Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2570▼ 305 respecto a la semana anterior
Críticas / altas1353▲ 102 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

21 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.6)3.2%—Changing CgservisignAI23/9/202624/9/2026
CGServiSign developed by Changing has a OS Command Injection vulnerability. Unauthenticated remote attackers can induce victims to visit a malicious web page and inject arbitrary OS commands through the local service interface, resulting in command execution on the victim's local computer.
AnalizadaMedia (4.3)0.48%—Changingtec Hwatai Servisign2/8/202417/6/2026
The specific API in HWATAIServiSign Windows Version from CHANGING Information Technology does not properly validate the length of server-side inputs. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the HWATAIServiSign, temporarily disrupting its service.
AnalizadaMedia (4.3)0.48%—Changingtec TCB Servisign2/8/202417/6/2026
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does does not properly validate the length of server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause a stack-based buffer overflow in the TCBServiSign, temporarily disrupting its service.
AnalizadaAlta (8.8)0.56%—Changingtec TCB Servisign2/8/202417/6/2026
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can cause the TCBServiSign to load a DLL from an arbitrary path.
AnalizadaAlta (8.8)0.59%—Changingtec TCB Servisign2/8/202417/6/2026
The specific API in TCBServiSign Windows Version from CHANGING Information Technology does not properly validate server-side input. When a user visits a spoofed website, unauthenticated remote attackers can modify the `HKEY_CURRENT_USER` registry to execute arbitrary commands.
AnalizadaMedia (6.5)0.18%—Changingtec TCB Servisign2/8/202417/6/2026
The encryption strength of the authorization keys in CHANGING Information Technology TCBServiSign Windows Version is insufficient. When a remote attacker tricks a victim into visiting a malicious website, TCBServiSign will treat that website as a legitimate server and interact with it.
ModificadaMedia (6.5)0.71%—Changingtec Megaservisignadapter31/1/202317/6/2026
ChangingTech MegaServiSignAdapter component has a vulnerability of Out-of-bounds Read due to insufficient validation for parameter length. An unauthenticated remote attacker can exploit this vulnerability to access partial sensitive content in memory and disrupts partial services.
ModificadaCrítica (9.8)0.91%—Changingtec Megaservisignadapter31/1/202317/6/2026
ChangingTech MegaServiSignAdapter component has a vulnerability of improper input validation. An unauthenticated remote attacker can exploit this vulnerability to access and modify HKEY_CURRENT_USER subkey (ex: AutoRUN) in Registry where malicious scripts can be executed to take control of the system or to terminate…
ModificadaAlta (7.5)1.00%—Changingtec Megaservisignadapter31/1/202317/6/2026
ChangingTech MegaServiSignAdapter component has a path traversal vulnerability within its file reading function. An unauthenticated remote attacker can exploit this vulnerability to access arbitrary system files.
ModificadaAlta (7.8)0.92%—Changingtec Servisign3/1/202317/6/2026
ChangingTec ServiSign component has a path traversal vulnerability due to insufficient filtering for special characters in the DLL file path. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers the component to load malicious DLL files under arbitrary file…
ModificadaMedia (6.5)0.40%—Changingtec Servisign3/1/202317/6/2026
ChangingTec ServiSign component has a path traversal vulnerability. An unauthenticated LAN attacker can exploit this vulnerability to bypass authentication and access arbitrary system files.
ModificadaAlta (8.8)1.5%—Changingtec Servisign3/1/202317/6/2026
ChangingTec ServiSign component has insufficient filtering for special characters in the connection response parameter. An unauthenticated remote attacker can host a malicious website for the component user to access, which triggers command injection and allows the attacker to execute arbitrary system command to…
ModificadaCrítica (9.8)2.0%—Tssservisignadapter Project Tssservisignadapter15/9/202117/6/2026
WriteRegistry function in TSSServiSign component does not filter and verify users’ input, remote attackers can rewrite to the registry without permissions thus perform hijack attacks to execute arbitrary code.
ModificadaAlta (7.4)0.97%—Panorama Project Nhiservisignadapter31/12/202017/6/2026
The digest generation function of NHIServiSignAdapter has not been verified for source file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.
ModificadaAlta (7.4)0.97%—Panorama Project Nhiservisignadapter31/12/202017/6/2026
Multiple functions of NHIServiSignAdapter failed to verify the users’ file path, which leads to the SMB request being redirected to a malicious host, resulting in the leakage of user's credential.
ModificadaCrítica (9.8)2.0%—Panorama Nhiservisignadapter31/12/202017/6/2026
The digest generation function of NHIServiSignAdapter has not been verified for parameter’s length, which leads to a stack overflow loophole. Remote attackers can use the leak to execute code without privilege.
ModificadaCrítica (9.8)2.0%—Panorama Nhiservisignadapter31/12/202017/6/2026
NHIServiSignAdapter fails to verify the length of digital credential files’ path which leads to a heap overflow loophole. Remote attackers can use the leak to execute code without privilege.
ModificadaAlta (7.5)0.51%—Panorama Nhiservisignadapter31/12/202017/6/2026
The encryption function of NHIServiSignAdapter fail to verify the file path input by users. Remote attacker can access arbitrary files through the flaw without privilege.
ModificadaAlta (7.5)1.2%—Changingtec Servisign3/2/202017/6/2026
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
ModificadaAlta (7.5)1.5%—Changingtec Servisign3/2/202017/6/2026
An arbitrary-file-access vulnerability exists in ServiSign security plugin, as long as the attackers learn the specific API function, they may access arbitrary files on target system via crafted API parameter.
ModificadaAlta (8.8)2.8%—Changingtec Servisign3/2/202017/6/2026
A Remote Code Execution(RCE) vulnerability exists in some designated applications in ServiSign security plugin, as long as the interface is captured, attackers are able to launch RCE and executes arbitrary command on target system via malicious crafted scripts.