Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
746 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (0.6) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (0.6) | 0.32% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (0.6) | 0.40% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (0.6) | 0.40% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A buffer overflow vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify memory or crash processes. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (1.3) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Baja (1.3) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Media (4.9) | 0.53% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later | |
| Analizada | Baja (0.6) | 0.30% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (… | |
| Analizada | Baja (0.6) | 0.42% | — | Qnap Qsync Central | 11/2/2026 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and… | |
| Analizada | Media (4.2) | 0.18% | — | Jtenman Central Authentication System Server | 4/2/2026 | 17/6/2026 | XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2. | |
| Analizada | Media (6.5) | 0.21% | — | Oracle Life Sciences Central Coding | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Coding product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Analizada | Media (5.3) | 0.25% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Analizada | Media (6.5) | 0.29% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Analizada | Media (6.5) | 0.26% | — | Oracle Life Sciences Central Designer | 20/1/2026 | 17/6/2026 | Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central… | |
| Aplazada | Media (6.4) | 0.23% | — | SAP ERP Central ComponentAISAP EHS ManagementAISAP S/4hanaAI | 13/1/2026 | 17/6/2026 | Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or… | |
| Analizada | Alta (7.5) | 1.6% | — | Trendmicro Apex Central | 8/1/2026 | 7/10/2026 | A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability. | |
| Analizada | Alta (7.5) | 1.6% | — | Trendmicro Apex Central | 8/1/2026 | 7/10/2026 | A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.. | |
| Analizada | Crítica (9.8) | 3.6% | — | Trendmicro Apex Central | 8/1/2026 | 7/10/2026 | A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations. | |
| Analizada | Media (6.1) | 0.17% | — | Linecorp Central Dogma | 4/12/2025 | 17/6/2026 | Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft. | |
| Analizada | Media (6.1) | 0.20% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields. | |
| Aplazada | Media (6.9) | 36% | 💥 Exploit | N-able N-centralAI | 12/11/2025 | 17/6/2026 | N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4. | |
| Analizada | Crítica (9.8) | 0.45% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials. | |
| Analizada | Crítica (9.8) | 0.35% | — | Centralsquare Community Development | 12/11/2025 | 17/6/2026 | A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field. | |
| Modificada | Alta (8.4) | 31% | 💥 Exploit | N-able N-central | 12/11/2025 | 17/6/2026 | N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure | |
| Analizada | Crítica (10) | 0.58% | — | N-able N-central | 12/11/2025 | 17/6/2026 | The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization |