Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
49 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.5) | 0.13% | — | Dell Command Integration Suite FOR System CenterAI | 21/9/2026 | 22/9/2026 | Dell Command | Integration Suite for System Center, versions prior to 6.7.2, contain an Incorrect Default Permissions vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Information Disclosure. | |
| Analizada | Alta (8.8) | 1.1% | — | Microsoft System Center Operations Manager | 10/3/2026 | 17/6/2026 | Improper input validation in System Center Operations Manager allows an authorized attacker to elevate privileges over a network. | |
| Aplazada | Media (6.9) | 0.18% | — | Subnet Powersystem CenterAI | 11/4/2025 | 17/6/2026 | Subnet Solutions PowerSYSTEM Center is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the API may trigger an exception, resulting in a denial-of-service condition. | |
| Aplazada | Media (5.3) | 0.14% | — | Subnet Powersystem CenterAI | 11/4/2025 | 17/6/2026 | Subnet Solutions PowerSYSTEM Center's SMTPS notification service can be affected by importing an EC certificate with crafted F2m parameters, which can lead to excessive CPU consumption during the evaluation of the curve parameters. | |
| Analizada | Alta (7.8) | 0.88% | — | Microsoft System Center Data Protection ManagerMicrosoft System Center Operations ManagerMicrosoft System Center OrchestratorMicrosoft System Center Service Manager+1 | 8/4/2025 | 17/6/2026 | Untrusted search path in System Center allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.3) | 1.7% | — | Microsoft System Center 2019Microsoft System Center 2022Microsoft System Center 2025 | 12/12/2024 | 17/6/2026 | Microsoft System Center Elevation of Privilege Vulnerability | |
| Aplazada | Alta (8.6) | 0.21% | — | Subnet Powersystem CenterAI | 15/5/2024 | 17/6/2026 | SUBNET Solutions Inc. has identified vulnerabilities in third-party components used in PowerSYSTEM Center. | |
| Analizada | Crítica (9.8) | 20% | — | Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 0.99% | — | Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+4 | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.17% | — | Subnet Powersystem Center | 8/1/2024 | 17/6/2026 | PowerSYSTEM Center versions 2020 Update 16 and prior contain a vulnerability that may allow an authorized local user to insert arbitrary code into the unquoted service path and escalate privileges. | |
| Modificada | Media (6.5) | 1.4% | — | Microsoft System Center Operations Manager | 14/11/2023 | 17/6/2026 | Open Management Infrastructure Information Disclosure Vulnerability | |
| Modificada | Media (6.1) | 0.39% | — | Subnet Powersystem Center | 19/6/2023 | 17/6/2026 | SUBNET PowerSYSTEM Center versions 2020 U10 and prior contain a cross-site scripting vulnerability that may allow an attacker to inject malicious code into report header graphic files that could propagate out of the system and reach users who are subscribed to email notifications. | |
| Modificada | Crítica (9.1) | 0.58% | — | Subnet Powersystem Center | 19/6/2023 | 17/6/2026 | SUBNET PowerSYSTEM Center versions 2020 U10 and prior are vulnerable to replay attacks which may result in a denial-of-service condition or a loss of data integrity. | |
| Modificada | Baja (3.3) | 0.17% | — | Dell Command | Integration Suite FOR System Center | 13/2/2023 | 17/6/2026 | Dell Command | Integration Suite for System Center, versions before 6.4.0 contain an arbitrary folder delete vulnerability during uninstallation. A locally authenticated malicious user may potentially exploit this vulnerability leading to arbitrary folder deletion. | |
| Modificada | Media (5.3) | 0.58% | — | Teclib-edition System Center Configuration Manager | 22/9/2022 | 17/6/2026 | The SCCM plugin for GLPI is a plugin to synchronize computers from SCCM (version 1802) to GLPI. In versions prior to 2.3.0, the Configuration page is publicly accessible in read-only mode. This issue is patched in version 2.3.0. No known workarounds exist. | |
| Modificada | Alta (7.8) | 0.22% | — | Dell Command | Integration Suite FOR System Center | 31/8/2022 | 17/6/2026 | Dell Command | Integration Suite for System Center, versions prior to 6.2.0, contains arbitrary file write vulnerability. A locally authenticated malicious user could potentially exploit this vulnerability in order to perform an arbitrary write as system. | |
| Modificada | Alta (7.8) | 0.60% | — | Microsoft Open Management InfrastructureMicrosoft System Center Operations Manager | 9/8/2022 | 17/6/2026 | System Center Operations Manager: Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.92% | — | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+6 | 15/6/2022 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 2.9% | — | Microsoft System Center Operations Manager | 13/10/2021 | 17/6/2026 | SCOM Information Disclosure Vulnerability | |
| Analizada | Alta (7.8) | 2.9% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 11% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.61% | — | Microsoft Windows DefenderMicrosoft Endpoint ProtectionMicrosoft Security EssentialsMicrosoft System Center Endpoint Protection | 25/2/2021 | 17/6/2026 | Microsoft Defender Elevation of Privilege Vulnerability | |
| Modificada | Alta (8.8) | 2.0% | — | Microsoft System Center Operations Manager | 25/2/2021 | 17/6/2026 | System Center Operations Manager Elevation of Privilege Vulnerability |