Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.55%—N-able N-central8/2/202417/6/2026
An issue discovered in N-able N-central before 2023.6 and earlier allows attackers to gain escalated privileges via API calls.
ModificadaMedia (6.7)0.22%—Rdkcentral Rdk-bGoogle AndroidOpenwrt5/2/202417/6/2026
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08477148; Issue ID: ALPS08477148.
ModificadaCrítica (9.8)0.84%—Gttb GTB Central Console2/2/202417/6/2026
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method setTermsHashAction at /opt/webapp/lib/PureApi/CCApi.class.php is vulnerable to an unauthenticated SQL injection via /ccapi.php that an attacker can abuse in order to change the Administrator password to a known value.
ModificadaAlta (7.2)2.5%—Gttb GTB Central Console2/2/202417/6/2026
An issue was discovered in GTB Central Console 15.17.1-30814.NG. The method systemSettingsDnsDataAction at /opt/webapp/src/AppBundle/Controller/React/SystemSettingsController.php is vulnerable to command injection via the /old/react/v1/api/system/dns/data endpoint. An authenticated attacker can abuse it to inject an…
ModificadaAlta (7.5)0.53%—Meshcentral2/2/202417/6/2026
Ylianst MeshCentral 1.1.16 suffers from Use of a Broken or Risky Cryptographic Algorithm.
ModificadaAlta (8.1)1.0%💥 PoCQnap Qsync Central2/2/202417/6/2026
An incorrect permission assignment for critical resource vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow authenticated users to read or modify the resource via a network. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.15 (…
ModificadaMedia (6.1)0.49%—Linecorp Central Dogma2/2/202417/6/2026
Central Dogma versions prior to 0.64.1 is vulnerable to Cross-Site Scripting (XSS), which could allow for the leakage of user sessions and subsequent authentication bypass.
ModificadaCrítica (9.8)0.47%—Meshcentral30/1/202417/6/2026
Ylianst MeshCentral 1.1.16 is vulnerable to Missing SSL Certificate Validation.
ModificadaAlta (7.5)0.83%—Meshcentral29/1/202417/6/2026
An algorithm-downgrade issue was discovered in Ylianst MeshCentral 1.1.16.
ModificadaAlta (7.1)0.55%—Trendmicro Apex Central23/1/202417/6/2026
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in order to exploit this…
ModificadaMedia (6.1)0.94%—Trendmicro Apex Central23/1/202417/6/2026
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52326.
ModificadaMedia (6.1)2.5%—Trendmicro Apex Central23/1/202417/6/2026
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52329.
ModificadaMedia (6.1)2.5%—Trendmicro Apex Central23/1/202417/6/2026
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52328.
ModificadaMedia (6.1)2.5%—Trendmicro Apex Central23/1/202417/6/2026
Certain dashboard widgets on Trend Micro Apex Central (on-premise) are vulnerable to cross-site scripting (XSS) attacks that may allow an attacker to achieve remote code execution on affected servers. Please note this vulnerability is similar, but not identical to CVE-2023-52327.
ModificadaAlta (7.5)4.5%—Trendmicro Apex Central23/1/202417/6/2026
A local file inclusion vulnerability in one of Trend Micro Apex Central's widgets could allow a remote attacker to execute arbitrary code on affected installations. Please note: this vulnerability must be used in conjunction with another one to exploit an affected system. In addition, an attacker must first obtain a…
ModificadaAlta (8.8)4.2%—Trendmicro Apex Central23/1/202417/6/2026
An unrestricted file upload vulnerability in Trend Micro Apex Central could allow a remote attacker to create arbitrary files on affected installations. Please note: although authentication is required to exploit this vulnerability, this vulnerability could be exploited when the attacker has any valid set of…
ModificadaMedia (5.4)0.32%—Trendmicro Apex Central23/1/202417/6/2026
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…
ModificadaMedia (5.4)0.32%—Trendmicro Apex Central23/1/202417/6/2026
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…
ModificadaMedia (5.4)0.32%—Trendmicro Apex Central23/1/202417/6/2026
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…
ModificadaMedia (5.4)0.33%—Trendmicro Apex Central23/1/202417/6/2026
A post-authenticated server-side request forgery (SSRF) vulnerability in Trend Micro Apex Central 2019 (lower than build 6481) could allow an attacker to interact with internal or local services directly. Please note: an attacker must first obtain the ability to execute low-privileged code on the target system in…
ModificadaAlta (7.8)0.33%—Fireeye Central Management15/1/202417/6/2026
Remote file inclusion vulnerability in FireEye Central Management affecting version 9.1.1.956704. This vulnerability allows an attacker to upload a malicious PDF file to the system during the report creation process.
ModificadaMedia (6.1)0.31%—Fireeye Central Management15/1/202417/6/2026
XSS vulnerability in FireEye Central Management affecting version 9.1.1.956704, which could allow an attacker to modify special HTML elements in the application and cause a reflected XSS, leading to a session hijacking.
ModificadaMedia (4.3)0.67%💥 PoCCentralsquare Click2gov Building Permit12/1/202417/6/2026
An issue was discovered in CentralSquare Click2Gov Building Permit before October 2023. Lack of access control protections allows remote attackers to arbitrarily delete the contractors from any user's account when the user ID and contractor information is known.
ModificadaMedia (5.5)0.13%—Primx Zonecentral13/12/202317/6/2026
Encrypted folders created by PRIMX ZONECENTRAL through 2023.5 can be modified by a local attacker (with appropriate privileges) so that specific file types are excluded from encryption temporarily. (This modification can, however, be detected, as described in the Administrator Guide.)
ModificadaMedia (5.5)0.23%—Primx Zed!Primx ZedmailPrimx Zonecentral13/12/202317/6/2026
ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before 2023.5; ZED!…
Orbitaley — Vulnerabilidades