Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2769▲ 8 respecto a la semana anterior
Críticas / altas1461▲ 292 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 416 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.24% | — | Openclaw Diagnostics PrometheusAI | 26/9/2026 | 29/9/2026 | The OpenClaw Prometheus diagnostics plugin (@openclaw/diagnostics-prometheus) before version 2026.9.3 does not enforce the operator.read scope on its authenticated metrics endpoint. In deployments using an identity-bearing Gateway authentication mode such as trusted-proxy, a caller whose effective role has no read… | |
| Analizada | Alta (8.1) | 0.50% | — | Microsoft.diagnostics.runtimeMicrosoft Visual Studio 2022Microsoft Visual Studio 2026 | 8/9/2026 | 29/9/2026 | External control of file name or path in .NET allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.8) | 0.41% | — | Roche Diagnostics Navify Digital PathologyAIRabbitmqAI | 2/6/2026 | 22/7/2026 | Use of default credentials vulnerability in Roche Diagnostics navify Digital Pathology (RabbitMQ Management interface modules) allows Default Usernames and Passwords. This issue affects navify Digital Pathology: from 2.0.0 before 2.4.1. | |
| Analizada | Alta (8.6) | 0.14% | — | Gallagher Active Directory SyncGallagher Cardholder Sync UtilityGallagher Command CentreGallagher Diagnostics Service+11 | 25/5/2026 | 17/8/2026 | Insertion of Sensitive Information into Log File (CWE-532) in some Command Centre Service installers could lead to Service Account credentials exposure. Mitigating Factor: Only sites that install Command Centre Services with a custom Service Account (not the default Network Service account) are potentially impacted.… | |
| Analizada | Media (6.9) | 0.21% | — | Lenovo DiagnosticsLenovo Hardware Scan | 15/4/2026 | 24/8/2026 | During an internal security assessment, a potential vulnerability was discovered in Lenovo Diagnostics and the HardwareScanAddin used in Lenovo Vantage that, during installation or when using hardware scan, could allow a local authenticated user to perform an arbitrary file write with elevated privileges. | |
| Aplazada | Alta (8.7) | 0.15% | — | GalaxydiagnosticsAI | 4/2/2026 | 17/6/2026 | Improper input validation in GalaxyDiagnostics prior to version 3.5.050 allows local privileged attackers to execute privileged commands. | |
| Aplazada | Alta (7.1) | 0.43% | — | Novarad Novapacs Diagnostics ViewerAI | 24/12/2025 | 17/6/2026 | NovaRad NovaPACS Diagnostics Viewer 8.5.19.75 contains an unauthenticated XML External Entity (XXE) injection vulnerability in XML preference import settings. Attackers can craft malicious XML files with DTD parameter entities to retrieve arbitrary system files through an out-of-band channel attack. | |
| Aplazada | Media (5.3) | 0.31% | — | B R Automation System Diagnostics ManagerAI | 14/10/2025 | 17/6/2026 | An Improper Neutralization of Formula Elements in a CSV File vulnerability exists in System Diagnostics Manager (SDM) of B&R Automation Runtime versions before 6.4 enabling a remote attacker to inject formula data into a generated CSV file. The exploitation of this vulnerability requires the attacker to create a… | |
| Aplazada | Alta (7.1) | 0.28% | — | Roche Diagnostics Navify MonitoringAI | 5/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in Roche Diagnostics navify Monitoring allows an attacker to manipulate input data, which may lead to a denial of service (DoS) due to negatively impacting the server's performance. This vulnerability has no impact on data confidentiality or integrity. This issue affects navify… | |
| Analizada | Media (5.5) | 0.16% | — | Beckhoff IPC Diagnostics PackageBeckhoff Twincat/bsd | 27/8/2024 | 17/6/2026 | The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local denial-of-service attack by a low privileged attacker. | |
