Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

49 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.9)0.16%—Tauri Updater PluginAI23/9/202623/9/2026
The Tauri updater plugin verifies update binaries using minisign signatures, but the signature covers only the raw binary bytes. The update manifest -- which contains the version number, download URL, and signature -- is fetched over TLS but is never itself signed or authenticated. Because the only anti-rollback check…
AplazadaMedia (6.8)0.45%—Tauri UpdaterAI22/9/202622/9/2026
The Tauri updater plugin's 'check' IPC command accepts an allowDowngrades boolean parameter directly from frontend JavaScript code. When set to true, it replaces the version comparator from "update must be newer" to "update must be different." Because the default permission set grants allow-check to the webview, any…
AplazadaCrítica (9.8)0.42%—Time4 PopcornAITime4 Popcorn Updater.exeAITime4 Popcorn Pt.upddAI27/8/20261/9/2026
An issue in Time4 Popcorn for Windows <= 6.2.1.18 and Time4Popcorn for MacOS <= 6.2.1.17 and Time4Popcorn for Android <= 3.5.0.173 allows a remote attacker to execute arbitrary code via the updater.exe for windows, PT.updd on MacOS components
AplazadaCrítica (9.8)0.34%—Epson Easymp Network UpdaterAI18/8/20269/9/2026
Verification Bypass vulnerability exists in EPSON 150075647YWWV110 EasyMP Network Updater Ver.1.20. The Epson projector can be updated by encrypted firmware through USB.
AplazadaAlta (8.3)0.19%—Capgo Capacitor UpdaterAI10/7/202610/7/2026
In @capgo/capacitor-updater (Cap-go/capgo) before 12.128.2, the end-to-end encryption scheme distributes the private key to each device that downloads the app. Because the public key can be derived from the private key, an attacker performing a man-in-the-middle attack or compromising the Capgo server can create a…
AplazadaCrítica (9.1)0.61%—Owncloud CoreAIOwncloud UpdaterAI6/7/202630/9/2026
ownCloud Core is the server-side component of the file storage, synchronization, and sharing application ownCloud Classic. In versions prior to 10.15.3, the Updater on ownCloud 10 before 10.15.3 has an exposed dangerous method or function. Attackers with administrative privileges may leverage functionality to execute…
AplazadaMedia (6.4)0.32%—Image Attributes From Filename With Bulk UpdaterAI2/6/202622/7/2026
The Auto Image Attributes From Filename With Bulk Updater (Add Alt Text, Image Title For Image SEO) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the attachment metadata in all versions up to, and including, 4.9 due to insufficient input sanitization and output escaping. This makes it possible…
Pendiente de análisisCrítica (9.1)0.41%—Argoproj Argocd Image UpdaterAI15/4/202615/7/2026
A flaw was found in ArgoCD Image Updater. This vulnerability allows an attacker, with permissions to create or modify an ImageUpdater resource in a multi-tenant environment, to bypass namespace boundaries. By exploiting insufficient validation, the attacker can trigger unauthorized image updates on applications…
AplazadaMedia (4.3)0.18%—Page Title Description Open Graph UpdaterAI19/2/202617/6/2026
The Page Title, Description & Open Graph Updater plugin for WordPress is vulnerable to Cross-Site Request Forgery in all versions up to, and including, 1.02. This is due to missing nonce validation on multiple AJAX actions including dieno_update_page_title. This makes it possible for unauthenticated attackers to…
AnalizadaAlta (7.8)0.17%—Avanquest PC Helpsoft Driver Updater3/2/202617/6/2026
Insecure Permissions vulnerability in avanquest Driver Updater v.9.1.57803.1174 allows a local attacker to escalate privileges via the Driver Updater Service windows component.
