Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3037▲ 563 respecto a la semana anterior
Críticas / altas1444▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)393▲ 186 respecto a la semana anterior
–

55 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.3)0.24%—Openclaw Diagnostics PrometheusAI26/9/202629/9/2026
The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective role has no read…
AnalizadaAlta (8.1)0.50%—Microsoft.diagnostics.runtimeMicrosoft Visual Studio 2022Microsoft Visual Studio 20268/9/202629/9/2026
External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network.
AplazadaAlta (8.8)0.41%—Roche Diagnostics Navify Digital PathologyAIRabbitmqAI2/6/202622/7/2026
Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1.
AnalizadaAlta (8.6)0.14%—Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+1125/5/202617/8/2026
Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.…
AnalizadaMedia (6.9)0.21%—Lenovo DiagnosticsLenovo Hardware Scan15/4/202624/8/2026
During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges.
AplazadaAlta (8.7)0.14%—GalaxydiagnosticsAI4/2/202617/6/2026
Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands.
AplazadaAlta (7.1)0.43%—Novarad Novapacs Diagnostics ViewerAI24/12/202517/6/2026
NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack.
AplazadaMedia (5.3)0.31%—B R Automation System Diagnostics ManagerAI14/10/202517/6/2026
An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attacker to create a…
AplazadaAlta (7.1)0.28%—Roche Diagnostics Navify MonitoringAI5/8/202517/6/2026
Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denial of service (DoS) due to negatively impacting the server's performance. This vulnerability has no impact on data confidentiality or integrity. This issue affects navify…
AnalizadaMedia (5.5)0.16%—Beckhoff IPC Diagnostics PackageBeckhoff Twincat/bsd27/8/202417/6/2026
The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker.
AnalizadaAlta (7.3)0.24%—Beckhoff IPC Diagnostics PackageBeckhoff Twincat/bsd27/8/202417/6/2026
The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker.
AnalizadaAlta (7.8)0.16%—Beckhoff IPC Diagnostics PackageBeckhoff Twincat/bsd27/8/202417/6/2026
The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker.
ModificadaAlta (7.8)0.17%—HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware31/10/202317/6/2026
Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege.
ModificadaAlta (7.8)4.2%—Lenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin25/10/202317/6/2026
A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges.
ModificadaMedia (4.4)0.21%—Lenovo DiagnosticsLenovo Hardwarescan Plugin25/10/202317/6/2026
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
ModificadaMedia (4.4)0.21%—Lenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin25/10/202317/6/2026
A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash.
ModificadaCrítica (9.8)0.89%—HP PC Hardware Diagnostics12/6/202317/6/2026
Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow.
ModificadaCrítica (9.8)0.89%—HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware12/6/202317/6/2026
Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege.
ModificadaCrítica (9.8)0.75%—SAP Diagnostics Agent11/4/202317/6/2026
Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality,…
ModificadaAlta (8.1)14%—SAP Diagnostics Agent11/4/202317/6/2026
Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality,…
ModificadaAlta (7.8)0.92%—Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+615/6/202217/6/2026
Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability
ModificadaAlta (7.8)0.52%—SAP Simple Diagnostics Agent10/3/202217/6/2026
The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or…
ModificadaAlta (7.5)2.5%—SAP Simple Diagnostics Agent10/3/202217/6/2026
Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a random port 9000-65535. This allows information gathering which could be used exploit future open-source security exploits.
AnalizadaAlta (7.8)2.9%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability
AnalizadaAlta (7.8)11%⚠ Explotación activaMicrosoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+715/9/202110/8/2026
Open Management Infrastructure Elevation of Privilege Vulnerability