Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.20% | — | Chiranjit Hazarika Smart ONE Click SetupAI | 2/10/2026 | 2/10/2026 | Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click-setup allows Retrieve Embedded Sensitive Data.This issue affects Smart One Click Setup – Complete Demo Import & Export: from n/a through 1.4.3. | |
| Analizada | Alta (7.5) | 0.33% | — | Oracle Isetup | 18/8/2026 | 31/8/2026 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful… | |
| Analizada | Media (6.8) | 0.29% | — | Oracle Isetup | 21/7/2026 | 29/7/2026 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful… | |
| Analizada | Crítica (9.8) | 2.0% | 💥 PoC | Shivammathur Setup PHP | 17/7/2026 | 18/8/2026 | setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled files such as .php-version, composer.lock through platform-overrides.php, and composer.json through… | |
| Analizada | Media (6.1) | 0.40% | — | Python Setuptools | 8/7/2026 | 13/7/2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Isetup | 17/6/2026 | 18/6/2026 | Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful… | |
| Analizada | Crítica (9.4) | 1.7% | ⚠ Explotación activa💥 PoC | Aquasec Setup-trivyAquasec TrivyAquasec Trivy ActionLitellm+1 | 23/3/2026 | 17/6/2026 | Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This… | |
| Analizada | Media (5.7) | 0.09% | — | Jrsoftware Inno Setup | 3/3/2026 | 17/6/2026 | Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions. | |
| Aplazada | Baja (2.9) | 0.24% | — | GE Vernova Enervista UR SetupAI | 10/2/2026 | 17/6/2026 | A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions. | |
| Aplazada | Alta (8.8) | 0.46% | — | Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI | 9/1/2026 | 17/6/2026 | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session… | |
| Aplazada | Alta (8.8) | 0.38% | — | Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI | 9/1/2026 | 17/6/2026 | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an… | |
| Aplazada | Alta (8.7) | 0.12% | — | Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI | 9/1/2026 | 17/6/2026 | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting… | |
| Aplazada | Alta (8.7) | 0.12% | — | Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI | 9/1/2026 | 17/6/2026 | This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this… | |
| Aplazada | Alta (8.3) | 0.11% | — | CryptsetupAIConstellationAI | 27/10/2025 | 17/6/2026 | Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persistent storage. When opening an encrypted storage device, the CVM uses the libcryptsetup function crypt_activate_by_passhrase. If the VM is successful in opening the partition with the disk encryption… | |
| Aplazada | Alta (8.7) | 3.9% | — | Avtech Cloudsetup.cgiAI | 9/10/2025 | 17/6/2026 | AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can… | |
| Aplazada | Media (4.4) | 0.18% | — | Conda-forge Conda Forge CI SetupAI | 13/6/2025 | 17/6/2026 | conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feedstock setup script is vulnerable due to the unsafe use of the eval function when parsing version information from a custom-formatted meta.yaml file. An attacker controlling meta.yaml can inject… | |
| Analizada | Alta (7.7) | 1.5% | 💥 PoC | Python SetuptoolsDebian Linux | 17/5/2025 | 17/6/2026 | setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of… | |
| Aplazada | Media (6.7) | 0.16% | — | IBM System XAIIBM TpmsetupAI | 11/4/2025 | 17/6/2026 | An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory. | |
| Analizada | Alta (8.6) | 2.4% | ⚠ Explotación activa | Reviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+2 | 19/3/2025 | 17/6/2026 | reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be… | |
| Aplazada | Media (6.1) | 0.18% | — | GE Vernova UR IEDAIGE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed. | |
| Aplazada | Alta (8.3) | 0.28% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network. | |
| Aplazada | Alta (8) | 0.15% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code. | |
| Aplazada | Alta (8) | 0.19% | — | GE Vernova Enervista UR SetupAI | 10/3/2025 | 17/6/2026 | CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify. | |
| Analizada | Media (5.5) | 0.13% | — | Samsung Easysetup | 4/2/2025 | 17/6/2026 | Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information. | |
| Aplazada | Media (6.5) | 0.41% | — | Setup Default Featured ImageAI | 3/2/2025 | 17/6/2026 | Missing Authorization vulnerability in theme funda Setup Default Featured Image setup-default-feature-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Setup Default Featured Image: from n/a through <= 1.2. |