Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.97% | — | Panorama Project Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential. | |
| Modificada | Alta (7.4) | 0.97% | — | Panorama Project Nhiservisignadapter | 31/12/2020 | 17/6/2026 | Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential. | |
| Modificada | Crítica (9.8) | 2.0% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege. | |
| Modificada | Crítica (9.8) | 2.0% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege. | |
| Modificada | Alta (7.5) | 0.51% | — | Panorama Nhiservisignadapter | 31/12/2020 | 17/6/2026 | The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege. |