Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 373 respecto a la semana anterior
Críticas / altas1323▲ 43 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)99▼ 428 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.20% | — | Control Center PROAI | 18/2/2026 | 17/6/2026 | Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on… | |
| Aplazada | Alta (7.8) | 0.63% | — | Micro-star International MSI Center PROAI | 18/11/2024 | 17/6/2026 | Insecure Permissions vulnerability in Micro-star International MSI Center Pro 2.1.37.0 allows a local attacker to execute arbitrary code via the Device_DeviceID.dat.bak file within the C:\ProgramData\MSI\One Dragon Center\Data folder | |
| Modificada | Crítica (9.8) | 0.75% | — | Property Cloud Platform Management Center Project Property Cloud Platform Management Center | 29/6/2023 | 17/6/2026 | Property Cloud Platform Management Center 1.0 is vulnerable to error-based SQL injection. | |
| Modificada | Alta (8.8) | 0.26% | — | Hospital Management Center Project Hospital Management Center | 16/11/2022 | 17/6/2026 | A vulnerability classified as problematic was found in Hospital Management Center. Affected by this vulnerability is an unknown functionality of the file appointment.php. The manipulation leads to cross-site request forgery. The attack can be launched remotely. The exploit has been disclosed to the public and may be… | |
| Modificada | Crítica (9.8) | 0.53% | — | Hospital Management Center Project Hospital Management Center | 16/11/2022 | 17/6/2026 | A vulnerability classified as critical has been found in Hospital Management Center. Affected is an unknown function of the file patient-info.php. The manipulation of the argument pt_id leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (7.8) | 0.30% | — | MSI Center PRO | 4/2/2022 | 17/6/2026 | Micro-Star International (MSI) Center Pro <= 2.0.16.0 is vulnerable to multiple Privilege Escalation (LPE/EoP) vulnerabilities in the atidgllk.sys, atillk64.sys, MODAPI.sys, NTIOLib.sys, NTIOLib_X64.sys, WinRing0.sys, WinRing0x64.sys drivers components. All the vulnerabilities are triggered by sending specific IOCTL… | |
| Modificada | Baja (3.3) | 0.31% | — | HP Application Lifecycle Management Quality Center Project HP Application Lifecycle Management Quality Center | 2/7/2020 | 17/6/2026 | Jenkins HP ALM Quality Center Plugin 1.6 and earlier stores a password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system. | |
| Modificada | Media (6.1) | 0.81% | — | Siemens Teamcenter Product Lifecycle Management | 9/7/2018 | 17/6/2026 | A reflected Cross-Site-Scripting (XSS) vulnerability has been identified in Siemens PLM Software TEAMCENTER (V9.1.2.5). If a user visits the login portal through the URL crafted by the attacker, the attacker can insert html/javascript and thus alter/rewrite the login portal page. Siemens PLM Software TEAMCENTER V9.1.3… | |
| Modificada | Alta (8.1) | 1.8% | — | Healthcenter Project Healthcenter | 4/6/2018 | 17/6/2026 | healthcenter - IBM Monitoring and Diagnostic Tools health Center agent healthcenter downloads binary resources over HTTP, which leaves it vulnerable to MITM attacks. It may be possible to cause remote code execution (RCE) by swapping out the requested resources with an attacker controlled copy if the attacker is on… | |
| Modificada | Crítica (9.8) | 23% | — | Iomega Storcenter PRO Firmware | 8/7/2009 | 16/6/2026 | cgi-bin/makecgi-pro in Iomega StorCenter Pro generates predictable session IDs, which allows remote attackers to hijack active sessions and gain privileges via brute force guessing attacks on the session_id parameter. |