Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 82 respecto a la semana anterior
Críticas / altas1416▲ 189 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)100▼ 400 respecto a la semana anterior
439 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.8) | 0.52% | — | GO Live Update UrlsAI | 30/9/2026 | 30/9/2026 | Contributor PHP Object Injection in Go Live Update Urls <= 7.0.8 versions. | |
| Aplazada | Media (5.9) | 0.16% | — | Tauri Updater PluginAI | 23/9/2026 | 23/9/2026 | The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check… | |
| Aplazada | Media (6.8) | 0.45% | — | Tauri UpdaterAI | 22/9/2026 | 22/9/2026 | The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from "update must be newer" to "update must be different." Because the default permission set grants allow-check to the webview, any… | |
| Aplazada | Alta (8.5) | 0.18% | — | Biostar Bios Update UtilityAI | 21/9/2026 | 22/9/2026 | A vulnerability was found in BioStar BIOS Update Utility 1.9.7.3. This issue affects the function sub_110BC of the file BSMEM64_W10.sys of the component IOCTL Handler. The manipulation of the argument PhysicalAddress/Size results in write-what-where condition. Attacking locally is a requirement. The exploit has been… | |
| Pendiente de análisis | Alta (8.2) | 0.19% | — | Dell Server Update UtilityAI | 17/9/2026 | 19/9/2026 | Dell Server Update Utility, versions prior to 26.07.01, contains an Uncontrolled Search Path Element vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Code execution. | |
| Analizada | Alta (8.8) | 0.41% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with adjacent network access could potentially exploit this vulnerability, leading to Remote execution. | |
| Analizada | Media (6) | 0.15% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Media (6) | 0.15% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Link Resolution Before File Access ('Link Following') vulnerability. A high privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Alta (7.8) | 0.15% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Unchecked Return Value vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (7.8) | 0.59% | — | Dell Update Package Framework | 16/9/2026 | 21/9/2026 | Dell Update Package Framework, versions prior to 26.07.03, contains an Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Pendiente de análisis | Media (5.4) | 0.23% | — | Jenkins Update-center2AI | 2/9/2026 | 3/9/2026 | Jenkins update-center2 3.18.3 and earlier does not escape plugin-provided values (plugin names, descriptions, and version metadata) on plugin download index pages, resulting in a stored cross-site scripting (XSS) vulnerability exploitable by attackers able to provide a plugin for hosting. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Time4 PopcornAITime4 Popcorn Updater.exeAITime4 Popcorn Pt.upddAI | 27/8/2026 | 1/9/2026 | An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components | |
| Analizada | Media (6.5) | 0.15% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Restriction of XML External Entity Reference vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges and Server-side request forgery. | |
| Analizada | Media (5.5) | 0.15% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Exposure of Sensitive System Information to an Unauthorized Control Sphere vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information disclosure. | |
| Analizada | Media (5.5) | 0.12% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of privileges. | |
| Analizada | Alta (8.8) | 0.14% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.14% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Filesystem access for attacker. | |
| Analizada | Alta (7.3) | 0.14% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Missing Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Unauthorized access. | |
| Analizada | Alta (7.3) | 0.12% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Media (6.6) | 0.17% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain an Improper Link Resolution Before File Access ('Link Following') vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.12% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Time-of-check Time-of-use (TOCTOU) Race Condition vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.31% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Analizada | Alta (7.8) | 0.31% | — | Dell Command Update | 19/8/2026 | 21/8/2026 | Dell Command Update (DCU), versions prior to 5.7.1, contain a Deserialization of Untrusted Data vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges. | |
| Aplazada | Crítica (9.8) | 0.34% | — | Epson Easymp Network UpdaterAI | 18/8/2026 | 9/9/2026 | Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB. | |
| Analizada | Alta (7.1) | 0.24% | — | Redhat Openshift Update ServiceRedhat Quay | 14/8/2026 | 20/8/2026 | A flaw was found in Red Hat Quay. A user with FEATURE_BUILD_SUPPORT enabled and repository write access can exploit a Server-Side Request Forgery (SSRF) vulnerability within the build API. This allows the user to provide a malicious URL, causing the Quay builder to make requests to internal network addresses. Such an… |