Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
20 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.19% | — | Splashtop Software UpdaterAI | 13/1/2026 | 17/6/2026 | Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and… | |
| Aplazada | Media (4.7) | 0.13% | — | SAP Netweaver JavaAISAP Software Update ManagerAI | 12/11/2024 | 17/6/2026 | In SAP NetWeaver Java (Software Update Manager 1.1), under certain conditions when a software upgrade encounters errors, credentials are written in plaintext to a log file. An attacker with local access to the server, authenticated as a non-administrative user, can acquire the credentials from the logs. This leads to… | |
| Aplazada | Alta (7.8) | 2.0% | — | Elefant Software UpdaterAI | 8/11/2024 | 17/6/2026 | An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service which is running as… | |
| Modificada | Alta (7.8) | 1.0% | — | Schneider-electric Software Update | 13/4/2022 | 17/6/2026 | A CWE-502: Deserialization of Untrusted Data vulnerability exists which could allow an attacker to execute arbitrary code on the targeted system with SYSTEM privileges when placing a malicious user to be authenticated for this vulnerability to be successfully exploited. Affected Product: Schneider Electric Software… | |
| Modificada | Baja (3.8) | 0.24% | — | Schneider-electric Software Update | 28/1/2022 | 17/6/2026 | A CWE-331: Insufficient Entropy vulnerability exists that could cause unintended connection from an internal network to an external network when an attacker manages to decrypt the SESU proxy password from the registry. Affected Product: Schneider Electric Software Update, V2.3.0 through V2.5.1 | |
| Modificada | Media (4.7) | 0.93% | — | Schneider-electric Software Update Utility | 23/7/2020 | 17/6/2026 | A CWE-601: URL Redirection to Untrusted Site ('Open Redirect') vulnerability exists in Schneider Electric Software Update (SESU), V2.4.0 and prior, which could cause execution of malicious code on the victim's machine. In order to exploit this vulnerability, an attacker requires privileged access on the engineering… | |
| Modificada | Media (6.6) | 0.55% | — | Splashtop Software UpdaterSplashtop Streamer | 21/5/2020 | 17/6/2026 | A Windows privilege change issue was discovered in Splashtop Software Updater before 1.5.6.16. Insecure permissions on the configuration file and named pipe allow for local privilege escalation to NT AUTHORITY/SYSTEM, by forcing a permission change to any Splashtop files and directories, with resultant DLL hijacking.… | |
| Modificada | Alta (7.8) | 0.45% | — | Avira Software Updater | 5/5/2020 | 17/6/2026 | An elevation of privilege vulnerability exists in Avira Software Updater before 2.0.6.27476 due to improperly handling file hard links. This allows local users to obtain take control of arbitrary files. | |
| Modificada | Media (6.7) | 0.40% | — | Avira Software Updater | 10/10/2019 | 17/6/2026 | Avira Software Updater before 2.0.6.21094 allows a DLL side-loading attack. NOTE: The vendor thinks that this vulnerability is invalid because exploiting it would require at least administrator privileges and would gain only SYSTEM privileges | |
| Modificada | Alta (7.8) | 0.57% | — | Avira Free Security SuiteAvira Software Updater | 29/8/2019 | 17/6/2026 | An issue was discovered in Avira Free Security Suite 10. The permissive access rights on the SoftwareUpdater folder (files / folders and configuration) are incompatible with the privileged file manipulation performed by the product. Files can be created that can be used by an unprivileged user to obtain SYSTEM… | |
| Modificada | Alta (7.8) | 2.8% | — | Schneider-electric Software Update Utility | 2/11/2018 | 17/6/2026 | A DLL hijacking vulnerability exists in Schneider Electric Software Update (SESU), all versions prior to V2.2.0, which could allow an attacker to execute arbitrary code on the targeted system when placing a specific DLL file. | |
| Modificada | Alta (8.1) | 1.5% | — | F-secure Software Updater | 11/3/2017 | 17/6/2026 | F-Secure Software Updater 2.20, as distributed in several F-Secure products, downloads installation packages over plain http and does not perform file integrity validation after download. Man-in-the-middle attackers can replace the file with their own executable which will be executed under the SYSTEM account. Note… | |
| Modificada | Media (5.9) | 0.92% | — | Apple Software Update | 14/3/2016 | 17/6/2026 | Apple Software Update before 2.2 on Windows does not use HTTPS, which makes it easier for man-in-the-middle attackers to spoof updates by modifying the client-server data stream. | |
| Modificada | Media (4.6) | 0.59% | — | HP Software Update | 29/9/2015 | 17/6/2026 | Unspecified vulnerability in HP Software Update before 5.005.002.002 allows local users to gain privileges via unknown vectors. | |
| Modificada | Alta (9.3) | 2.9% | — | Schneider-electric Software Update Utility | 21/1/2013 | 16/6/2026 | The client in Schneider Electric Software Update (SESU) Utility 1.0.x and 1.1.x does not ensure that updates have a valid origin, which allows man-in-the-middle attackers to spoof updates, and consequently execute arbitrary code, by modifying the data stream on TCP port 80. | |
| Modificada | Media (6.8) | 6.9% | — | HP Software Update | 21/5/2008 | 16/6/2026 | Hpufunction.dll 4.0.0.1 in HP Software Update exposes the unsafe (1) ExecuteAsync and (2) Execute methods, which allows remote attackers to execute arbitrary code via an absolute pathname in the first argument. | |
| Modificada | Media (6.8) | 4.7% | — | HP Software Update | 25/4/2008 | 16/6/2026 | Unspecified vulnerability in the HP HPeDiag (aka eSupportDiagnostics) ActiveX control in hpediag.dll in HP Software Update 4.000.009.002 and earlier allows remote attackers to execute arbitrary code or obtain sensitive information via unspecified vectors. NOTE: this might overlap CVE-2007-6513. | |
| Modificada | Alta (9.3) | 16% | — | HP Software Update | 20/12/2007 | 16/6/2026 | The HPRulesEngine.ContentCollection.1 ActiveX Control in RulesEngine.dll for HP Software Update 4.000.005.007 and earlier, including 3.0.8.4, allows remote attackers to (1) overwrite and corrupt arbitrary files via arguments to the SaveToFile method, and possibly (2) access arbitrary files via the LoadDataFromFile… | |
| Modificada | Media (5) | 18% | — | Apple Software Update | 29/1/2007 | 16/6/2026 | Format string vulnerability in Apple Software Update 2.0.5 on Mac OS X 10.4.8 allows remote attackers to cause a denial of service (application crash) or execute arbitrary code via format string specifiers in (1) SWUTMP or (2) SUCATALOG filenames, or using the (3) application/x-apple.sucatalog+xml MIME type. | |
| Modificada | Media (5) | 2.0% | — | Pyramid Benhur Software Update | 31/12/2002 | 16/6/2026 | The default configuration of BenHur Firewall release 3 update 066 fix 2 allows remote attackers to access arbitrary services by connecting from source port 20. |