Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.48%—Central Monitor Cns-6201AI30/9/202517/6/2026
Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafted certain UDP packet, the affected device may abnormally terminate.
AnalizadaAlta (7.8)0.27%—Zohocorp Manageengine Endpoint Central25/9/202517/6/2026
ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13.
AnalizadaAlta (7.8)0.13%—N-able N-central10/9/202525/9/2026
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.
AnalizadaAlta (7.2)0.49%—Qnap Qsync Central29/8/202517/6/2026
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )…
AnalizadaAlta (7.2)0.49%—Qnap Qsync Central29/8/202517/6/2026
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )…
AnalizadaAlta (7.2)0.49%—Qnap Qsync Central29/8/202517/6/2026
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )…
AnalizadaAlta (7.2)0.49%—Qnap Qsync Central29/8/202517/6/2026
A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )…
AnalizadaAlta (8.3)0.23%—Qnap Qsync Central29/8/202517/6/2026
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )…
AnalizadaAlta (8.3)0.23%—Qnap Qsync Central29/8/202517/6/2026
An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )…
AnalizadaMedia (5.3)0.37%—Qnap Qsync Central29/8/202517/6/2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and…
AnalizadaMedia (5.3)0.46%—Qnap Qsync Central29/8/202517/6/2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.0 ( 2025/06/13 ) and…
AnalizadaMedia (5.3)0.46%—Qnap Qsync Central29/8/202517/6/2026
A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.0 ( 2025/06/13 ) and…
AnalizadaAlta (7.1)0.46%—Qnap Qsync Central29/8/202517/6/2026
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the…
AnalizadaAlta (7.1)0.46%—Qnap Qsync Central29/8/202517/6/2026
An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the…
AnalizadaMedia (6)0.46%—Qnap Qsync Central29/8/202517/6/2026
An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 (…
AnalizadaAlta (7.5)0.47%—Qnap Qsync Central29/8/202517/6/2026
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
AnalizadaAlta (7.5)0.47%—Qnap Qsync Central29/8/202517/6/2026
An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later
AplazadaAlta (8.6)0.47%💥 PoCHikvision Hikcentral ProfessionalAI29/8/202517/6/2026
There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission.
AplazadaMedia (5.3)0.33%—Hikvision Hikcentral FocsignAI29/8/202517/6/2026
There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access.
AplazadaMedia (4.7)0.35%—Hikvision Hikcentral Master LiteAI29/8/202517/6/2026
There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data.
AplazadaCrítica (9.8)0.71%💥 PoCRingcentral CommunicationsAI28/8/202517/6/2026
The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes.
AnalizadaAlta (8.3)0.28%—N-able N-central21/8/202517/6/2026
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.
AplazadaCrítica (9.3)0.33%—Nutanix Prism CentralAI20/8/202517/6/2026
Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context.
AnalizadaCrítica (9.4)3.4%⚠ Explotación activaN-able N-central14/8/202517/6/2026
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
AnalizadaCrítica (9.4)1.9%⚠ Explotación activa💥 PoCN-able N-central14/8/202524/9/2026
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.