Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
148 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.44% | — | Tcman GIM | 11/2/2022 | 17/6/2026 | The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data. | |
| Modificada | Alta (7.2) | 0.83% | — | Tcman GIM | 17/12/2021 | 17/6/2026 | TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to obtain sensible information. | |
| Modificada | Media (6.1) | 0.72% | — | Tcman GIM | 17/12/2021 | 17/6/2026 | TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information. | |
| Modificada | Alta (7.5) | 1.3% | — | Tcman GIM | 17/12/2021 | 17/6/2026 | TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information. | |
| Modificada | Crítica (9.8) | 0.94% | — | Tcman GIM | 17/12/2021 | 17/6/2026 | TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx. | |
| Modificada | Media (6.5) | 0.30% | — | Huawei PC Smart Full SceneHuawei Pcmanager | 27/10/2021 | 17/6/2026 | There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special characters,attackers can construct a file path with special characters to exploit this vulnerability. Successful exploitation could allow the attacker to transport a file to certain path.Affected product… | |
| Modificada | Alta (7.8) | 0.25% | — | Lenovo Pcmanager | 16/7/2021 | 17/6/2026 | A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation. | |
| Modificada | Alta (7.8) | 0.26% | — | Lenovo Pcmanager | 27/4/2021 | 17/6/2026 | A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation. | |
| Modificada | Media (5.5) | 0.20% | — | Lenovo Pcmanager | 27/4/2021 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations. | |
| Modificada | Media (5.5) | 0.22% | — | Lenovo Pcmanager | 9/3/2021 | 17/6/2026 | A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations. | |
| Modificada | Alta (7.8) | 0.34% | — | Lenovo Pcmanager | 30/11/2020 | 17/6/2026 | A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges. | |
| Modificada | Alta (7.8) | 0.23% | — | Huawei Pcmanager | 30/4/2020 | 17/6/2026 | Huawei PCManager with versions earlier than 10.0.1.36 has a privilege escalation vulnerability. Due to improper permission management of specific files, local attackers with low permissions can inject commands to exploit this vulnerability. Successful exploit may cause privilege escalation. | |
| Modificada | Media (6.7) | 0.23% | — | Huawei Pcmanager | 27/4/2020 | 17/6/2026 | Huawei PCManager product with versions earlier than 10.0.5.53 have a local privilege escalation vulnerability. An authenticated, local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. | |
| Modificada | Alta (7.8) | 0.23% | — | Huawei Pcmanager | 28/2/2020 | 17/6/2026 | PCManager with versions earlier than 10.0.5.51 have a privilege escalation vulnerability in Huawei PCManager products. An authenticated, local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. | |
| Modificada | Crítica (9.8) | 3.7% | — | Pacman Project PacmanFedoraproject Fedora | 24/2/2020 | 17/6/2026 | pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable the non-default delta feature and retrieve an attacker-controlled crafted database and delta… | |
| Modificada | Crítica (9.8) | 3.7% | — | Pacman Project PacmanFedoraproject Fedora | 24/2/2020 | 17/6/2026 | pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default XferCommand and retrieve an attacker-controlled crafted database and package. | |
| Modificada | Alta (7.8) | 0.94% | — | Huawei Pcmanager | 13/8/2019 | 17/6/2026 | PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mode data properly, successful exploit could result in malicious code execution. | |
| Modificada | Media (5.5) | 0.66% | — | Huawei Pcmanager(china)Huawei Pcmanager(oversea) | 8/8/2019 | 17/6/2026 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information leak vulnerability. Successful exploitation may cause the attacker to read information. | |
| Modificada | Alta (7.8) | 0.86% | — | Huawei Pcmanager(china)Huawei Pcmanager(oversea) | 8/8/2019 | 17/6/2026 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. Successful exploitation may cause the attacker to execute code and read/write information. | |
| Modificada | Alta (7.8) | 0.86% | — | Huawei Pcmanager(china)Huawei Pcmanager(oversea) | 8/8/2019 | 17/6/2026 | Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. Successful exploitation may cause the attacker to execute code and read/write information. | |
| Modificada | Alta (7.8) | 1.0% | — | Huawei Pcmanager | 6/6/2019 | 17/6/2026 | There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a user to install and run a malicious application to exploit this vulnerability. Successful exploitation may cause the attacker to execute malicious code and read/write memory. | |
| Modificada | Alta (7.8) | 0.84% | — | Huawei Pcmanager | 6/6/2019 | 17/6/2026 | There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a user to install and run a malicious application to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege. | |
| Modificada | Alta (8.8) | 3.4% | — | Pacman Project Pacman | 11/3/2019 | 17/6/2026 | pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Disposition header. pacman renames the downloaded package file to match the name given in this header. However, pacman did not sanitize this… | |
| Modificada | Crítica (9.8) | 4.5% | — | Pcman FTP Server | 20/11/2018 | 19/8/2026 | Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command. | |
| Modificada | Alta (8.8) | 2.5% | — | Opendocman | 10/4/2018 | 17/6/2026 | OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php. |