Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.44%—Trane Tracer SC+ FirmwareTrane Tracer SC FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Use of Hard-coded, Security-relevant Constants vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
AnalizadaAlta (8.2)0.48%—Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Use of Hard-coded Credentials vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to disclose sensitive information and take over accounts.
AnalizadaMedia (6.9)0.42%—Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Missing Authorization vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to access sensitive information through unprotected APIs.
AnalizadaAlta (8.7)0.49%—Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Memory Allocation with Excessive Size Value vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an unauthenticated attacker to cause a denial-of-service condition
AnalizadaCrítica (9.2)0.35%—Trane Tracer SC FirmwareTrane Tracer SC+ FirmwareTrane Tracer Concierge12/3/202617/6/2026
A Use of a Broken or Risky Cryptographic Algorithm vulnerability in Trane Tracer SC, Tracer SC+, and Tracer Concierge could allow an attacker to bypass authentication and gain root-level access to the device.
ModificadaAlta (8.8)1.0%—Trane Tracer ConciergeTrane Tracer SC FirmwareTrane Tracer SC+ Firmware27/10/202117/6/2026
The affected controllers do not properly sanitize the input containing code syntax. As a result, an attacker could craft code to alter the intended controller flow of the software.
ModificadaMedia (6.1)0.61%—Trane Tracer SC Firmware22/10/202117/6/2026
The affected product’s web application does not properly neutralize the input during webpage generation, which could allow an attacker to inject code in the input forms.
ModificadaAlta (7.5)0.31%—Trane Tracer SC19/9/201617/6/2026
ABB DataManagerPro 1.x before 1.7.1 allows local users to gain privileges by replacing a DLL file in the package directory.
ModificadaMedia (5.3)1.2%—Trane Tracer SC19/9/201617/6/2026
The web server in Trane Tracer SC 4.2.1134 and earlier allows remote attackers to read sensitive configuration files via a direct request.