Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 223 respecto a la semana anterior
Críticas / altas1373▲ 144 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.8) | 0.36% | — | Yggdrasil Worker-package-managerAI | 31/7/2026 | 3/8/2026 | A flaw was found in yggdrasil-worker-package-manager. A local attacker with existing access to the system could exploit an argument injection vulnerability in the APT backend. This allows specially crafted package names, which begin with a hyphen, to be misinterpreted as command options by apt-get. Successful… | |
| Aplazada | Media (6.9) | 0.26% | — | Intel Simics Package ManagerAI | 13/5/2025 | 17/6/2026 | Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.4) | 0.17% | — | Intel Simics Package ManagerAI | 13/5/2025 | 17/6/2026 | Insecure inherited permissions for some Intel(R) Simics(R) Package Manager software before version 1.12.0 may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.5) | 0.19% | — | Beckhoff Twincat Package ManagerAI | 31/10/2024 | 17/6/2026 | A local user with administrative access rights can enter specialy crafted values for settings at the user interface (UI) of the TwinCAT Package Manager which then causes arbitrary OS commands to be executed. | |
| Analizada | Media (5.4) | 0.14% | — | Intel Simics Package Manager | 14/8/2024 | 17/6/2026 | Uncontrolled search path for some Intel(R) Simics Package Manager software before version 1.8.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Alta (8.1) | 2.0% | — | Caphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+66 | 6/6/2022 | 9/7/2026 | Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected… | |
| Modificada | Alta (8.8) | 6.3% | — | BundlerFedoraproject FedoraMicrosoft Package Manager Configurations | 29/4/2021 | 17/6/2026 | Bundler 1.16.0 through 2.2.9 and 2.2.11 through 2.2.16 sometimes chooses a dependency source based on the highest gem version number, which means that a rogue gem found at a public source may be chosen, even if the intended choice was a private gem that is a dependency of another private gem that is explicitly… | |
| Modificada | Alta (7.8) | 2.4% | — | Microsoft Package Manager Configurations | 25/2/2021 | 17/6/2026 | <p>Depending on configuration of various package managers it is possible for an attacker to insert a malicious package into a package manager's repository which can be retrieved and used during development, build, and release processes. This insertion could lead to remote code execution. We believe this vulnerability… | |
| Modificada | Alta (8.2) | 1.1% | — | QuaggaOpensuseSuse LinuxRedhat Package Manager | 24/7/2018 | 17/6/2026 | Open Shortest Path First (OSPF) protocol implementations may improperly determine Link State Advertisement (LSA) recency for LSAs with MaxSequenceNumber. According to RFC 2328 section 13.1, for two instances of the same LSA, recency is determined by first comparing sequence numbers, then checksums, and finally MaxAge.… | |
| Modificada | Media (5.4) | 3.6% | — | RPM Package ManagerUbuntu Linux | 6/11/2006 | 16/6/2026 | Heap-based buffer overflow in the showQueryPackage function in librpm in RPM Package Manager 4.4.8, when the LANG environment variable is set to ru_RU.UTF-8, might allow user-assisted attackers to execute arbitrary code via crafted RPM packages. | |
| Modificada | Alta (7.5) | 1.5% | — | Redhat Package Manager | 31/12/2002 | 16/6/2026 | The default --checksig setting in RPM Package Manager 4.0.4 checks that a package's signature is valid without listing who signed it, which can allow remote attackers to make it appear that a malicious package comes from a trusted source. | |
| Modificada | Alta (7.2) | 0.60% | — | Redhat Package Manager | 25/10/2001 | 16/6/2026 | RPM Package Manager 4.0.x through 4.0.2.x allows an attacker to execute arbitrary code via corrupted data in the RPM file when the file is queried. |