Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.48% | — | Central Monitor Cns-6201AI | 30/9/2025 | 17/6/2026 | Multiple versions of Central Monitor CNS-6201 contain a NULL pointer dereference vulnerability. When processing a crafted certain UDP packet, the affected device may abnormally terminate. | |
| Analizada | Alta (7.8) | 0.27% | — | Zohocorp Manageengine Endpoint Central | 25/9/2025 | 17/6/2026 | ZohoCorp ManageEngine Endpoint Central was impacted by an improper privilege management issue in the agent setup. This issue affects Endpoint Central: through 11.4.2500.25, through 11.4.2508.13. | |
| Analizada | Alta (7.8) | 0.13% | — | N-able N-central | 10/9/2025 | 25/9/2026 | An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions. | |
| Analizada | Alta (7.2) | 0.49% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Alta (7.2) | 0.49% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Alta (7.2) | 0.49% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Alta (7.2) | 0.49% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A path traversal vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to read the contents of unexpected files or system data. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Alta (8.3) | 0.23% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Alta (8.3) | 0.23% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An improper certificate validation vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to compromise the security of the system. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 )… | |
| Analizada | Media (5.3) | 0.37% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and… | |
| Analizada | Media (5.3) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.0 ( 2025/06/13 ) and… | |
| Analizada | Media (5.3) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | A NULL pointer dereference vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 5.0.0.0 ( 2025/06/13 ) and… | |
| Analizada | Alta (7.1) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Alta (7.1) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An allocation of resources without limits or throttling vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to prevent other systems, applications, or processes from accessing the same type of resource. We have already fixed the… | |
| Analizada | Media (6) | 0.46% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An uncontrolled resource consumption vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to launch a denial-of-service (DoS) attack. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 (… | |
| Analizada | Alta (7.5) | 0.47% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later | |
| Analizada | Alta (7.5) | 0.47% | — | Qnap Qsync Central | 29/8/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Qsync Central. If a remote attacker gains a user account, they can then exploit the vulnerability to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.7 ( 2025/04/23 ) and later | |
| Aplazada | Alta (8.6) | 0.47% | 💥 PoC | Hikvision Hikcentral ProfessionalAI | 29/8/2025 | 17/6/2026 | There is an Access Control Vulnerability in some HikCentral Professional versions. This could allow an unauthenticated user to obtain the admin permission. | |
| Aplazada | Media (5.3) | 0.33% | — | Hikvision Hikcentral FocsignAI | 29/8/2025 | 17/6/2026 | There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.7) | 0.35% | — | Hikvision Hikcentral Master LiteAI | 29/8/2025 | 17/6/2026 | There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data. | |
| Aplazada | Crítica (9.8) | 0.71% | 💥 PoC | Ringcentral CommunicationsAI | 28/8/2025 | 17/6/2026 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes. | |
| Analizada | Alta (8.3) | 0.28% | — | N-able N-central | 21/8/2025 | 17/6/2026 | On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2. | |
| Aplazada | Crítica (9.3) | 0.33% | — | Nutanix Prism CentralAI | 20/8/2025 | 17/6/2026 | Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context. | |
| Analizada | Crítica (9.4) | 3.4% | ⚠ Explotación activa | N-able N-central | 14/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. | |
| Analizada | Crítica (9.4) | 1.9% | ⚠ Explotación activa💥 PoC | N-able N-central | 14/8/2025 | 24/9/2026 | Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. |