Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.1) | 0.13% | — | Acer NitrosenseAI | 23/9/2026 | 25/9/2026 | An unauthenticated local attacker can connect to the Electron DevTools endpoint exposed by Acer NitroSense software (versions up to and including 5.2.63) on localhost TCP port 9993. Because Chromium remote debugging is enabled in the production application, the attacker can execute JavaScript in the privileged… | |
| Aplazada | Media (6.1) | 0.35% | — | Acer NitrosenseAI | 23/9/2026 | 25/9/2026 | An unauthenticated local attacker can connect to the MQTT broker over its localhost WebSocket endpoint in Acer NitroSense software (versions up to and including 5.2.62). This allows the attacker to invoke exposed ddsc RPC functions, including child_process.execSync(), resulting in arbitrary command execution in the… | |
| Aplazada | Alta (7.4) | 0.13% | — | Acer NitrosenseAIAcer PredatorsenseAI | 17/9/2026 | 18/9/2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense due to insufficient access controls in a privileged service. An authenticated local user may be able to access the service and perform unauthorized registry modifications, potentially resulting in… | |
| Aplazada | Alta (7.4) | 0.13% | — | Acer NitrosenseAIAcer PredicatsenseAI | 17/9/2026 | 18/9/2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. Insufficient access controls within a privileged Named Pipe service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to… | |
| Aplazada | Baja (1.2) | 0.21% | — | Acer NitrosenseAIAcer PredatorsenseAI | 17/9/2026 | 18/9/2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The WebSocket handshake process does not properly require authentication before allowing connections to the service. Under certain circumstances, unauthorized access to service functionality may be… | |
| Aplazada | Baja (2.7) | 0.43% | — | Acer NitrosenseAIAcer PredatorsenseAI | 17/9/2026 | 18/9/2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. A WebSocket service was configured to listen on all network interfaces, which may expose the service to unintended network access. | |
| Aplazada | Baja (1.2) | 0.10% | — | Acer NitrosenseAIAcer PredatorsenseAI | 17/9/2026 | 18/9/2026 | A vulnerability has been identified in the Acer System Monitoring component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected… | |
| Aplazada | Alta (7.4) | 0.13% | — | Acer NitrosenseAIAcer PredatorsenseAI | 17/9/2026 | 18/9/2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. Insufficient access controls within a privileged service may allow an authenticated local user to perform unauthorized registry operations. In certain situations, this could lead to privilege escalation… | |
| Aplazada | Media (4.9) | 0.21% | — | Acer NitrosenseAIAcer PredatorsenseAI | 17/9/2026 | 18/9/2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The socket handshake process does not properly require authentication before granting access to the service. Under certain circumstances, an unauthorized connection may be established, potentially… | |
| Aplazada | Media (4.9) | 0.10% | — | Acer NitrosenseAIAcer PredatorsenseAI | 17/9/2026 | 18/9/2026 | A vulnerability has been identified in the Acer Agent Service component included with NitroSense and PredatorSense. The vulnerability is caused by the use of a hard-coded AES encryption key within the software. Under certain circumstances, a local attacker may be able to use the embedded key to access protected… | |
| Aplazada | Alta (8.5) | 0.15% | — | Acer NitrosenseAI | 28/5/2026 | 17/6/2026 | A Local Privilege Escalation (LPE) vulnerability affects Acer NitroSense software versions prior to 3.01.3052. The vulnerability stems from the the PSAdminAgent service, which creates a Named Pipe with a weak Access Control List (ACL). This allows any authenticated local user to connect and send commands. Because the… | |
| Pendiente de análisis | Alta (8.5) | 0.16% | — | Acer NitrosenseAI | 25/5/2026 | 23/7/2026 | NitroSense 3.x before 3.01.3052 contains Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT AUTHORITY\SYSTEM… | |
| Analizada | Alta (8.5) | 0.17% | — | Acer NitrosenseAcer Predatorsense | 8/5/2026 | 12/8/2026 | PredatorSense version 3.00.3136 to 3.00.3196 contain Local Privilege Escalation (LPE) vulnerability.The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing any authenticated local user to execute arbitrary code with NT… |