Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

148 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.44%—Tcman GIM11/2/202217/6/2026
The m_txtNom y m_txtCognoms parameters in TCMAN GIM v8.01 allow an attacker to perform persistent XSS attacks. This vulnerability could be used to carry out a number of browser-based attacks including browser hijacking or theft of sensitive data.
ModificadaAlta (7.2)0.83%—Tcman GIM17/12/202117/6/2026
TCMAN GIM does not perform an authorization check when trying to access determined resources. A remote attacker could exploit this vulnerability to access URL that require privileges without having them. The exploitation of this vulnerability might allow a remote attacker to obtain sensible information.
ModificadaMedia (6.1)0.72%—Tcman GIM17/12/202117/6/2026
TCMAN GIM is affected by an open redirect vulnerability. This vulnerability allows the redirection of user navigation to pages controlled by the attacker. The exploitation of this vulnerability might allow a remote attacker to obtain information.
ModificadaAlta (7.5)1.3%—Tcman GIM17/12/202117/6/2026
TCMAN GIM is vulnerable to a lack of authorization in all available webservice methods listed in /PC/WebService.asmx. The exploitation of this vulnerability might allow a remote attacker to obtain information.
ModificadaCrítica (9.8)0.94%—Tcman GIM17/12/202117/6/2026
TCMAN GIM is vulnerable to a SQL injection vulnerability inside several available webservice methods in /PC/WebService.asmx.
ModificadaMedia (6.5)0.30%—Huawei PC Smart Full SceneHuawei Pcmanager27/10/202117/6/2026
There is a path traversal vulnerability in Huawei PC product. Because the product does not filter path with special characters,attackers can construct a file path with special characters to exploit this vulnerability. Successful exploitation could allow the attacker to transport a file to certain path.Affected product…
ModificadaAlta (7.8)0.25%—Lenovo Pcmanager16/7/202117/6/2026
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.500.5102, that could allow privilege escalation.
ModificadaAlta (7.8)0.26%—Lenovo Pcmanager27/4/202117/6/2026
A DLL search path vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow privilege escalation.
ModificadaMedia (5.5)0.20%—Lenovo Pcmanager27/4/202117/6/2026
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.400.3252, that could allow configuration files to be written to non-standard locations.
ModificadaMedia (5.5)0.22%—Lenovo Pcmanager9/3/202117/6/2026
A denial of service vulnerability was reported in Lenovo PCManager, prior to version 3.0.200.2042, that could allow configuration files to be written to non-standard locations.
ModificadaAlta (7.8)0.34%—Lenovo Pcmanager30/11/202017/6/2026
A privilege escalation vulnerability was reported in Lenovo PCManager prior to version 3.0.50.9162 that could allow an authenticated user to execute code with elevated privileges.
ModificadaAlta (7.8)0.23%—Huawei Pcmanager30/4/202017/6/2026
Huawei PCManager with versions earlier than 10.0.1.36 has a privilege escalation vulnerability. Due to improper permission management of specific files, local attackers with low permissions can inject commands to exploit this vulnerability. Successful exploit may cause privilege escalation.
ModificadaMedia (6.7)0.23%—Huawei Pcmanager27/4/202017/6/2026
Huawei PCManager product with versions earlier than 10.0.5.53 have a local privilege escalation vulnerability. An authenticated, local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege.
ModificadaAlta (7.8)0.23%—Huawei Pcmanager28/2/202017/6/2026
PCManager with versions earlier than 10.0.5.51 have a privilege escalation vulnerability in Huawei PCManager products. An authenticated, local attacker can perform specific operation to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege.
ModificadaCrítica (9.8)3.7%—Pacman Project PacmanFedoraproject Fedora24/2/202017/6/2026
pacman before 5.2 is vulnerable to arbitrary command injection in lib/libalpm/sync.c in the apply_deltas() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable the non-default delta feature and retrieve an attacker-controlled crafted database and delta…
ModificadaCrítica (9.8)3.7%—Pacman Project PacmanFedoraproject Fedora24/2/202017/6/2026
pacman before 5.2 is vulnerable to arbitrary command injection in conf.c in the download_with_xfercommand() function. This can be exploited when unsigned databases are used. To exploit the vulnerability, the user must enable a non-default XferCommand and retrieve an attacker-controlled crafted database and package.
ModificadaAlta (7.8)0.94%—Huawei Pcmanager13/8/201917/6/2026
PCManager 9.1.3.1 has an improper authentication vulnerability. The certain driver interface of the software does not perform a validation of user-mode data properly, successful exploit could result in malicious code execution.
ModificadaMedia (5.5)0.66%—Huawei Pcmanager(china)Huawei Pcmanager(oversea)8/8/201917/6/2026
Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have an information leak vulnerability. Successful exploitation may cause the attacker to read information.
ModificadaAlta (7.8)0.86%—Huawei Pcmanager(china)Huawei Pcmanager(oversea)8/8/201917/6/2026
Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. Successful exploitation may cause the attacker to execute code and read/write information.
ModificadaAlta (7.8)0.86%—Huawei Pcmanager(china)Huawei Pcmanager(oversea)8/8/201917/6/2026
Huawei PCManager with the versions before 9.0.1.66 (Oversea) and versions before 9.0.1.70 (China) have a code execution vulnerability. Successful exploitation may cause the attacker to execute code and read/write information.
ModificadaAlta (7.8)1.0%—Huawei Pcmanager6/6/201917/6/2026
There is a code execution vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a user to install and run a malicious application to exploit this vulnerability. Successful exploitation may cause the attacker to execute malicious code and read/write memory.
ModificadaAlta (7.8)0.84%—Huawei Pcmanager6/6/201917/6/2026
There is a privilege escalation vulnerability in Huawei PCManager versions earlier than PCManager 9.0.1.50. The attacker can tricking a user to install and run a malicious application to exploit this vulnerability. Successful exploitation may cause the attacker to obtain a higher privilege.
ModificadaAlta (8.8)3.4%—Pacman Project Pacman11/3/201917/6/2026
pacman before 5.1.3 allows directory traversal when installing a remote package via a specified URL "pacman -U <url>" due to an unsanitized file name received from a Content-Disposition header. pacman renames the downloaded package file to match the name given in this header. However, pacman did not sanitize this…
ModificadaCrítica (9.8)4.5%—Pcman FTP Server20/11/201819/8/2026
Buffer overflow in PCMan FTP Server 2.0.7 allows for remote code execution via the APPE command.
ModificadaAlta (8.8)2.5%—Opendocman10/4/201817/6/2026
OpenDocMan 1.2.7 and earlier does not properly validate allowed actions, which allows remote authenticated users to bypass an intended access restrictions and assign administrative privileges to themselves via a crafted request to signup.php.
Orbitaley — Vulnerabilidades