Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.2%—F5 Big-iq Centralized Management24/4/202017/6/2026
In BIG-IQ 6.0.0-7.0.0, a remote access vulnerability has been discovered that may allow a remote user to execute shell commands on affected systems using HTTP requests to the BIG-IQ user interface.
ModificadaAlta (8.8)2.0%—Anti-virus FOR Sophos CentralAnti-virus FOR Sophos Home17/4/202017/6/2026
Mac Endpoint for Sophos Central before 9.9.6 and Mac Endpoint for Sophos Home before 2.2.6 allow Privilege Escalation.
ModificadaAlta (8)6.8%—Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV15/4/202017/6/2026
A remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
ModificadaAlta (7.5)6.3%—Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV15/4/202017/6/2026
An information disclosure vulnerability exists when Microsoft Dynamics Business Central/NAV on-premise does not properly hide the value of a masked field when showing the records as a chart page.The attacker who successfully exploited the vulnerability could see the information that are in a masked field.The security…
ModificadaAlta (7.5)11%—Zohocorp Manageengine Desktop Central30/3/202017/6/2026
Zoho ManageEngine Desktop Central before 10.0.483 allows unauthenticated users to access PDFGenerationServlet, leading to sensitive information disclosure.
ModificadaAlta (8.1)0.85%—F5 Big-iq Centralized ManagementF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+827/3/202017/6/2026
On BIG-IP 15.0.0-15.1.0.2, 14.1.0-14.1.2.3, 13.1.0-13.1.3.2, 12.1.0-12.1.5.1, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, in a High Availability (HA) network failover in Device Service Cluster (DSC), the failover service does not require a strong form of authentication and HA network failover…
ModificadaAlta (7.8)0.45%—F5 Big-iq Centralized ManagementF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+1027/3/202017/6/2026
On BIG-IP 15.0.0-15.0.1.2, 14.1.0-14.1.2.2, 13.1.0-13.1.3.2, 12.1.0-12.1.5, and 11.5.2-11.6.5.1 and BIG-IQ 7.0.0, 6.0.0-6.1.0, and 5.2.0-5.4.0, users with non-administrator roles (for example, Guest or Resource Administrator) with tmsh shell access can execute arbitrary commands with elevated privilege via a crafted…
ModificadaMedia (6.1)3.2%—Zohocorp Manageengine Desktop Central23/3/202017/6/2026
ManageEngine_DesktopCentral.exe in Zoho ManageEngine Desktop Central 10 allows HTML injection on the user administration page via the description of a role.
ModificadaAlta (7.5)0.65%—Dell EMC Data Protection CentralDell EMC Integrated Data Protection Appliance18/3/202017/6/2026
Data Protection Central versions 1.0, 1.0.1, 18.1, 18.2, and 19.1 contains an Improper Certificate Chain of Trust Vulnerability. A remote unauthenticated attacker could potentially exploit this vulnerability by obtaining a CA signed certificate from Data Protection Central to impersonate a valid system to compromise…
ModificadaAlta (8)11%—Microsoft Dynamics 365 Business CentralMicrosoft Dynamics NAV12/3/202017/6/2026
An remote code execution vulnerability exists in Microsoft Dynamics Business Central, aka 'Dynamics Business Central Remote Code Execution Vulnerability'.
ModificadaCrítica (9.8)13%—Zohocorp Manageengine Desktop Central11/3/202017/6/2026
An XML external entity (XXE) vulnerability in Zoho ManageEngine Desktop Central before the 07-Mar-2020 update allows remote unauthenticated users to read arbitrary files or conduct server-side request forgery (SSRF) attacks via a crafted DTD in an XML request.
ModificadaAlta (7.5)2.8%—Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server10/3/202017/6/2026
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The streaming service (default port 5410/tcp) of the SiVMS/SiNVR Video Server contains a path traversal vulnerability, that could allow an unauthenticated remote attacker to access and download arbitrary files from the server.
