Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

75 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.20%—Chiranjit Hazarika Smart ONE Click SetupAI2/10/20262/10/2026
Insertion of Sensitive Information Into Sent Data vulnerability in Chiranjit Hazarika Smart One Click Setup – Complete Demo Import & Export smart-one-click-setup allows Retrieve Embedded Sensitive Data.This issue affects Smart One Click Setup – Complete Demo Import & Export: from n/a through 1.4.3.
AnalizadaAlta (7.5)0.33%—Oracle Isetup18/8/202631/8/2026
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful…
AnalizadaMedia (6.8)0.29%—Oracle Isetup21/7/202629/7/2026
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful…
AnalizadaCrítica (9.8)2.0%💥 PoCShivammathur Setup PHP17/7/202618/8/2026
setup-php is a GitHub action to set up PHP with extensions, php.ini configuration, coverage drivers, and tools. From 2.25.0 prior to 2.37.1, shivammathur/setup-php resolves the PHP version from repository-controlled files such as .php-version, composer.lock through platform-overrides.php, and composer.json through…
AnalizadaMedia (6.1)0.40%—Python Setuptools8/7/202613/7/2026
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. Prior to 83.0.0, FileList applied MANIFEST.in exclude, global-exclude, recursive-exclude, and prune directives by matching compiled glob patterns against on-disk file names without Unicode normalization, so…
AnalizadaAlta (8.8)0.43%—Oracle Isetup17/6/202618/6/2026
Vulnerability in the Oracle iSetup product of Oracle E-Business Suite (component: General Ledger Update Transform, Reports). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle iSetup. Successful…
AnalizadaCrítica (9.4)1.7%⚠ Explotación activa💥 PoCAquasec Setup-trivyAquasec TrivyAquasec Trivy ActionLitellm+123/3/202617/6/2026
Trivy is a security scanner. On March 19, 2026, a threat actor used compromised credentials to publish a malicious Trivy v0.69.4 release, force-push 76 of 77 version tags in `aquasecurity/trivy-action` to credential-stealing malware, and replace all 7 tags in `aquasecurity/setup-trivy` with malicious commits. This…
AnalizadaMedia (5.7)0.09%—Jrsoftware Inno Setup3/3/202617/6/2026
Privilege escalation via dll hijacking in Inno Setup 6.2.1 and ealier versions.
AplazadaBaja (2.9)0.24%—GE Vernova Enervista UR SetupAI10/2/202617/6/2026
A vulnerability in GE Vernova Enervista UR Setup on Windows allows File Manipulation.This issue affects Enervista: 8.6 and prior versions.
AplazadaAlta (8.8)0.46%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the use of login credentials as the session ID through its web-based administrative interface. A remote attacker could exploit this vulnerability by intercepting network traffic and capturing the session…
AplazadaAlta (8.8)0.38%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the missing HTTPOnly flag for session cookies associated with the web-based administrative interface. A remote at-tacker could exploit this vulnerability by capturing session cookies transmitted over an…
AplazadaAlta (8.7)0.12%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the transmission of credentials encoded using reversible Base64 encoding through the web-based administrative interface. An attacker on the same network could exploit this vulnerability by intercepting…
AplazadaAlta (8.7)0.12%—Tenda 300mbps Wireless Router F3AITenda N300 Easy Setup RouterAI9/1/202617/6/2026
This vulnerability exists in Tenda wireless routers (300Mbps Wireless Router F3 and N300 Easy Setup Router) due to the plaintext transmission of login credentials during the initial login or post-factory reset setup through the web-based administrative interface. An attacker on the same network could exploit this…
AplazadaAlta (8.3)0.11%—CryptsetupAIConstellationAI27/10/202517/6/2026
Constellation is the first Confidential Kubernetes. The Constellation CVM image uses LUKS2-encrypted volumes for persistent storage. When opening an encrypted storage device, the CVM uses the libcryptsetup function crypt_activate_by_passhrase. If the VM is successful in opening the partition with the disk encryption…
