Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 214 respecto a la semana anterior
Críticas / altas1385▲ 153 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain an issue with incorrect default permissions. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Aplazada | Media (5.8) | 0.61% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A stack-based buffer overflow vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected product… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… | |
| Aplazada | Media (5.8) | 0.65% | — | Skysea Client ViewAISkymec IT ManagerAI | 25/8/2026 | 28/8/2026 | SKYSEA Client View and SKYMEC IT Manager contain a path traversal vulnerability. If this vulnerability is exploited, an attacker who can log in to a Windows system on which the affected product is installed may be able to execute arbitrary code on another Windows system that has the affected products installed and can… | |
| Aplazada | Alta (8.5) | 0.16% | — | Skysea Client ViewAISkygroup Skymec IT ManagerAI | 25/8/2026 | 28/8/2026 | A missing authorization vulnerability exists in SKYSEA Client View and SKYMEC IT Manager. If this vulnerability is exploited, an attacker who can log in to the Windows system on which the affected product is installed may execute arbitrary code with SYSTEM privilege. | |
| Analizada | Alta (8.5) | 0.15% | — | Skygroup Skymec IT ManagerSkygroup Skysea Client View | 20/4/2026 | 17/6/2026 | SKYSEA Client View and SKYMEC IT Manager provided by Sky Co.,LTD. configure the installation folder with improper file access permission settings. A non-administrative user may manipulate and/or place arbitrary files within the installation folder of the product. As a result, arbitrary code may be executed with the… | |
| Analizada | Alta (7.5) | 0.62% | — | Skygroup Skysea Client View | 29/7/2024 | 17/6/2026 | Path traversal vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary executable file may be executed by a user who can log in to the PC where the product's Windows client is installed. | |
| Modificada | Alta (7.8) | 0.12% | — | Skygroup Skysea Client View | 29/7/2024 | 17/6/2026 | Origin validation error vulnerability exists in SKYSEA Client View Ver.3.013.00 to Ver.19.210.04e. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed. | |
| Analizada | Alta (7.8) | 0.18% | — | Skygroup Skysea Client View | 29/7/2024 | 17/6/2026 | Incorrect privilege assignment vulnerability exists in SKYSEA Client View Ver.6.010.06 to Ver.19.210.04e. If a user who can log in to the PC where the product's Windows client is installed places a specially crafted DLL file in a specific folder, arbitrary code may be executed with SYSTEM privilege. | |
| Analizada | Media (6.3) | 0.41% | — | Skygroup Skysea Client View | 12/3/2024 | 17/6/2026 | Improper access control vulnerability exists in the resident process of SKYSEA Client View versions from Ver.11.220 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary process may be executed with SYSTEM privilege by a user who can log in to the PC where the product's Windows client is installed. | |
| Analizada | Alta (7.8) | 0.24% | — | Skygroup Skysea Client View | 12/3/2024 | 17/6/2026 | Improper access control vulnerability exists in the specific folder of SKYSEA Client View versions from Ver.16.100 prior to Ver.19.2. If this vulnerability is exploited, an arbitrary file may be placed in the specific folder by a user who can log in to the PC where the product's Windows client is installed. In case… | |
| Analizada | Media (6.7) | 0.36% | — | Hexagon Qognify VMS Client Viewer | 26/2/2024 | 17/6/2026 | A DLL hijacking vulnerability was identified in the Qognify VMS Client Viewer version 7.1 or higher, which allows local users to execute arbitrary code and obtain higher privileges via careful placement of a malicious DLL, if some specific pre-conditions are met. | |
| Modificada | Alta (7.8) | 0.32% | — | Skygroup Skysea Client View | 13/1/2021 | 17/6/2026 | Untrusted search path vulnerability in the installer of SKYSEA Client View Ver.1.020.05b to Ver.16.001.01g allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory. | |
| Modificada | Alta (7.8) | 0.34% | — | Skygroup Skysea Client View | 4/8/2020 | 17/6/2026 | Privilege escalation vulnerability in SKYSEA Client View Ver.12.200.12n to 15.210.05f allows an attacker to obtain unauthorized privileges and modify/obtain sensitive information or perform unintended operations via unspecified vectors. | |
| Analizada | Crítica (9.8) | 19% | ⚠ Explotación activa | Skygroup Skysea Client View | 9/6/2017 | 17/6/2026 | SKYSEA Client View Ver.11.221.03 and earlier allows remote code execution via a flaw in processing authentication on the TCP connection with the management console program. |