Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▲ 27 respecto a la semana anterior
Críticas / altas1477▲ 294 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)68▼ 441 respecto a la semana anterior
–

32 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)3.2%—Changing CgservisignAI23/9/202624/9/2026
CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.
AnalizadaCrítica (9.3)0.55%—Changingtec Idexpert2/3/202617/6/2026
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary DLL files from a remote source and execute them.
AnalizadaCrítica (9.3)0.55%—Changingtec Idexpert2/3/202617/6/2026
IDExpert Windows Logon Agent developed by Changing has a Remote Code Execution vulnerability, allowing unauthenticated remote attackers to force the system to download arbitrary executable files from a remote source and execute them.
AplazadaCrítica (9.3)0.52%—Changing TSAAI29/8/202517/6/2026
TSA developed by Changing has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to read, modify, and delete database contents.
AplazadaAlta (8.7)0.42%—Changing Clinic Image SystemAI29/8/202517/6/2026
Clinic Image System developed by Changing has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read database contents.
AplazadaCrítica (9.3)0.53%—Changing Clinic Image SystemAI29/8/202517/6/2026
Clinic Image System developed by Changing contains hard-coded Credentials, allowing unauthenticated remote attackers to log into the system using administrator credentials embedded in the source code.
AplazadaAlta (8.8)0.70%—Changing Information Technology CgfidoAI31/12/202417/6/2026
The login mechanism via device authentication of CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability. If a user visits a forged website, the agent program deployed on their device will send an authentication signature to the website. An unauthenticated remote attacker who obtains…
AplazadaAlta (8.8)0.74%—Changing Information Technology CgfidoAI31/12/202417/6/2026
The passwordless login mechanism in CGFIDO from Changing Information Technology has an Authentication Bypass vulnerability, allowing remote attackers with regular privileges to send a crafted request to switch to the identity of any user, including administrators.
AplazadaAlta (7.2)0.58%—Changingtec IdexpertAI1/11/202417/6/2026
IDExpert from CHANGING Information Technology does not properly validate a specific parameter in the administrator interface, allowing remote attackers with administrative privileges to inject and execute OS commands on the server.
AplazadaMedia (6.1)0.31%—Changingtec IdexpertAI1/11/202417/6/2026
IDExpert from CHANGING Information Technology does not properly validate a parameter for a specific functionality, allowing unauthenticated remote attackers to inject JavsScript code and perform Reflected Cross-site scripting attacks.
AnalizadaMedia (4.3)0.48%—Changingtec Hwatai Servisign2/8/202417/6/2026
The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the HWATAIServiSign, temporarily disrupting its service.
AnalizadaMedia (4.3)0.48%—Changingtec TCB Servisign2/8/202417/6/2026
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the TCBServiSign, temporarily disrupting its service.
AnalizadaAlta (8.8)0.56%—Changingtec TCB Servisign2/8/202417/6/2026
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path.
AnalizadaAlta (8.8)0.59%—Changingtec TCB Servisign2/8/202417/6/2026
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.
AnalizadaMedia (6.5)0.18%—Changingtec TCB Servisign2/8/202417/6/2026
The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it.
AplazadaAlta (7.2)0.59%—Changingtec Mobile ONE Time PasswordAI1/7/202417/6/2026
CHANGING Mobile One Time Password's uploading function in a hidden page does not filter file type properly. Remote attackers with administrator privilege can exploit this vulnerability to upload and run malicious file to execute system commands.
AplazadaMedia (4.9)0.61%—Changingtec Mobile ONE Time PasswordAI1/7/202417/6/2026
CHANGING Mobile One Time Password does not properly filter parameters for the file download functionality, allowing remote attackers with administrator privilege to read arbitrary file on the system.
ModificadaMedia (4.9)0.90%—Changingtec Mobile ONE Time Password27/4/202317/6/2026
ChangingTec MOTP system has a path traversal vulnerability. A remote attacker with administrator’s privilege can exploit this vulnerability to access arbitrary system files.
ModificadaMedia (6.5)0.71%—Changingtec Megaservisignadapter31/1/202317/6/2026
ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for parameter length. An unauthenticated remote attacker can exploit this vulnerability to access partial sensitive content in memory and disrupts partial services.
ModificadaCrítica (9.8)0.91%—Changingtec Megaservisignadapter31/1/202317/6/2026
ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate…
ModificadaAlta (7.5)1.00%—Changingtec Megaservisignadapter31/1/202317/6/2026
ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
ModificadaAlta (7.8)0.92%—Changingtec Servisign3/1/202317/6/2026
ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load malicious DLL files under arbitrary file…
ModificadaMedia (6.5)0.40%—Changingtec Servisign3/1/202317/6/2026
ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
ModificadaAlta (8.8)1.5%—Changingtec Servisign3/1/202317/6/2026
ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers command injection and allows the attacker to execute arbitrary system command to…
ModificadaAlta (7.5)1.9%—Changingtec Rava Certificate Validation System18/10/202217/6/2026
RAVA certification validation system has a path traversal vulnerability. An unauthenticated remote attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.