Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2778▼ 418 respecto a la semana anterior
Críticas / altas1332▼ 108 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)7.2%💥 PoCF5 Big-ip Next Central Manager8/5/202417/6/2026
An SQL injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaAlta (7.5)7.1%💥 PoCF5 Big-ip Next Central Manager8/5/202417/6/2026
An OData injection vulnerability exists in the BIG-IP Next Central Manager API (URI). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.7)0.09%—Rdkcentral Rdk-bGoogle AndroidOpenwrt6/5/202417/6/2026
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528185; Issue ID: ALPS08528185.
AnalizadaMedia (5.3)0.08%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt6/5/202417/6/2026
In DA, there is a possible permission bypass due to an incorrect status check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08355514; Issue ID: ALPS08355514.
AnalizadaMedia (6.6)0.27%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In gnss, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08580200; Issue ID: ALPS08580200.
AnalizadaAlta (8.4)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible out of bounds write due to an uncaught exception. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541764.
AnalizadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541761.
AnalizadaBaja (2.3)0.08%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible system crash due to an uncaught exception. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541758.
AnalizadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541757; Issue ID: ALPS08541757.
AnalizadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/4/202417/6/2026
In flashc, there is a possible information disclosure due to an uncaught exception. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541765; Issue ID: ALPS08541765.
AnalizadaAlta (8.8)0.18%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidLinux Kernel+11/4/202417/6/2026
In wlan firmware, there is a possible out of bounds write due to improper input validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08360153 (for MT6XXX chipsets) / WCNCR00363530 (for MT79XX…
AnalizadaMedia (6.7)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/3/202417/6/2026
In flashc, there is a possible out of bounds write due to lack of valudation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08541638; Issue ID: ALPS08541638.
ModificadaMedia (6.7)0.12%—Linuxfoundation YoctoRdkcentral RdkbGoogle AndroidOpenwrt4/3/202417/6/2026
In lk, there is a possible escalation of privilege due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08528255; Issue ID: ALPS08528255.
ModificadaMedia (4.3)0.43%—Hikvision Hikcentral Professional2/3/202417/6/2026
Due to insufficient server-side validation, an attacker with login privileges could access certain resources that the attacker should not have access to by changing parameter values.
ModificadaAlta (7.5)0.57%—Hikvision Hikcentral Professional2/3/202417/6/2026
Due to insufficient server-side validation, a successful exploit of this vulnerability could allow an attacker to gain access to certain URLs that the attacker should not have access to.
AnalizadaAlta (8.8)0.46%—Meshcentral20/2/202417/6/2026
MeshCentral is a full computer management web site. Versions prior to 1.1.21 a cross-site websocket hijacking (CSWSH) vulnerability within the control.ashx endpoint. This component is the primary mechanism used within MeshCentral to perform administrative actions on the server. The vulnerability is exploitable when an…
AnalizadaAlta (7.5)0.52%—F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+814/2/202417/6/2026
When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaAlta (7.5)0.34%—F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+814/2/202417/6/2026
When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaMedia (6)0.17%—F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+814/2/202417/6/2026
When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaAlta (7.5)0.52%—F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+914/2/202417/6/2026
When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaAlta (7.2)0.50%—F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+814/2/202417/6/2026
When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaAlta (8.7)0.83%—F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+814/2/202417/6/2026
When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not…
AnalizadaMedia (6.7)0.18%—F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+814/2/202417/6/2026
BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873. Note: Software…
ModificadaAlta (8)1.7%—Microsoft Dynamics 365 Business Central13/2/202410/8/2026
Microsoft Dynamics Business Central/NAV Information Disclosure Vulnerability
ModificadaMedia (5.4)0.34%—Trellix Central Management System13/2/202417/6/2026
A cross-site scripting vulnerability in Trellix Central Management (CM) prior to 9.1.3.97129 allows a remote authenticated attacker to craft CM dashboard internal requests causing arbitrary content to be injected into the response when accessing the CM dashboard.