ModificadaAlta (8.1)1.8%—Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server10/3/202017/6/2026
A vulnerability has been identified in SiNVR/SiVMS Video Server (All versions < V5.0.0). The two FTP services (default ports 21/tcp and 5411/tcp) of the SiVMS/SiNVR Video Server contain a path traversal vulnerability that could allow an authenticated remote attacker to access and download arbitrary files from the…
ModificadaMedia (4.3)1.1%—Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server10/3/202017/6/2026
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) does not enforce logging of security-relevant activities in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An authenticated remote attacker could…
ModificadaMedia (5.4)1.0%—Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server10/3/202017/6/2026
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains multiple stored Cross-site Scripting (XSS) vulnerabilities in several input fields. This could allow an authenticated remote attacker to inject malicious JavaScript…
ModificadaMedia (6.1)1.3%—Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server10/3/202017/6/2026
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The web interface of the Control Center Server (CCS) contains a reflected Cross-site Scripting (XSS) vulnerability that could allow an unauthenticated remote attacker to steal sensitive data or execute administrative actions on…
ModificadaAlta (8.8)2.0%—Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server10/3/202017/6/2026
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The Control Center Server (CCS) contains an SQL injection vulnerability in its XML-based communication protocol as provided by default on ports 5444/tcp and 5440/tcp. An authenticated remote attacker could exploit this…
ModificadaMedia (6.5)0.75%—Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server10/3/202017/6/2026
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0), SiNVR/SiVMS Video Server (All versions < V5.0.0). The FTP services of the SiVMS/SiNVR Video Server and the Control Center Server (CCS) maintain log files that store login credentials in cleartext. In configurations where the…
ModificadaMedia (6.5)1.8%—Siemens Sinvr 3 Central Control ServerSiemens Sinvr 3 Video Server10/3/202017/6/2026
A vulnerability has been identified in Control Center Server (CCS) (All versions < V1.5.0). The DOWNLOADS section in the web interface of the Control Center Server (CCS) contains a path traversal vulnerability that could allow an authenticated remote attacker to access and download arbitrary files from the server…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitZohocorp Manageengine Desktop Central6/3/202017/6/2026
Zoho ManageEngine Desktop Central before 10.0.474 allows remote code execution because of deserialization of untrusted data in getChartImage in the FileStorage class. This is related to the CewolfServlet and MDMLogUploaderServlet servlets.
ModificadaAlta (8.8)8.2%💥 ExploitWpcentral17/2/202017/6/2026
The wpCentral plugin before 1.5.1 for WordPress allows disclosure of the connection key.
ModificadaMedia (5.9)0.81%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+136/2/202017/6/2026
On BIG-IP 15.0.0-15.0.1.1, 14.1.0-14.1.2.2, 14.0.0-14.0.1, 13.1.0-13.1.3.1, 12.1.0-12.1.5, and 11.6.0-11.6.5.1, the tmm crashes under certain circumstances when using the connector profile if a specific sequence of connections are made.
ModificadaCrítica (9.8)75%💥 ExploitZohocorp Manageengine Desktop Central27/1/202017/6/2026
Unrestricted file upload vulnerability in AgentLogUploadServlet in ManageEngine DesktopCentral 7.x and 8.0.0 before build 80293 allows remote attackers to execute arbitrary code by uploading a file with a jsp extension, then accessing it via a direct request to the file in the webroot.
ModificadaCrítica (9.8)2.1%—Bitdefender BOX 2 FirmwareBitdefender Central27/1/202017/6/2026
A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command.
ModificadaAlta (7.5)2.5%—Solarwinds N-central26/1/202017/6/2026
SolarWinds N-central before 12.1 SP1 HF5 and 12.2 before SP1 HF2 allows remote attackers to retrieve cleartext domain admin credentials from the Agent & Probe settings, and obtain other sensitive information. The attacker can use a customer ID to self register and read any aspects of the agent/appliance configuration.
Orbitaley — Vulnerabilidades