AplazadaAlta (8.7)3.9%—Avtech Cloudsetup.cgiAI9/10/202517/6/2026
AVTECH devices that include the CloudSetup.cgi management endpoint are vulnerable to authenticated OS command injection. The `exefile` parameter in CloudSetup.cgi is passed to the underlying system command execution without proper validation or whitelisting. An authenticated attacker who can invoke this endpoint can…
AplazadaMedia (4.4)0.18%—Conda-forge Conda Forge CI SetupAI13/6/202517/6/2026
conda-forge-ci-setup is a package installed by conda-forge each time a build is run on CI. The conda-forge-ci-setup-feedstock setup script is vulnerable due to the unsafe use of the eval function when parsing version information from a custom-formatted meta.yaml file. An attacker controlling meta.yaml can inject…
AnalizadaAlta (7.7)1.5%💥 PoCPython SetuptoolsDebian Linux17/5/202517/6/2026
setuptools is a package that allows users to download, build, install, upgrade, and uninstall Python packages. A path traversal vulnerability in `PackageIndex` is present in setuptools prior to version 78.1.1. An attacker would be allowed to write files to arbitrary locations on the filesystem with the permissions of…
AplazadaMedia (6.7)0.16%—IBM System XAIIBM TpmsetupAI11/4/202517/6/2026
An input validation weakness was reported in the TpmSetup module for some legacy System x server products that could allow a local attacker with elevated privileges to read the contents of memory.
AnalizadaAlta (8.6)2.4%⚠ Explotación activaReviewdog Action-ast-grepReviewdog Action-composite-templateReviewdog Action-setupReviewdog Action-shellcheck+219/3/202517/6/2026
reviewdog/action-setup is a GitHub action that installs reviewdog. reviewdog/action-setup@v1 was compromised March 11, 2025, between 18:42 and 20:31 UTC, with malicious code added that dumps exposed secrets to Github Actions Workflow Logs. Other reviewdog actions that use `reviewdog/action-setup@v1` that would also be…
AplazadaMedia (6.1)0.18%—GE Vernova UR IEDAIGE Vernova Enervista UR SetupAI10/3/202517/6/2026
Insufficient Verification of Data Authenticity vulnerability in GE Vernova UR IED family devices allows an authenticated user to install a modified firmware. The firmware signature verification is enforced only on the client-side dedicated software Enervista UR Setup, allowing the integration check to be bypassed.
AplazadaAlta (8.3)0.28%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
Missing Authentication for Critical Function vulnerability in GE Vernova Enervista UR Setup application allows Authentication Bypass due to a missing SSH server authentication. Since the client connection is not authenticated, an attacker may perform a man-in-the-middle attack on the network.
AplazadaAlta (8)0.15%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
Use of Hard-coded Credentials vulnerability in GE Vernova EnerVista UR Setup allows Privilege Escalation. The local user database is encrypted using an hardcoded password retrievable by an attacker analyzing the application code.
AplazadaAlta (8)0.19%—GE Vernova Enervista UR SetupAI10/3/202517/6/2026
CWE-282 "Improper Ownership Management" in GE Vernova EnerVista UR Setup allows Authentication Bypass. The software's startup authentication can be disabled by altering a Windows registry setting that any user can modify.
AnalizadaMedia (5.5)0.13%—Samsung Easysetup4/2/202517/6/2026
Use of implicit intent for sensitive communication in EasySetup prior to version 11.1.18 allows local attackers to access sensitive information.
AplazadaMedia (6.5)0.41%—Setup Default Featured ImageAI3/2/202517/6/2026
Missing Authorization vulnerability in theme funda Setup Default Featured Image setup-default-feature-image allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Setup Default Featured Image: from n/a through <= 1.2.
Orbitaley — Vulnerabilidades