Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

746 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.7)0.22%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/7/202417/6/2026
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412.
AnalizadaCrítica (9.8)0.29%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle Android1/7/202417/6/2026
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.
AplazadaMedia (4.3)0.21%—Decentralizejustice AnonymouslockerAIDecentralizejustice AnonbackendAI13/6/202417/6/2026
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.
AplazadaMedia (6.5)0.39%—Annonshop APPAIDecentralizejustice AnonymouslockerAI13/6/202417/6/2026
An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.
ModificadaAlta (8.8)3.4%—Microsoft Dynamics 365 Business Central11/6/202410/8/2026
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
ModificadaAlta (7.3)0.95%—Microsoft Dynamics 365 Business Central11/6/202421/7/2026
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
AnalizadaCrítica (9.1)1.8%💥 ExploitApereo Central Authentication Service23/5/202417/6/2026
The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack
AnalizadaMedia (6.8)0.23%—F5 Big-ip Next Central Manager8/5/202417/6/2026
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (7.4)0.55%—F5 Big-ip Next Central Manager8/5/202417/6/2026
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (7.5)7.2%💥 PoCF5 Big-ip Next Central Manager8/5/202417/6/2026
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaAlta (7.5)7.1%💥 PoCF5 Big-ip Next Central Manager8/5/202417/6/2026
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.7)0.09%—Rdkcentral Rdk-bGoogle AndroidOpenwrt6/5/202417/6/2026
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.
AnalizadaMedia (5.3)0.08%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt6/5/202417/6/2026
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.
AnalizadaMedia (6.6)0.27%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.
AnalizadaAlta (8.4)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.
AnalizadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541761.
AnalizadaBaja (2.3)0.08%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.
AnalizadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757.
AnalizadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765.
AnalizadaAlta (8.8)0.18%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidLinux Kernel+11/4/202417/6/2026
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08360153 (for MT6XXX chipsets) / WCNCR00363530 (for MT79XX…
AnalizadaMedia (6.7)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/3/202417/6/2026
In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541638; Issue ID: ALPS08541638.
ModificadaMedia (6.7)0.12%—Linuxfoundation YoctoRdkcentral RdkbGoogle AndroidOpenwrt4/3/202417/6/2026
In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528255; Issue ID: ALPS08528255.
ModificadaMedia (4.3)0.43%—Hikvision Hikcentral Professional2/3/202417/6/2026
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
ModificadaAlta (7.5)0.57%—Hikvision Hikcentral Professional2/3/202417/6/2026
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.
AnalizadaAlta (8.8)0.46%—Meshcentral20/2/202417/6/2026
MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary mechanism used within MeshCentral to perform administrative actions on the server. The vulnerability is exploitable when an…
Orbitaley — Vulnerabilidades