Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2630▼ 308 respecto a la semana anterior
Críticas / altas1351▲ 88 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
387 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.1) | 0.35% | — | Oracle E-business SuiteAIOracle Installed BaseAI | 15/9/2026 | 18/9/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… | |
| Aplazada | Media (5.4) | 0.17% | — | Iobit UninstallerAI | 12/9/2026 | 14/9/2026 | A flaw has been found in IOBit Uninstaller 15.5.0.11. Affected by this issue is the function sub_11838 of the file IURegistryFilter.sys of the component IOCTL Dispatch Handler. This manipulation causes null pointer dereference. The attack requires local access. The exploit has been published and may be used. Identical… | |
| Aplazada | Alta (8.6) | 0.19% | — | Siemens Desigo CC Clickonce ClientAISiemens Desigo CC Flex ClientAISiemens Desigo CC Installed ClientAISiemens Desigo CCAI | 8/9/2026 | 14/9/2026 | A vulnerability has been identified in Desigo CC ClickOnce Client V6 (All versions), Desigo CC ClickOnce Client V7 (All versions), Desigo CC family V8 (All versions), Desigo CC family V9 (All versions), Desigo CC Flex Client V6 (All versions), Desigo CC Flex Client V7 (All versions), Desigo CC Installed Client V6 (All… | |
| Aplazada | Media (4.8) | 0.14% | — | Iobit UninstallerAI | 31/8/2026 | 31/8/2026 | A flaw has been found in IObit Uninstaller 15.5.0.11. This affects the function IRP_MJ_DEVICE_CONTROL in the library IUForceDelete.sys of the component IOCTL Handler. Executing a manipulation can lead to improper privilege management. The attack requires local access. The vendor was contacted early about this… | |
| Aplazada | Alta (7) | 0.17% | — | Electron-builderAIMicrosoft Windows InstallerAI | 30/8/2026 | 1/9/2026 | SiYuan Windows installer before version 3.8.1 (affected versions >= 2.0.14) contains an uncontrolled search path element vulnerability in its NSIS installer, which invokes system executables such as TASKKILL by name rather than by absolute path. Because NSIS nsExec::Exec resolves these calls using a search path that… | |
| Aplazada | Alta (8.5) | 0.39% | — | Stalwart Mail ServerAI | 26/8/2026 | 24/9/2026 | Stalwart Mail Server does not compare an OAuth redirect target against any registered destination in its default configuration. The validation routine in crates/http/src/auth/oauth/registration.rs returns success immediately when the client-authentication requirement is disabled, and that requirement is false in the… | |
| Analizada | Media (6.3) | 0.26% | — | Oracle Installed Base | 18/8/2026 | 3/9/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: User Interface). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks of… | |
| Analizada | Media (5.5) | 0.15% | — | Autodesk Installer | 12/8/2026 | 4/9/2026 | A maliciously crafted input, when processed by the Autodesk Installer IPC frame parser, may trigger improper validation of an input-specified position or offset, resulting in an out-of-range substring operation. A malicious actor may leverage this vulnerability to cause the NT AUTHORITY\SYSTEM service to terminate… | |
| Analizada | Alta (7.8) | 0.15% | — | Autodesk Installer | 12/8/2026 | 4/9/2026 | A maliciously created executable, when executed on the victim's machine, may allow a local low-privileged attacker to inject unauthenticated IPC messages into named pipes, modify pipe permissions or ownership, and potentially impact confidentiality, integrity, and availability. | |
| Analizada | Alta (7.8) | 0.32% | — | Microsoft APP Installer | 11/8/2026 | 29/8/2026 | Improper privilege management in Windows Package Manager allows an authorized attacker to elevate privileges locally. | |
| Aplazada | Alta (7.2) | 0.34% | — | Karr Security SystemAISwds Dealer Installed Automotive Anti Theft SystemAI | 5/8/2026 | 8/9/2026 | The KARR Security System and SWDS dealer-installed automotive anti-theft systems use a shared Bluetooth authentication key across affected devices. An attacker within Bluetooth range can leverage this weakness to issue unauthorized commands to the vehicle, potentially allowing unauthorized access to vehicle functions,… | |
| Modificada | Alta (8.6) | 0.30% | — | Adobe Photoshop Installer | 28/7/2026 | 26/8/2026 | Adobe Photoshop Installer was affected by an Uncontrolled Search Path Element vulnerability that could have resulted in arbitrary code execution in the context of the current user. An attacker could have exploited this vulnerability by placing a malicious library in a directory searched by the installer. Exploitation… | |
| Aplazada | Alta (7.8) | 0.15% | — | Unistal Systems PVT LTD Protegent 360AI | 23/7/2026 | 30/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| Aplazada | Alta (7.8) | 0.14% | — | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the sub_186f4 function | |
| Aplazada | Alta (7.8) | 0.14% | — | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to escalate privileges via the kernel driver pgsecdl.sys | |
| Aplazada | Media (5.5) | 0.14% | — | Unistal Systems Pvt. LTD Protegent 360AI | 22/7/2026 | 24/7/2026 | An issue in Unistal Systems Pvt. Ltd.Protegent 360 v2.0.0.4 allows a local attacker to cause a denial of service via the function sub_13828 | |
| Analizada | Alta (8.3) | 0.39% | — | Oracle Installed Base | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Installed Base | 21/7/2026 | 6/8/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… | |
| Analizada | Alta (7.1) | 0.30% | — | Oracle Installed Base | 21/7/2026 | 13/8/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… | |
| Analizada | Media (5) | 0.21% | — | Oracle Installed Base | 21/7/2026 | 13/8/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.4-12.2.15. Difficult to exploit vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful… | |
| Analizada | Alta (8.1) | 0.36% | — | Oracle Installed Base | 21/7/2026 | 13/8/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… | |
| Analizada | Alta (8.8) | 0.43% | — | Oracle Installed Base | 21/7/2026 | 30/7/2026 | Vulnerability in the Oracle Installed Base product of Oracle E-Business Suite (component: Create Item Instance). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Installed Base. Successful attacks… | |
| Aplazada | Alta (7.1) | 0.14% | — | VS Revo RevouninstallerAI | 15/6/2026 | 24/7/2026 | A vulnerability was identified in VS Revo RevoUninstaller 2.5.x/2.6.x. The affected element is the function IOCtl_Handler in the library RevoDetector.sys of the component IOCTL Handler. Such manipulation leads to heap-based buffer overflow. The attack must be carried out locally. The exploit is publicly available and… | |
| Aplazada | Alta (8.5) | 0.12% | — | Iobit UninstallerAI | 13/5/2026 | 17/6/2026 | IObit Uninstaller 9.5.0.15 contains an unquoted service path vulnerability in the IObitUnSvr service that allows local attackers to escalate privileges to SYSTEM level. Attackers can place a malicious executable named IObit.exe in the C:\Program Files (x86)\IObit directory and restart the service to execute code with… | |
| Analizada | Alta (7.8) | 0.24% | — | Nullsoft Scriptable Install System | 24/4/2026 | 17/6/2026 | NSIS (Nullsoft Scriptable Install System) 3.06.1 before 3.12 sometimes uses the Low IL temp directory when executing as SYSTEM, allowing local attackers to gain privileges (if they can cause my_GetTempFileName to return 0, as shown in the references). |