Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.52%—Primx Zed!Primx ZedmailPrimx Zonecentral13/12/202317/6/2026
ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission), ZED! for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission), ZONECENTRAL for Windows before 2023.5, or ZEDMAIL for Windows before 2023.5…
ModificadaAlta (7.5)0.61%—Primx Zed!Primx ZedmailPrimx Zonecentral13/12/202317/6/2026
By default, .ZED containers produced by PRIMX ZED! for Windows before Q.2020.3 (ANSSI qualification submission); ZED! for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission); ZONECENTRAL for Windows before 2023.5; ZEDMAIL for Windows before…
ModificadaMedia (5.5)0.24%—Primx Zonecentral13/12/202317/6/2026
Encrypted folders created by PRIMX ZONECENTRAL for Windows before Q.2021.2 (ANSSI qualification submission) or ZONECENTRAL for Windows before 2023.5 can be modified by an unauthenticated attacker to include a UNC reference so that it could trigger outbound network traffic from computers on which folders are opened.
ModificadaMedia (6.7)0.11%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/12/202317/6/2026
In aee, there is a possible escalation of privilege due to a missing permission check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07909204; Issue ID: ALPS07909204.
ModificadaMedia (5.5)0.69%—Zohocorp Manageengine Analytics PlusZohocorp Manageengine AppcreatorZohocorp Manageengine Application Control PlusZohocorp Manageengine Browser Security Plus+3515/11/202317/6/2026
An information disclosure vulnerability exists in multiple ManageEngine products that can result in encryption keys being exposed. A low-privileged OS user with access to the host where an affected ManageEngine product is installed can view and use the exposed key to decrypt product database passwords. This allows the…
ModificadaCrítica (9.8)0.94%—Apereo Central Authentication Service9/11/202317/6/2026
Improper Authentication vulnerability in Apereo CAS in jakarta.servlet.http.HttpServletRequest.getRemoteAddr method allows Multi-Factor Authentication bypass.This issue affects CAS: through 7.0.0-RC7. It is unknown whether in new versions the issue will be fixed. For the date of publication there is no patch, and the…
ModificadaCrítica (9.8)0.55%—Microfocus Fortify Scancentral Dast8/11/202317/6/2026
Incorrect Privilege Assignment vulnerability in opentext Fortify ScanCentral DAST. The vulnerability could be exploited to gain elevated privileges.This issue affects Fortify ScanCentral DAST versions 21.1, 21.2, 21.2.1, 22.1, 22.1.1, 22.2, 23.1.
ModificadaAlta (8.8)3.3%—Zohocorp Manageengine Desktop Central3/11/202317/6/2026
A SSRF vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0, specifically the /smtpConfig.do component. This vulnerability could allow an authenticated attacker to launch targeted attacks, such as a cross-port attack, service enumeration and other attacks via HTTP requests.
ModificadaMedia (6.1)2.9%—Zohocorp Manageengine Desktop Central3/11/202317/6/2026
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.pdf.
ModificadaMedia (6.1)2.9%—Zohocorp Manageengine Desktop Central3/11/202317/6/2026
A CRLF injection vulnerability has been found in ManageEngine Desktop Central affecting version 9.1.0. This vulnerability could allow a remote attacker to inject arbitrary HTTP headers and perform HTTP response splitting attacks via the fileName parameter in /STATE_ID/1613157927228/InvSWMetering.csv.
ModificadaMedia (5.5)0.17%—F5 Big-iq Centralized ManagementF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Application Security Manager+1510/10/202317/6/2026
When TACACS+ audit forwarding is configured on BIG-IP or BIG-IQ system, sharedsecret is logged in plaintext in the audit log. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaMedia (6.5)0.24%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1610/10/202317/6/2026
The BIG-IP and BIG-IQ systems do not encrypt some sensitive information written to Database (DB) variables. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaAlta (8.8)0.25%—Wpcentral10/10/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Softaculous Ltd. WpCentral plugin <= 1.5.7 versions.
ModificadaMedia (6.1)0.45%—Broadpeak Centralized Accounts Management Auth Agent3/10/202317/6/2026
A cross-site scripting (XSS) vulnerability in the bpk-common/auth/login/index.html login portal in Broadpeak Centralized Accounts Management Auth Agent 01.01.00.19219575_ee9195b0, 01.01.01.30097902_fd999e76, and 00.12.01.9565588_1254b459 allows remote attackers to inject arbitrary web script or HTML via the…
ModificadaAlta (7.5)0.20%—Dell Data Protection Central27/9/202317/6/2026
Dell Data Protection Central, version 19.9, contains an Inadequate Encryption Strength Vulnerability. An unauthenticated network attacker could potentially exploit this vulnerability, allowing an attacker to recover plaintext from a block of ciphertext.
ModificadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/9/202317/6/2026
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08013530.
ModificadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/9/202317/6/2026
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014162.
ModificadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/9/202317/6/2026
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014156.
ModificadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/9/202317/6/2026
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014148.
ModificadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/9/202317/6/2026
In gps, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08014144; Issue ID: ALPS08014144.
ModificadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/9/202317/6/2026
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07937113; Issue ID: ALPS07937113.
ModificadaMedia (6.1)0.46%—Decentraland Single Sign ON Client1/9/202317/6/2026
@dcl/single-sign-on-client is an open source npm library which deals with single sign on authentication flows. Improper input validation in the `init` function allows arbitrary javascript to be executed using the `javascript:` prefix. This vulnerability has been patched on version `0.1.0`. Users are advised to…
ModificadaAlta (7.2)1.4%—Microsoft Dynamics 365 Business Central8/8/202310/8/2026
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
ModificadaMedia (4.4)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt7/8/202317/6/2026
In power, there is a possible memory corruption due to an incorrect bounds check. This could lead to local denial of service with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07929790; Issue ID: ALPS07929790.
ModificadaMedia (4.4)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt7/8/202317/6/2026
In nvram, there is a possible out of bounds write due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS07740194; Issue ID: ALPS07740194.