Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Gemalto Sentinel LDK RTE | 13/3/2018 | 17/6/2026 | Denial of service in Gemalto's Sentinel LDK RTE version before 7.65 | |
| Modificada | Alta (7.5) | 1.9% | — | Gemalto Sentinel LDK RTE | 13/3/2018 | 17/6/2026 | Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE version before 7.65 leads to remote denial of service | |
| Modificada | Media (5.3) | 0.54% | — | Microfocus Sentinel | 7/3/2018 | 17/6/2026 | In NetIQ Sentinel before 8.1.x, a Sentinel user is logged into the Sentinel Web Interface. After performing some tasks within Sentinel the user does not log out but does go idle for a period of time. This in turn causes the interface to timeout so that it requires the user to re-authenticate. If another user is… | |
| Modificada | Crítica (9.9) | 1.2% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors. | |
| Modificada | Crítica (9.8) | 2.9% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execution. | |
| Modificada | Alta (7.5) | 1.7% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service. | |
| Modificada | Crítica (9.8) | 1.4% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55. | |
| Modificada | Alta (7.5) | 1.9% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service. | |
| Modificada | Alta (7.5) | 3.0% | — | Gemalto Sentinel LDK RTE | 3/10/2017 | 17/6/2026 | Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to shut down the remote process (a denial of service) via a language pack (ZIP file) with invalid HTML files. | |
| Modificada | Crítica (9.8) | 4.8% | — | Gemalto Sentinel LDK RTE | 3/10/2017 | 17/6/2026 | Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via language packs containing filenames longer than 1024 characters. | |
| Modificada | Crítica (9.8) | 4.8% | — | Gemalto Sentinel LDK RTE | 3/10/2017 | 17/6/2026 | Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via malformed ASN.1 streams in V2C and similar input files. | |
| Modificada | Crítica (9.8) | 2.3% | — | Opwglobal Sitesentinel Isite ATG FirmwareOpwglobal Sitesentinel Integra 500 FirmwareOpwglobal Sitesentinel Integra 100 Firmware | 9/9/2017 | 17/6/2026 | A Missing Authentication for Critical Function issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. An attacker may create an application user… | |
| Modificada | Crítica (9.8) | 1.6% | — | Opwglobal Sitesentinel Isite ATG FirmwareOpwglobal Sitesentinel Integra 500 FirmwareOpwglobal Sitesentinel Integra 100 Firmware | 9/9/2017 | 17/6/2026 | A SQL Injection issue was discovered in OPW Fuel Management Systems SiteSentinel Integra 100, SiteSentinel Integra 500, and SiteSentinel iSite ATG consoles with the following software versions: older than V175, V175-V189, V191-V195, and V16Q3.1. The application is vulnerable to injection of malicious SQL queries via… | |
| Modificada | Alta (7.5) | 1.7% | — | Microfocus Sentinel | 30/3/2017 | 17/6/2026 | A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow remote denial of service. | |
| Modificada | Media (5.3) | 1.0% | — | Microfocus Sentinel | 30/3/2017 | 17/6/2026 | A vulnerability was discovered in NetIQ Sentinel Server 8.0 before 8.0.1 that may allow leakage of information (account enumeration). | |
| Modificada | Media (6.5) | 3.8% | — | Netiq Sentinel | 1/8/2016 | 17/6/2026 | Directory traversal vulnerability in the ReportViewServlet servlet in the server in NetIQ Sentinel 7.4.x before 7.4.2 allows remote attackers to read arbitrary files via a PREVIEW value for the fileType field. | |
| Modificada | Media (5.4) | 0.27% | — | Sentinels Randomizer Project Sentinels Randomizer | 30/9/2014 | 17/6/2026 | The Sentinels Randomizer (aka com.mikehipps.sentinelsrandomizer) application 1.1.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.8) | 3.3% | — | Microfocus SentinelMicrofocus Sentinel Agent Manager | 20/5/2014 | 17/6/2026 | Directory traversal vulnerability in the DumpToFile method in the NQMcsVarSet ActiveX control in Agent Manager in NetIQ Sentinel allows remote attackers to create arbitrary files, and consequently execute arbitrary code, via a crafted pathname. | |
| Modificada | Media (4.3) | 4.5% | 💥 Exploit | Novell Sentinel LOG Manager | 29/3/2013 | 16/6/2026 | Novell Sentinel Log Manager before 1.2.0.3 allows remote attackers to create data retention policies via a crafted text/x-gwt-rpc request to novelllogmanager/datastorageservice.rpc, and allows remote authenticated Report Administrators to create data retention policies via a search-results "Save Query As" "Save As… | |
| Modificada | Media (6.8) | 1.2% | — | Trioniclabs Sentinel | 25/10/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to hijack the authentication of an administrator for requests that trigger snapshots. | |
| Modificada | Media (4.3) | 2.5% | — | Trioniclabs Sentinel | 25/10/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in wordpress_sentinel.php in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to inject arbitrary web script or HTML via unknown vectors. | |
| Modificada | Alta (7.5) | 2.7% | — | Trioniclabs Sentinel | 25/10/2012 | 16/6/2026 | SQL injection vulnerability in the Sentinel plugin 1.0.0 for WordPress allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Alta (7.8) | 1.5% | — | Arbiter Power Sentinel 1133a FirmwareArbiter Power Sentinel | 5/9/2012 | 16/6/2026 | The Arbiter Power Sentinel 1133A device with firmware before 11Jun2012 Rev 421 allows remote attackers to cause a denial of service (Ethernet outage) via unspecified Ethernet traffic that fills a buffer, as demonstrated by a port scan. | |
| Modificada | Media (4) | 3.2% | 💥 Exploit | Novell Sentinel LOG Manager | 29/12/2011 | 16/6/2026 | Directory traversal vulnerability in novelllogmanager/FileDownload in Novell Sentinel Log Manager 1.2.0.1_938 and earlier, as used in Novell Sentinel before 7.0.1.0, allows remote authenticated users to read arbitrary files via a .. (dot dot) in the filename parameter. | |
| Modificada | Media (4.3) | 1.3% | — | 7T IgssSafenet-inc Sentinel Hasp Run-timeSafenet-inc Sentinel Hasp SDK | 17/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Admin Control Center in Sentinel HASP Run-time Environment 5.95 and earlier in SafeNet Sentinel HASP (formerly Aladdin HASP SRM) run-time installer before 6.x and SDK before 5.11, as used in 7 Technologies (7T) IGSS 7 and other products, when Firefox 2.0 is used, allows… |