 17/4/2025 | 17/6/2026 | Nullsoft Scriptable Install System (NSIS) before 3.11 on Windows allows local users to escalate privileges to SYSTEM during an installation, because the temporary plugins directory is created under %WINDIR%\temp and unprivileged users can place a crafted executable file by winning a race condition. This occurs because… | |
| Modificada | Media (5.3) | 0.88% | — | Nullsoft Scriptable Install System | 3/7/2023 | 17/6/2026 | Nullsoft Scriptable Install System (NSIS) before 3.09 mishandles access control for an uninstaller directory. | |
| Modificada | Alta (7.8) | 1.5% | — | Nullsoft Scriptable Install SystemDebian Linux | 1/10/2018 | 17/6/2026 | Nullsoft Scriptable Install System (NSIS) before 2.49 has unsafe implicit linking against Version.dll. In other words, there is no protection mechanism in which a wrapper function resolves the dependency at an appropriate time during runtime. | |
| Modificada | Media (5.5) | 0.39% | — | Nullsoft Scriptable Install SystemDebian Linux | 1/10/2018 | 17/6/2026 | Nullsoft Scriptable Install System (NSIS) before 2.49 uses temporary folder locations that allow unprivileged local users to overwrite files. This allows a local attack in which either a plugin or the uninstaller can be replaced by a Trojan horse program. |