Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.55% | — | N-able N-central | 8/2/2024 | 17/6/2026 | An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls. | |
| Modificada | Media (6.7) | 0.22% | — | Rdkcentral Rdk-bGoogle AndroidOpenwrt | 5/2/2024 | 17/6/2026 | In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: ALPS08477148. | |
| Modificada | Crítica (9.8) | 0.84% | — | Gttb GTB Central Console | 2/2/2024 | 17/6/2026 | An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value. | |
| Modificada | Alta (7.2) | 2.5% | — | Gttb GTB Central Console | 2/2/2024 | 17/6/2026 | An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an… | |
| Modificada | Alta (7.5) | 0.53% | — | Meshcentral | 2/2/2024 | 17/6/2026 | Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm. | |
| Modificada | Alta (8.1) | 1.0% | 💥 PoC | Qnap Qsync Central | 2/2/2024 | 17/6/2026 | An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 (… | |
| Modificada | Media (6.1) | 0.49% | — | Linecorp Central Dogma | 2/2/2024 | 17/6/2026 | Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass. | |
| Modificada | Crítica (9.8) | 0.47% | — | Meshcentral | 30/1/2024 | 17/6/2026 | Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation. | |
| Modificada | Alta (7.5) | 0.83% | — | Meshcentral | 29/1/2024 | 17/6/2026 | An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16. | |
| Modificada | Alta (7.1) | 0.55% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this… | |
| Modificada | Media (6.1) | 0.94% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52326. | |
| Modificada | Media (6.1) | 2.5% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52329. | |
| Modificada | Media (6.1) | 2.5% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52328. | |
| Modificada | Media (6.1) | 2.5% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52327. | |
| Modificada | Alta (7.5) | 4.5% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations. Please note: this vulnerability must be used in conjunction with another one to exploit an affected system. In addition, an attacker must first obtain a… | |
| Modificada | Alta (8.8) | 4.2% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of… | |
| Modificada | Media (5.4) | 0.32% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Media (5.4) | 0.32% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Media (5.4) | 0.32% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Media (5.4) | 0.33% | — | Trendmicro Apex Central | 23/1/2024 | 17/6/2026 | A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in… | |
| Modificada | Alta (7.8) | 0.33% | — | Fireeye Central Management | 15/1/2024 | 17/6/2026 | Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system during the report creation process. | |
| Modificada | Media (6.1) | 0.31% | — | Fireeye Central Management | 15/1/2024 | 17/6/2026 | XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a session hijacking. | |
| Modificada | Media (4.3) | 0.67% | 💥 PoC | Centralsquare Click2gov Building Permit | 12/1/2024 | 17/6/2026 | An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known. | |
| Modificada | Media (5.5) | 0.13% | — | Primx Zonecentral | 13/12/2023 | 17/6/2026 | Encrypted folders created by PRIMX ZONECENTRAL through 2023.5 can be modified by a local attacker (with appropriate privileges) so that specific file types are excluded from encryption temporarily. (This modification can, however, be detected, as described in the Administrator Guide.) | |
| Modificada | Media (5.5) | 0.23% | — | Primx Zed!Primx ZedmailPrimx Zonecentral | 13/12/2023 | 17/6/2026 | ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; ZED!… |