Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
746 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 13% | — | Zohocorp Manageengine Desktop Central | 29/7/2020 | 17/6/2026 | An issue was discovered in the client side of Zoho ManageEngine Desktop Central 10.0.552.W. An attacker-controlled server can trigger an integer overflow in InternetSendRequestEx and InternetSendRequestByBitrate that leads to a heap-based buffer overflow and Remote Code Execution with SYSTEM privileges. This issue… | |
| Modificada | Alta (7.8) | 0.42% | — | Riverbed Steelcentral Aternity Agent | 27/7/2020 | 17/6/2026 | SteelCentral Aternity Agent 11.0.0.120 on Windows mishandles IPC. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among different processes and uses IPC (Inter-Process Communication) primitives to… | |
| Modificada | Alta (7.5) | 1.9% | — | Riverbed Steelcentral Aternity Agent | 27/7/2020 | 17/6/2026 | SteelCentral Aternity Agent before 11.0.0.120 on Windows allows Privilege Escalation via a crafted file. It uses an executable running as a high privileged Windows service to perform administrative tasks and collect data from other processes. It distributes functionality among different processes and uses IPC… | |
| Modificada | Media (6.3) | 1.8% | — | Apache ANTCanonical Ubuntu LinuxFedoraproject FedoraOpensuse Leap+46 | 14/5/2020 | 17/6/2026 | Apache Ant 1.1 to 1.9.14 and 1.10.0 to 1.10.7 uses the default temporary directory identified by the Java system property java.io.tmpdir for several tasks and may thus leak sensitive information. The fixcrlf and replaceregexp tasks also copy files from the temporary directory back into the build tree allowing an… | |
| Modificada | Media (6.5) | 4.4% | — | Zohocorp Manageengine Desktop Central | 5/5/2020 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.0.484 allows authenticated arbitrary file writes during ZIP archive extraction via Directory Traversal in a crafted AppDependency API request. | |
| Modificada | Media (5.5) | 0.47% | — | F5 Big-iq Centralized ManagementF5 Big-ip Local Traffic ManagerF5 Big-ip Application Acceleration ManagerF5 Big-ip Advanced Firewall Manager+8 | 30/4/2020 | 17/6/2026 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.3, and 12.1.0-12.1.5.1 and BIG-IQ 5.2.0-7.1.0, when creating a QKView, credentials for binding to LDAP servers used for remote authentication of the BIG-IP administrative interface will not fully obfuscate if they contain whitespace. | |
| Modificada | Alta (7.2) | 1.4% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 30/4/2020 | 17/6/2026 | On BIG-IP 15.0.0-15.0.1, 14.1.0-14.1.2.3, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.1-11.6.5 and BIG-IQ 5.2.0-7.1.0, a user associated with the Resource Administrator role who has access to the secure copy (scp) utility but does not have access to Advanced Shell (bash) can execute arbitrary commands using a maliciously… | |
| Modificada | Alta (8.1) | 0.52% | — | F5 Big-iq Centralized Management | 24/4/2020 | 17/6/2026 | In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization mechanisms do not use any form of authentication for connecting to the peer. | |
| Modificada | Crítica (9.1) | 0.48% | — | F5 Big-iq Centralized Management | 24/4/2020 | 17/6/2026 | In BIG-IQ 5.2.0-7.0.0, high availability (HA) synchronization is not secure by TLS and may allow on-path attackers to read / modify confidential data in transit. | |
| Modificada | Crítica (9.8) | 2.2% | — | F5 Big-iq Centralized Management | 24/4/2020 | 17/6/2026 | In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface. | |
| Modificada | Alta (8.8) | 2.0% | — | Anti-virus FOR Sophos CentralAnti-virus FOR Sophos Home | 17/4/2020 | 17/6/2026 | Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation. | |
| Modificada | Alta (8) | 6.8% | — | Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV | 15/4/2020 | 17/6/2026 | A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | |
| Modificada | Alta (7.5) | 6.3% | — | Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV | 15/4/2020 | 17/6/2026 | An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security… | |
| Modificada | Alta (7.5) | 11% | — | Zohocorp Manageengine Desktop Central | 30/3/2020 | 17/6/2026 | Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure. | |
| Modificada | Alta (8.1) | 0.85% | — | F5 Big-iq Centralized ManagementF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 27/3/2020 | 17/6/2026 | On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of authentication and HA network failover… | |
| Modificada | Alta (7.8) | 0.45% | — | F5 Big-iq Centralized ManagementF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+10 | 27/3/2020 | 17/6/2026 | On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users with non-administrator roles (for example, Guest or Resource Administrator) with tmsh shell access can execute arbitrary commands with elevated privilege via a crafted… | |
| Modificada | Media (6.1) | 3.2% | — | Zohocorp Manageengine Desktop Central | 23/3/2020 | 17/6/2026 | ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role. | |
| Modificada | Alta (7.5) | 0.65% | — | Dell EMC Data Protection CentralDell EMC Integrated Data Protection Appliance | 18/3/2020 | 17/6/2026 | Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to impersonate a valid system to compromise… | |
| Modificada | Alta (8) | 11% | — | Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV | 12/3/2020 | 17/6/2026 | An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'. | |
| Modificada | Crítica (9.8) | 13% | — | Zohocorp Manageengine Desktop Central | 11/3/2020 | 17/6/2026 | An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request. | |
| Modificada | Alta (7.5) | 2.8% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 10/3/2020 | 17/6/2026 | A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and download arbitrary files from the server. | |
| Modificada | Alta (8.1) | 1.8% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 10/3/2020 | 17/6/2026 | A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The two FTP services (default ports 21/tcp and 5411/tcp) of the SiVMS/SiNVR Video Server contain a path traversal vulnerability that could allow an authenticated remote attacker to access and download arbitrary files from the… | |
| Modificada | Media (4.3) | 1.1% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 10/3/2020 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) does not enforce logging of security-relevant activities in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An authenticated remote attacker could… | |
| Modificada | Media (5.4) | 1.0% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 10/3/2020 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains multiple stored Cross-site Scripting (XSS) vulnerabilities in several input fields. This could allow an authenticated remote attacker to inject malicious JavaScript… | |
| Modificada | Media (6.1) | 1.3% | — | Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server | 10/3/2020 | 17/6/2026 | A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains a reflected Cross-site Scripting (XSS) vulnerability that could allow an unauthenticated remote attacker to steal sensitive data or execute administrative actions on… |