Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaBaja (1.3)0.42%—Qnap Qsync Central11/2/202617/6/2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and…
AnalizadaMedia (4.9)0.53%—Qnap Qsync Central11/2/202617/6/2026
An out-of-bounds write vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to modify or corrupt memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and later
AnalizadaBaja (0.6)0.30%—Qnap Qsync Central11/2/202617/6/2026
A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 (…
AnalizadaBaja (0.6)0.42%—Qnap Qsync Central11/2/202617/6/2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.4 ( 2026/01/20 ) and…
AnalizadaMedia (4.2)0.18%—Jtenman Central Authentication System Server4/2/202617/6/2026
XML Injection (aka Blind XPath Injection) vulnerability in Drupal Central Authentication System (CAS) Server allows Privilege Escalation.This issue affects Central Authentication System (CAS) Server: from 0.0.0 before 2.0.3, from 2.1.0 before 2.1.2.
AnalizadaMedia (6.5)0.21%—Oracle Life Sciences Central Coding20/1/202617/6/2026
Vulnerability in the Oracle Life Sciences Central Coding product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central…
AnalizadaMedia (5.3)0.25%—Oracle Life Sciences Central Designer20/1/202617/6/2026
Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central…
AnalizadaMedia (6.5)0.29%—Oracle Life Sciences Central Designer20/1/202617/6/2026
Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Life Sciences Central…
AnalizadaMedia (6.5)0.26%—Oracle Life Sciences Central Designer20/1/202617/6/2026
Vulnerability in the Oracle Life Sciences Central Designer product of Oracle Health Sciences Applications (component: Platform). The supported version that is affected is 7.0.1.0. Easily exploitable vulnerability allows unauthenticated attacker with network access via HTTP to compromise Oracle Life Sciences Central…
AplazadaMedia (6.4)0.23%—SAP ERP Central ComponentAISAP EHS ManagementAISAP S/4hanaAI13/1/202617/6/2026
Due to missing authorization check in the SAP ERP Central Component (SAP ECC) and SAP S/4HANA (SAP EHS Management), an attacker could extract hardcoded clear-text credentials and bypass the password authentication check by manipulating user parameters. Upon successful exploitation, the attacker can access, modify or…
AnalizadaAlta (7.5)1.6%—Trendmicro Apex Central8/1/20267/10/2026
A message out-of-bounds read vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability.
AnalizadaAlta (7.5)1.6%—Trendmicro Apex Central8/1/20267/10/2026
A message unchecked NULL return value vulnerability in Trend Micro Apex Central could allow a remote attacker to create a denial-of-service condition on affected installations. Please note: authentication is not required in order to exploit this vulnerability..
AnalizadaCrítica (9.8)3.6%—Trendmicro Apex Central8/1/20267/10/2026
A LoadLibraryEX vulnerability in Trend Micro Apex Central could allow an unauthenticated remote attacker to load an attacker-controlled DLL into a key executable, leading to execution of attacker-supplied code under the context of SYSTEM on affected installations.
AnalizadaMedia (6.1)0.17%—Linecorp Central Dogma4/12/202517/6/2026
Central Dogma versions before 0.78.0 contain an Open Redirect vulnerability that allows attackers to redirect users to untrusted sites via specially crafted URLs, potentially facilitating phishing attacks and credential theft.
AnalizadaMedia (6.1)0.20%—Centralsquare Community Development12/11/202517/6/2026
Cross Site Scripting vulnerability in CentralSquare Community Development 19.5.7 via form fields.
AplazadaMedia (6.9)36%💥 ExploitN-able N-centralAI12/11/202517/6/2026
N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.
AnalizadaCrítica (9.8)0.45%—Centralsquare Community Development12/11/202517/6/2026
An Authentication Bypass issue in CentralSquare Community Development 19.5.7 allows attackers to access the admin panel without admin credentials.
AnalizadaCrítica (9.8)0.35%—Centralsquare Community Development12/11/202517/6/2026
A SQL Injection Vulnerability in CentralSquare Community Development 19.5.7 allows attackers to inject SQL via the permit_no field.
ModificadaAlta (8.4)31%💥 ExploitN-able N-central12/11/202517/6/2026
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
AnalizadaCrítica (10)0.58%—N-able N-central12/11/202517/6/2026
The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
AnalizadaCrítica (9.4)0.56%—N-able N-central12/11/202517/6/2026
N-central < 2025.4 is vulnerable to authentication bypass via path traversal
AnalizadaMedia (4)0.45%—Qnap Qsync Central7/11/202517/6/2026
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.3 ( 2025/08/28 )…
AnalizadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+14/11/202517/6/2026
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010443; Issue ID: MSV-3966.
AnalizadaMedia (6.7)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+14/11/202517/6/2026
In gnss service, there is a possible out of bounds write due to an incorrect bounds check. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10010441; Issue ID: MSV-3967.
AnalizadaMedia (6.7)0.08%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/11/202517/6/2026
In preloader, there is a possible escalation of privilege due to an insecure default value. This could lead to local escalation of privilege if a malicious actor has already obtained the System privilege. User interaction is not needed for exploitation. Patch ID: ALPS10068463; Issue ID: MSV-4141.