Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2537▼ 360 respecto a la semana anterior
Críticas / altas1344▲ 80 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.13% | — | Dell Command Integration Suite FOR System CenterAI | 21/9/2026 | 22/9/2026 | Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Pendiente de análisis | Alta (8.5) | 0.38% | — | SAP Integration SuiteAI | 8/9/2026 | 8/9/2026 | SAP Integration Suite does not sufficiently validate XML documents accepted from untrusted sources in certain internal components. An attacker with low privileges could submit specially crafted XML payloads containing malicious external entity declarations. Successful exploitation could allow the attacker to read… | |
| Modificada | Baja (3.3) | 0.17% | — | Dell Command | Integration Suite FOR System Center | 13/2/2023 | 17/6/2026 | Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. | |
| Modificada | Alta (7.8) | 0.22% | — | Dell Command | Integration Suite FOR System Center | 31/8/2022 | 17/6/2026 | Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to perform an arbitrary write as system. | |
| Modificada | Crítica (9.8) | 1.9% | — | Hillrom Connex Central StationHillrom Connex Device Integration Suite Network Connectivity EngineHillrom Connex Integrated Wall SystemHillrom Connex Spot Monitor+5 | 11/6/2021 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds write, which may result in corruption of data or code execution on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device Integration Suite – Network Connectivity Engine (NCE): versions prior… | |
| Modificada | Alta (7.5) | 1.7% | — | Hillrom Connex Central StationHillrom Connex Device Integration Suite Network Connectivity EngineHillrom Connex Integrated Wall SystemHillrom Connex Spot Monitor+5 | 11/6/2021 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds read, which can cause information leakage leading to arbitrary code execution if chained to the out-of-bounds write vulnerability on the Welch Allyn medical device management tools (Welch Allyn Service Tool: versions prior to v1.10, Welch Allyn Connex Device… | |
| Modificada | Alta (9.3) | 2.6% | — | IBM Gentran Integration SuiteIBM Sterling B2B IntegratorIBM Sterling File GatewayIBM Sterling Integrator | 12/4/2013 | 16/6/2026 | Unspecified vulnerability in the CLA2 server in IBM Gentran Integration Suite 4.3, Sterling Integrator 5.0 and 5.1, and Sterling B2B Integrator 5.2, as used in IBM Sterling File Gateway 1.1 through 2.2 and other products, allows remote attackers to execute arbitrary commands via unknown vectors. |