Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7) | 0.18% | — | Thales Sentinel LDK RuntimeAI | 27/3/2026 | 3/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22. | |
| Modificada | Crítica (9.8) | 1.3% | — | Thalesgroup Sentinel LDK Run-time Environment | 16/6/2021 | 17/6/2026 | The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947. While uninstalling, the uninstaller fails to close Port 1947. | |
| Modificada | Alta (7.8) | 0.42% | — | Gemalto Sentinel LDK License Manager | 11/12/2019 | 17/6/2026 | SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to create, write, and/or delete files in system folder using symbolic links, leading to a privilege… | |
| Modificada | Media (6.5) | 1.2% | — | Gemalto Sentinel LDK | 7/6/2019 | 17/6/2026 | Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it. | |
| Modificada | Media (5.3) | 0.41% | — | Gemalto Sentinel LDK | 7/6/2019 | 17/6/2026 | Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace original language pack by malicious one. | |
| Modificada | Media (6.1) | 0.78% | — | Gemalto Sentinel LDK RTE | 2/5/2018 | 17/6/2026 | The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability. | |
| Modificada | Alta (7.5) | 1.3% | — | Gemalto Sentinel LDK RTE | 13/3/2018 | 17/6/2026 | Denial of service in Gemalto's Sentinel LDK RTE version before 7.65 | |
| Modificada | Alta (7.5) | 1.9% | — | Gemalto Sentinel LDK RTE | 13/3/2018 | 17/6/2026 | Stack overflow in custom XML-parser in Gemalto's Sentinel LDK RTE version before 7.65 leads to remote denial of service | |
| Modificada | Crítica (9.9) | 1.2% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Remote enabling and disabling admin interface in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to new attack vectors. | |
| Modificada | Crítica (9.8) | 2.9% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Memory corruption in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 might cause remote code execution. | |
| Modificada | Alta (7.5) | 1.7% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Arbitrary memory read from controlled memory pointer in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service. | |
| Modificada | Crítica (9.8) | 1.4% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Remote manipulations with language pack updater lead to NTLM-relay attack for system user in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55. | |
| Modificada | Alta (7.5) | 1.9% | — | Sentinel LDK RTE Firmware | 4/10/2017 | 17/6/2026 | Stack overflow in custom XML-parser in Gemalto's HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE version 7.55 leads to remote denial of service. | |
| Modificada | Alta (7.5) | 3.0% | — | Gemalto Sentinel LDK RTE | 3/10/2017 | 17/6/2026 | Buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to shut down the remote process (a denial of service) via a language pack (ZIP file) with invalid HTML files. | |
| Modificada | Crítica (9.8) | 4.8% | — | Gemalto Sentinel LDK RTE | 3/10/2017 | 17/6/2026 | Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via language packs containing filenames longer than 1024 characters. | |
| Modificada | Crítica (9.8) | 4.8% | — | Gemalto Sentinel LDK RTE | 3/10/2017 | 17/6/2026 | Stack buffer overflow in hasplms in Gemalto ACC (Admin Control Center), all versions ranging from HASP SRM 2.10 to Sentinel LDK 7.50, allows remote attackers to execute arbitrary code via malformed ASN.1 streams in V2C and similar input files. |