| Analizada | Alta (7.3) | 0.24% | — | Beckhoff IPC Diagnostics PackageBeckhoff Twincat/bsd | 27/8/2024 | 17/6/2026 | The IPC-Diagnostics package in TwinCAT/BSD is susceptible to improper input neutralization by a low-privileged local attacker. | |
| Analizada | Alta (7.8) | 0.16% | — | Beckhoff IPC Diagnostics PackageBeckhoff Twincat/bsd | 27/8/2024 | 17/6/2026 | The IPC-Diagnostics package included in TwinCAT/BSD is vulnerable to a local authentication bypass by a low privileged attacker. | |
| Modificada | Alta (7.8) | 0.17% | — | HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware | 31/10/2023 | 17/6/2026 | Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to elevation of privilege. | |
| Modificada | Alta (7.8) | 4.2% | — | Lenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin | 25/10/2023 | 17/6/2026 | A privilege escalation vulnerability was reported in the Lenovo HardwareScanPlugin prior to version 1.3.1.2 and Lenovo Diagnostics prior to version 4.45 that could allow a local user to execute code with elevated privileges. | |
| Modificada | Media (4.4) | 0.21% | — | Lenovo DiagnosticsLenovo Hardwarescan Plugin | 25/10/2023 | 17/6/2026 | A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash. | |
| Modificada | Media (4.4) | 0.21% | — | Lenovo DiagnosticsLenovo Hardwarescan AddinLenovo Hardwarescan Plugin | 25/10/2023 | 17/6/2026 | A denial of service vulnerability was reported in the Lenovo HardwareScanPlugin versions prior to 1.3.1.2 and Lenovo Diagnostics versions prior to 4.45 that could allow a local user with administrative access to trigger a system crash. | |
| Modificada | Crítica (9.8) | 0.89% | — | HP PC Hardware Diagnostics | 12/6/2023 | 17/6/2026 | Certain versions of HP PC Hardware Diagnostics Windows are potentially vulnerable to buffer overflow. | |
| Modificada | Crítica (9.8) | 0.89% | — | HP Image AssistantHP PC Hardware DiagnosticsHP Thunderbolt Dock G2 Firmware | 12/6/2023 | 17/6/2026 | Certain versions of HP PC Hardware Diagnostics Windows, HP Image Assistant, and HP Thunderbolt Dock G2 Firmware are potentially vulnerable to elevation of privilege. | |
| Modificada | Crítica (9.8) | 0.75% | — | SAP Diagnostics Agent | 11/4/2023 | 17/6/2026 | Due to missing authentication and input sanitization of code the EventLogServiceCollector of SAP Diagnostics Agent - version 720, allows an attacker to execute malicious scripts on all connected Diagnostics Agents running on Windows. On successful exploitation, the attacker can completely compromise confidentiality,… | |
| Modificada | Alta (8.1) | 14% | — | SAP Diagnostics Agent | 11/4/2023 | 17/6/2026 | Due to missing authentication and insufficient input validation, the OSCommand Bridge of SAP Diagnostics Agent - version 720, allows an attacker with deep knowledge of the system to execute scripts on all connected Diagnostics Agents. On successful exploitation, the attacker can completely compromise confidentiality,… | |
| Modificada | Alta (7.8) | 0.92% | — | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+6 | 15/6/2022 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.8) | 0.52% | — | SAP Simple Diagnostics Agent | 10/3/2022 | 17/6/2026 | The Simple Diagnostics Agent - versions 1.0 up to version 1.57, does not perform any authentication checks for functionalities that can be accessed via localhost on http port 3005. Due to lack of authentication checks, an attacker could access administrative or other privileged functionalities and read, modify, or… | |
| Modificada | Alta (7.5) | 2.5% | — | SAP Simple Diagnostics Agent | 10/3/2022 | 17/6/2026 | Simple Diagnostics Agent - versions 1.0 (up to version 1.57.), allows an attacker to access information which would otherwise be restricted via a random port 9000-65535. This allows information gathering which could be used exploit future open-source security exploits. | |
| Analizada | Alta (7.8) | 2.9% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 11% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability |