Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
746 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.7) | 0.22% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/7/2024 | 17/6/2026 | In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412. | |
| Analizada | Crítica (9.8) | 0.29% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle Android | 1/7/2024 | 17/6/2026 | In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424. | |
| Aplazada | Media (4.3) | 0.21% | — | Decentralizejustice AnonymouslockerAIDecentralizejustice AnonbackendAI | 13/6/2024 | 17/6/2026 | An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext. | |
| Aplazada | Media (6.5) | 0.39% | — | Annonshop APPAIDecentralizejustice AnonymouslockerAI | 13/6/2024 | 17/6/2026 | An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request. | |
| Modificada | Alta (8.8) | 3.4% | — | Microsoft Dynamics 365 Business Central | 11/6/2024 | 10/8/2026 | Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability | |
| Modificada | Alta (7.3) | 0.95% | — | Microsoft Dynamics 365 Business Central | 11/6/2024 | 21/7/2026 | Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability | |
| Analizada | Crítica (9.1) | 1.8% | 💥 Exploit | Apereo Central Authentication Service | 23/5/2024 | 17/6/2026 | The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack | |
| Analizada | Media (6.8) | 0.23% | — | F5 Big-ip Next Central Manager | 8/5/2024 | 17/6/2026 | An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.4) | 0.55% | — | F5 Big-ip Next Central Manager | 8/5/2024 | 17/6/2026 | BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (7.5) | 7.2% | 💥 PoC | F5 Big-ip Next Central Manager | 8/5/2024 | 17/6/2026 | An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (7.5) | 7.1% | 💥 PoC | F5 Big-ip Next Central Manager | 8/5/2024 | 17/6/2026 | An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.7) | 0.09% | — | Rdkcentral Rdk-bGoogle AndroidOpenwrt | 6/5/2024 | 17/6/2026 | In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185. | |
| Analizada | Media (5.3) | 0.08% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 6/5/2024 | 17/6/2026 | In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514. | |
| Analizada | Media (6.6) | 0.27% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200. | |
| Analizada | Alta (8.4) | 0.09% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764. | |
| Analizada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541761. | |
| Analizada | Baja (2.3) | 0.08% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758. | |
| Analizada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757. | |
| Analizada | Media (4.4) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 1/4/2024 | 17/6/2026 | In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765. | |
| Analizada | Alta (8.8) | 0.18% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidLinux Kernel+1 | 1/4/2024 | 17/6/2026 | In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08360153 (for MT6XXX chipsets) / WCNCR00363530 (for MT79XX… | |
| Analizada | Media (6.7) | 0.10% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt | 4/3/2024 | 17/6/2026 | In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541638; Issue ID: ALPS08541638. | |
| Modificada | Media (6.7) | 0.12% | — | Linuxfoundation YoctoRdkcentral RdkbGoogle AndroidOpenwrt | 4/3/2024 | 17/6/2026 | In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528255; Issue ID: ALPS08528255. | |
| Modificada | Media (4.3) | 0.43% | — | Hikvision Hikcentral Professional | 2/3/2024 | 17/6/2026 | Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values. | |
| Modificada | Alta (7.5) | 0.57% | — | Hikvision Hikcentral Professional | 2/3/2024 | 17/6/2026 | Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to. | |
| Analizada | Alta (8.8) | 0.46% | — | Meshcentral | 20/2/2024 | 17/6/2026 | MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary mechanism used within MeshCentral to perform administrative actions on the server. The vulnerability is exploitable when an… |