Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Modificada | Media (5.3) | 0.95% | — | Beckhoff IPC Diagnostics UA ServerBeckhoff Tf6100Beckhoff Twincat OPC UA Server | 13/5/2021 | 17/6/2026 | TwinCAT OPC UA Server in versions up to 2.3.0.12 and IPC Diagnostics UA Server in versions up to 3.1.0.1 from Beckhoff Automation GmbH & Co. KG are vulnerable to denial of service attacks. The attacker needs to send several specifically crafted requests to the running OPC UA server. After some of these requests the… | |
| Modificada | Alta (7.5) | 34% | — | Rockwellautomation Factorytalk Diagnostics | 29/12/2020 | 17/6/2026 | An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer… | |
| Modificada | Alta (7.8) | 0.44% | — | Lenovo Diagnostics | 14/10/2020 | 17/6/2026 | A DLL search path vulnerability was reported in Lenovo Diagnostics prior to version 4.35.4 that could allow a user with local access to execute code on the system. | |
| Modificada | Media (4.3) | 0.70% | — | SAP Diagnostics Agent | 13/11/2019 | 17/6/2026 | Under certain conditions SAP Data Hub (corrected in DH_Foundation version 2) allows an attacker to access information which would otherwise be restricted. Connection details that are maintained in Connection Manager are visible to users. | |
| Modificada | Crítica (9.1) | 2.2% | — | SAP Diagnostics Agent | 10/7/2019 | 17/6/2026 | The OS Command Plugin in the transaction GPA_ADMIN and the OSCommand Console of SAP Diagnostic Agent (LM-Service), version 7.2, allow an attacker to inject code that can be executed by the application. An attacker could thereby control the behavior of the application. | |
| Modificada | Media (5.4) | 1.1% | — | HP Diagnostics | 15/2/2018 | 17/6/2026 | A cross-site scripting vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found. | |
| Modificada | Media (6.5) | 3.6% | — | HP Diagnostics | 15/2/2018 | 17/6/2026 | A Remote click jacking vulnerability in HPE Diagnostics version 9.24 IP1, 9.26 , 9.26IP1 was found. | |
| Analizada | Alta (7.8) | 9.0% | ⚠ Explotación activa | Intel Ethernet Diagnostics Driver Iqvw32.sysIntel Ethernet Diagnostics Driver Iqvw64.sys | 9/8/2017 | 1/10/2026 | (1) IQVW32.sys before 1.3.1.0 and (2) IQVW64.sys before 1.3.1.0 in the Intel Ethernet diagnostics driver for Windows allows local users to cause a denial of service or possibly execute arbitrary code with kernel privileges via a crafted (a) 0x80862013, (b) 0x8086200B, (c) 0x8086200F, or (d) 0x80862007 IOCTL call. | |
| Modificada | Alta (7.8) | 2.0% | — | Microsoft Windows Diagnostics HUB | 16/6/2016 | 17/6/2026 | The Standard Collector service in Windows Diagnostics Hub mishandles library loading, which allows local users to gain privileges via a crafted application, aka "Windows Diagnostics Hub Elevation of Privilege Vulnerability." | |
| Modificada | Alta (9) | 5.7% | — | Beckhoff IPC Diagnostics | 8/6/2015 | 17/6/2026 | Beckhoff IPC Diagnostics before 1.8 does not properly restrict access to functions in /config, which allows remote attackers to cause a denial of service (reboot or shutdown), create arbitrary users, or possibly have unspecified other impact via a crafted request, as demonstrated by a… | |
| Modificada | Baja (2.1) | 0.53% | — | HP Array Configuration UtilityHP Array Diagnostics UtilityHP Proliant Array DiagnosticsHP Smartssd Wear Gauge Utility | 12/4/2014 | 17/6/2026 | Unspecified vulnerability in HP Array Configuration Utility, Array Diagnostics Utility, ProLiant Array Diagnostics, and SmartSSD Wear Gauge Utility 9.40 and earlier allows local users to gain privileges via unknown vectors. | |
| Modificada | Media (5) | 3.8% | — | HP Insight Diagnostics | 14/6/2013 | 16/6/2026 | hpdiags/frontend2/help/pageview.php in HP Insight Diagnostics 9.4.0.4710 does not properly restrict PHP include or require statements, which allows remote attackers to include arbitrary hpdiags/frontend2/help/ .html files via the path parameter. | |
| Modificada | Alta (7.8) | 4.9% | — | HP Insight Diagnostics | 14/6/2013 | 16/6/2026 | Absolute path traversal vulnerability in hpdiags/frontend2/commands/saveCompareConfig.php in HP Insight Diagnostics 9.4.0.4710 allows remote attackers to write data to arbitrary files via a full pathname in the argument to the devicePath (aka mount) parameter. | |
| Modificada | Alta (10) | 4.3% | — | HP Insight Diagnostics | 14/6/2013 | 16/6/2026 | HP Insight Diagnostics 9.4.0.4710 allows remote attackers to conduct unspecified injection attacks via unknown vectors. | |
| Modificada | Alta (10) | 11% | — | HP Diagnostics Server | 25/1/2013 | 16/6/2026 | Stack-based buffer overflow in magentservice.exe in HP Diagnostics Server 8.x through 8.07 and 9.x through 9.21 allows remote attackers to execute arbitrary code via a malformed message packet. | |
| Modificada | Alta (10) | 64% | — | HP Diagnostics | 13/1/2012 | 16/6/2026 | Stack-based buffer overflow in magentservice.exe in the server in HP LoadRunner 11.00 before patch 4 allows remote attackers to execute arbitrary code via a crafted size value in a packet. NOTE: it was originally reported that the affected product is HP Diagnostics Server, but HP states that "the vulnerable product is… | |
| Modificada | Media (6.9) | 0.64% | — | Rockwellautomation Factorytalk Diagnostics Viewer | 28/7/2011 | 16/6/2026 | Unspecified vulnerability in Rockwell Automation FactoryTalk Diagnostics Viewer before V2.30.00 (CPR9 SR3) allows local users to execute arbitrary code via a crafted FactoryTalk Diagnostics Viewer (.ftd) configuration file, which triggers memory corruption. | |
| Modificada | Media (4.3) | 1.8% | — | HP Diagnostics | 29/3/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Diagnostics 7.5x and 8.0x before 8.05.54.225 allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Media (4.3) | 1.8% | — | HP Insight Diagnostics | 22/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.1.3712 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 4.8% | — | HP Insight Diagnostics | 10/9/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in HP Insight Diagnostics Online Edition before 8.5.0-11 on Linux allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 3.5% | — | HP Insight Diagnostics | 2/10/2008 | 16/6/2026 | Unspecified vulnerability in HP Insight Diagnostics before 7.9.1.2402 allows remote attackers to read arbitrary files via unknown vectors. | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (disk space exhaustion) via a file with "crafted data structures" that trigger the creation of large… | |
| Modificada | Media (5) | 13% | — | Microsoft Antigen FOR ExchangeMicrosoft Antigen FOR Smtp GatewayMicrosoft Diagnostics AND Recovery ToolkitMicrosoft Forefront Client Security+5 | 13/5/2008 | 16/6/2026 | Unspecified vulnerability in Microsoft Malware Protection Engine (mpengine.dll) 1.1.3520.0 and 0.1.13.192, as used in multiple Microsoft products, allows context-dependent attackers to cause a denial of service (engine hang and restart) via a crafted file, a different vulnerability than CVE-2008-1438. |