Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2819→ sin cambios respecto a la semana anterior
Críticas / altas1469▲ 239 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)83▼ 429 respecto a la semana anterior
63 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.66% | — | Spacelabs Healthcare SentinelAIMicrosoft IISAIMicrosoft DotnetAI | 2/6/2026 | 22/7/2026 | Spacelabs Healthcare Sentinel versions 10.5.x and higher and 11.x.x before 11.6.0 contain an unauthenticated remote code execution vulnerability through a deprecated .NET Remoting HTTP channel exposed on port 8989 that allows attackers to perform arbitrary file read and write operations by supplying valid .NET URI… | |
| Pendiente de análisis | Alta (7) | 0.18% | — | Thales Sentinel LDK RuntimeAI | 27/3/2026 | 3/9/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Thales Sentinel LDK Runtime on Windows allows Stored XSS. This issue affects Sentinel LDK Runtime: before 10.22. | |
| Aplazada | Crítica (9.8) | 0.72% | — | OPW Fuel Management Systems SitesentinelAI | 27/9/2024 | 17/6/2026 | OPW Fuel Management Systems SiteSentinel could allow an attacker to bypass authentication to the server and obtain full admin privileges. | |
| Analizada | Alta (7.8) | 0.99% | — | Microsoft Azure AutomationMicrosoft Azure Automation Update ManagementMicrosoft Azure Security CenterMicrosoft Azure Sentinel+4 | 12/3/2024 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 0.43% | — | Thalesgroup Sentinel Hasp LDK | 27/2/2024 | 17/6/2026 | A flaw in the installer for Thales SafeNet Sentinel HASP LDK prior to 9.16 on Windows allows an attacker to escalate their privilege level via local access. | |
| Modificada | Crítica (9.8) | 0.83% | — | Franklin-electric System Sentinel Anyware | 8/12/2023 | 17/6/2026 | Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Session Fixation. The 'sid' parameter in the group_status.asp resource allows an attacker to escalate privileges and obtain sensitive information. | |
| Modificada | Media (6.1) | 0.46% | — | Franklin-electric System Sentinel Anyware | 8/12/2023 | 17/6/2026 | Franklin Fueling Systems System Sentinel AnyWare (SSA) version 1.6.24.492 is vulnerable to Open Redirect. The 'path' parameter of the prefs.asp resource allows an attacker to redirect a victim user to an arbitrary web site using a crafted URL. | |
| Modificada | Alta (7.8) | 0.17% | — | Gbgplc Acuant Asureid Sentinel | 4/4/2023 | 17/6/2026 | An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It allows elevation of privileges because it opens Notepad after the installation of AssureID, Identify x64, and Identify x86, aka CORE-7361. | |
| Modificada | Media (5.5) | 0.19% | — | Gbgplc Acuant Asureid Sentinel | 4/4/2023 | 17/6/2026 | An issue was discovered in Acuant AsureID Sentinel before 5.2.149. It uses the root of the C: drive for the i-Dentify and Sentinel Installer log files, aka CORE-7362. | |
| Modificada | Alta (7.8) | 0.92% | — | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure DiagnosticsMicrosoft Azure Security Center+6 | 15/6/2022 | 17/6/2026 | Open Management Infrastructure (OMI) Elevation of Privilege Vulnerability | |
| Modificada | Alta (7.5) | 5.6% | — | Hashicorp Sentinel | 23/3/2022 | 17/6/2026 | Sentinel 1.8.2 is vulnerable to Server-side request forgery (SSRF). | |
| Modificada | Alta (7.8) | 0.29% | — | Thalesgroup Sentinel Protection Installer | 20/12/2021 | 17/6/2026 | Improper Access Control of Dynamically-Managed Code Resources (DLL) in Thales Sentinel Protection Installer could allow the execution of arbitrary code. | |
| Modificada | Media (6.7) | 0.22% | — | Thalesgroup Sentinel Protection Installer | 20/12/2021 | 17/6/2026 | Improper Access Control in Thales Sentinel Protection Installer could allow a local user to escalate privileges. | |
| Analizada | Alta (7.8) | 2.9% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Alta (7.8) | 11% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Open Management Infrastructure+7 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.8) | 100% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure (OMI) Remote Code Execution Vulnerability | |
| Analizada | Alta (7.8) | 2.7% | ⚠ Explotación activa | Microsoft Azure Automation State ConfigurationMicrosoft Azure Automation Update ManagementMicrosoft Azure Diagnostics (lad)Microsoft Azure Security Center+6 | 15/9/2021 | 10/8/2026 | Open Management Infrastructure Elevation of Privilege Vulnerability | |
| Modificada | Crítica (9.8) | 1.3% | — | Thalesgroup Sentinel LDK Run-time Environment | 16/6/2021 | 17/6/2026 | The Sentinel LDK Run-Time Environment installer (Versions 7.6 and prior) adds a firewall rule named “Sentinel License Manager” that allows incoming connections from private networks using TCP Port 1947. While uninstalling, the uninstaller fails to close Port 1947. | |
| Modificada | Alta (7.5) | 1.2% | — | Hashicorp Sentinel | 14/2/2020 | 17/6/2026 | HashiCorp Sentinel up to 0.10.1 incorrectly parsed negation in certain policy expressions. Fixed in 0.10.2. | |
| Modificada | Alta (7.8) | 0.42% | — | Gemalto Sentinel LDK License Manager | 11/12/2019 | 17/6/2026 | SafeNet Sentinel LDK License Manager, all versions prior to 7.101(only Microsoft Windows versions are affected) is vulnerable when configured as a service. This vulnerability may allow an attacker with local access to create, write, and/or delete files in system folder using symbolic links, leading to a privilege… | |
| Modificada | Media (6.5) | 1.2% | — | Gemalto Sentinel LDK | 7/6/2019 | 17/6/2026 | Hasplm cookie in Gemalto Admin Control Center, all versions prior to 7.92, does not have 'HttpOnly' flag. This allows malicious javascript to steal it. | |
| Modificada | Media (5.3) | 0.41% | — | Gemalto Sentinel LDK | 7/6/2019 | 17/6/2026 | Gemalto Admin Control Center, all versions prior to 7.92, uses cleartext HTTP to communicate with www3.safenet-inc.com to obtain language packs. This allows attacker to do man-in-the-middle (MITM) attack and replace original language pack by malicious one. | |
| Modificada | Alta (7.8) | 1.5% | — | Gemalto Sentinel Ultrapro Client Library | 11/4/2019 | 17/6/2026 | The uncontrolled search path element vulnerability in Gemalto Sentinel UltraPro Client Library ux32w.dll Versions 1.3.0, 1.3.1, and 1.3.2 enables an attacker to load and execute a malicious file. | |
| Modificada | Alta (7.5) | 1.2% | — | Gemalto Sentinel License Manager | 18/8/2018 | 17/6/2026 | A vulnerability in the lservnt.exe component of Sentinel License Manager version 8.5.3.35 (fixed in 8.5.3.2403) causes UDP amplification. | |
| Modificada | Media (6.1) | 0.78% | — | Gemalto Sentinel LDK RTE | 2/5/2018 | 17/6/2026 | The License Manager service of HASP SRM, Sentinel HASP and Sentinel LDK products prior to Sentinel LDK RTE 7.80 allows remote attackers to inject malicious web script in the logs page of Admin Control Center (ACC) for cross-site scripting (XSS) vulnerability. |