AplazadaAlta (8.5)0.18%—Acer Updater ServiceAI16/1/202617/6/2026
Acer Updater Service 1.2.3500.0 contains an unquoted service path vulnerability that allows local users to execute code with elevated system privileges. Attackers can exploit the unquoted path in C:\Program Files\Acer\Acer Updater\ to inject malicious executables that will run with LocalSystem permissions during…
AplazadaAlta (8.5)0.19%—Splashtop Software UpdaterAI13/1/202617/6/2026
Splashtop 8.71.12001.0 contains an unquoted service path vulnerability in the Splashtop Software Updater Service that allows local attackers to potentially execute arbitrary code. Attackers can exploit the unquoted path in C:\Program Files (x86)\Splashtop\Splashtop Software Updater\ to inject malicious executables and…
AplazadaBaja (3.8)0.13%—Github Workflow UpdaterAIMicrosoft VS CodeAI28/10/202517/6/2026
GitHub Workflow Updater is a VS Code extension that automatically pins GitHub Actions to specific commits for enhanced security. Before 0.0.7, any provided Github token would be stored in plaintext in the editor configuration as json on disk, rather than through the more secure "securestorage" api. An attacker with…
AplazadaMedia (4.3)0.25%—Joby Joseph SEO Meta Description UpdaterAI27/10/202517/6/2026
Missing Authorization vulnerability in Joby Joseph SEO Meta Description Updater seo-meta-description-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects SEO Meta Description Updater: from n/a through <= 1.2.0.
AplazadaAlta (8.8)0.12%—Altiris Core Agent UpdaterAI11/9/202530/9/2026
The Altiris Core Agent Updater package (AeXNSC.exe) is prone to an elevation of privileges vulnerability through DLL hijacking.
AplazadaAlta (7.3)0.27%—Patch MY PC Home UpdaterAI9/5/202517/6/2026
A vulnerability was found in Patch My PC Home Updater up to 5.1.3.0. It has been rated as critical. This issue affects some unknown processing in the library…
AplazadaAlta (7.1)0.29%—Devu Status UpdaterAI3/3/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in devu Status Updater fb-status-updater allows Reflected XSS.This issue affects Status Updater: from n/a through <= 1.9.2.
AplazadaCrítica (9)0.64%—Veeam UpdaterAI5/2/202517/6/2026
A vulnerability in Veeam Updater component allows Man-in-the-Middle attackers to execute arbitrary code on the affected server. This issue occurs due to a failure to properly validate TLS certificate.
AplazadaMedia (5.3)0.50%—Apasionados Comment Blacklist UpdaterAI13/12/202417/6/2026
Missing Authorization vulnerability in apasionados Comment Blacklist Updater comment-blacklist-updater allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Comment Blacklist Updater: from n/a through <= 1.1.0.
AplazadaAlta (7.8)2.0%—Elefant Software UpdaterAI8/11/202417/6/2026
An attacker with local access the to medical office computer can escalate his Windows user privileges to "NT AUTHORITY\SYSTEM" by exploiting a command injection vulnerability in the Elefant Update Service. The command injection can be exploited by communicating with the Elefant Update Service which is running as…
AplazadaAlta (7.1)0.35%—Obtaininfotech Multisite Content Copier UpdaterAI20/7/202417/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Obtain Infotech Multisite Content Copier/Updater allows Reflected XSS.This issue affects Multisite Content Copier/Updater: from n/a through 1.5.0.
ModificadaAlta (7.8)0.15%—Google Updater7/6/202417/6/2026
Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to bypass discretionary access control via a malicious file. (Chromium security severity: High)
ModificadaAlta (7.8)0.16%—Google Updater7/6/202417/6/2026
Inappropriate implementation in Google Updator prior to 1.3.36.351 in Google Chrome allowed a local attacker to perform privilege escalation via a malicious file. (Chromium security severity: High)
ModificadaAlta (7.8)0.95%—Kylinos Kylin-system-updater25/12/202317/6/2026
A vulnerability classified as critical has been found in KylinSoft kylin-system-updater up to 2.0.5.16-0k2.33. Affected is an unknown function of the file /usr/share/kylin-system-updater/SystemUpdater/UpgradeStrategiesDbus.py of the component com.kylin.systemupgrade Service. The manipulation of the argument…
ModificadaAlta (7.8)0.23%—Corecode Macupdater20/9/202317/6/2026
An XPC misconfiguration vulnerability in CoreCode MacUpdater before 2.3.8, and 3.x before 3.1.2, allows attackers to escalate privileges by crafting malicious .pkg files.