Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2753▲ 26 respecto a la semana anterior
Críticas / altas1468▲ 333 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.2) | 0.19% | — | Plugin-alliance Installation Manager | 3/12/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in the Plugin Alliance InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 on macOS. Due to the absence of a hardened runtime and a __RESTRICT segment, a local user may exploit the DYLD_INSERT_LIBRARIES environment variable to inject a… | |
| Analizada | Media (6.2) | 0.21% | — | Plugin-alliance Installation Manager | 3/12/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in the InstallationHelper service included with Plugin Alliance Installation Manager v1.4.0 for macOS. The service accepts unauthenticated XPC connections and executes input via system(), which may allow a local user to execute arbitrary commands with root privileges. | |
| Modificada | Crítica (9.8) | 0.93% | — | Jenkins Installation Manager Tool | 3/12/2020 | 17/6/2026 | Jenkins Plugin Installation Manager Tool 2.1.3 and earlier does not verify plugin downloads. | |
| Modificada | Alta (7) | 0.42% | — | IBM Installation ManagerIBM Packaging Utility | 2/1/2016 | 17/6/2026 | consoleinst.sh in IBM Installation Manager before 1.7.4.4 and 1.8.x before 1.8.4 and Packaging Utility before 1.7.4.4 and 1.8.x before 1.8.4 allows local users to gain privileges via a Trojan horse program that is located in /tmp with a name based on a predicted PID value. | |
| Modificada | Baja (1.2) | 0.33% | — | IBM Installation ManagerIBM Rational Clearcase | 25/3/2015 | 17/6/2026 | IBM Rational ClearCase 8.0.0 before 8.0.0.14 and 8.0.1 before 8.0.1.7, when Installation Manager before 1.8.2 is used, retains cleartext server passwords in process memory throughout the installation procedure, which might allow local users to obtain sensitive information by leveraging access to the installation… | |
| Modificada | Alta (9.3) | 5.5% | — | IBM Installation Manager | 1/10/2009 | 16/6/2026 | Argument injection vulnerability in the iim: URI handler in IBMIM.exe in IBM Installation Manager 1.3.2 and earlier, as used in IBM Rational Robot and Rational Team Concert, allows remote attackers to load arbitrary DLL files via the -vm option, as demonstrated by a reference to a UNC share pathname. |