Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2783▲ 27 respecto a la semana anterior
Críticas / altas1477▲ 294 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.6) | 3.2% | — | Changing CgservisignAI | 23/9/2026 | 24/9/2026 | CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer. | |
| Analizada | Crítica (9.3) | 0.55% | — | Changingtec Idexpert | 2/3/2026 | 17/6/2026 | IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them. | |
| Analizada | Crítica (9.3) | 0.55% | — | Changingtec Idexpert | 2/3/2026 | 17/6/2026 | IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them. | |
| Aplazada | Crítica (9.3) | 0.52% | — | Changing TSAAI | 29/8/2025 | 17/6/2026 | TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents. | |
| Aplazada | Alta (8.7) | 0.42% | — | Changing Clinic Image SystemAI | 29/8/2025 | 17/6/2026 | Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents. | |
| Aplazada | Crítica (9.3) | 0.53% | — | Changing Clinic Image SystemAI | 29/8/2025 | 17/6/2026 | Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source code. | |
| Aplazada | Alta (8.8) | 0.70% | — | Changing Information Technology CgfidoAI | 31/12/2024 | 17/6/2026 | The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains… | |
| Aplazada | Alta (8.8) | 0.74% | — | Changing Information Technology CgfidoAI | 31/12/2024 | 17/6/2026 | The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request to switch to the identity of any user, including administrators. | |
| Aplazada | Alta (7.2) | 0.58% | — | Changingtec IdexpertAI | 1/11/2024 | 17/6/2026 | IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server. | |
| Aplazada | Media (6.1) | 0.31% | — | Changingtec IdexpertAI | 1/11/2024 | 17/6/2026 | IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform Reflected Cross-site scripting attacks. | |
| Analizada | Media (4.3) | 0.48% | — | Changingtec Hwatai Servisign | 2/8/2024 | 17/6/2026 | The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the HWATAIServiSign, temporarily disrupting its service. | |
| Analizada | Media (4.3) | 0.48% | — | Changingtec TCB Servisign | 2/8/2024 | 17/6/2026 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the TCBServiSign, temporarily disrupting its service. | |
| Analizada | Alta (8.8) | 0.56% | — | Changingtec TCB Servisign | 2/8/2024 | 17/6/2026 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path. | |
| Analizada | Alta (8.8) | 0.59% | — | Changingtec TCB Servisign | 2/8/2024 | 17/6/2026 | The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands. | |
| Analizada | Media (6.5) | 0.18% | — | Changingtec TCB Servisign | 2/8/2024 | 17/6/2026 | The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it. | |
| Aplazada | Alta (7.2) | 0.59% | — | Changingtec Mobile ONE Time PasswordAI | 1/7/2024 | 17/6/2026 | CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands. | |
| Aplazada | Media (4.9) | 0.61% | — | Changingtec Mobile ONE Time PasswordAI | 1/7/2024 | 17/6/2026 | CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system. | |
| Modificada | Media (4.9) | 0.90% | — | Changingtec Mobile ONE Time Password | 27/4/2023 | 17/6/2026 | ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files. | |
| Modificada | Media (6.5) | 0.71% | — | Changingtec Megaservisignadapter | 31/1/2023 | 17/6/2026 | ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for parameter length. An unauthenticated remote attacker can exploit this vulnerability to access partial sensitive content in memory and disrupts partial services. | |
| Modificada | Crítica (9.8) | 0.91% | — | Changingtec Megaservisignadapter | 31/1/2023 | 17/6/2026 | ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate… | |
| Modificada | Alta (7.5) | 1.00% | — | Changingtec Megaservisignadapter | 31/1/2023 | 17/6/2026 | ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files. | |
| Modificada | Alta (7.8) | 0.92% | — | Changingtec Servisign | 3/1/2023 | 17/6/2026 | ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load malicious DLL files under arbitrary file… | |
| Modificada | Media (6.5) | 0.40% | — | Changingtec Servisign | 3/1/2023 | 17/6/2026 | ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary system files. | |
| Modificada | Alta (8.8) | 1.5% | — | Changingtec Servisign | 3/1/2023 | 17/6/2026 | ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers command injection and allows the attacker to execute arbitrary system command to… | |
| Modificada | Alta (7.5) | 1.9% | — | Changingtec Rava Certificate Validation System | 18/10/2022 | 17/6/2026 | RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files. |