Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
746 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.33% | — | Hikvision Hikcentral FocsignAI | 29/8/2025 | 17/6/2026 | There is an Unquoted Service Path Vulnerability in some HikCentral FocSign versions. This could allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.7) | 0.35% | — | Hikvision Hikcentral Master LiteAI | 29/8/2025 | 17/6/2026 | There is a CSV Injection Vulnerability in some HikCentral Master Lite versions. This could allow an attacker to inject executable commands via malicious CSV data. | |
| Aplazada | Crítica (9.8) | 0.71% | 💥 PoC | Ringcentral CommunicationsAI | 28/8/2025 | 17/6/2026 | The RingCentral Communications plugin for WordPress is vulnerable to Authentication Bypass due to improper validation within the ringcentral_admin_login_2fa_verify() function in versions 1.5 to 1.6.8. This makes it possible for unauthenticated attackers to log in as any user simply by supplying identical bogus codes. | |
| Analizada | Alta (8.3) | 0.28% | — | N-able N-central | 21/8/2025 | 17/6/2026 | On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2. | |
| Aplazada | Crítica (9.3) | 0.33% | — | Nutanix Prism CentralAI | 20/8/2025 | 17/6/2026 | Prism Central versions prior to 2024.3.1 are vulnerable to a stored cross-site scripting attack via the Events component, allowing an attacker to hijack a victim user’s session and perform actions in their security context. | |
| Analizada | Crítica (9.4) | 3.4% | ⚠ Explotación activa | N-able N-central | 14/8/2025 | 17/6/2026 | Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1. | |
| Analizada | Crítica (9.4) | 1.9% | ⚠ Explotación activa💥 PoC | N-able N-central | 14/8/2025 | 24/9/2026 | Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1. | |
| Analizada | Media (6.9) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+22 | 13/8/2025 | 17/6/2026 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (6.8) | 0.12% | — | Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt+1 | 4/8/2025 | 17/6/2026 | In DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09915215; Issue ID: MSV-3801. | |
| Aplazada | Crítica (10) | 2.9% | 💥 Exploit | Riverbed Steelcentral NetprofilerAIRiverbed Steelcentral NetexpressAI | 15/7/2025 | 17/6/2026 | An authenticated multi-stage remote code execution vulnerability exists in Riverbed SteelCentral NetProfiler and NetExpress 10.8.7 virtual appliances. A SQL injection vulnerability in the '/api/common/1.0/login' endpoint can be exploited to create a new user account in the appliance database. This user can then… | |
| Aplazada | Alta (8.8) | 0.45% | — | Wikimedia Mediawiki Centralauth ExtensionAI | 3/7/2025 | 17/6/2026 | Improper Authentication vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows : Bypass Authentication.This issue affects Mediawiki - CentralAuth Extension: from 1.39.X before 1.39.13, from 1.42.X before 1.42.7, from 1.43.X before 1.43.2. | |
| Analizada | Alta (7.1) | 0.30% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (SaaS) could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. Please note: this vulnerability only affects the SaaS instance of Apex Central - customers that automatically apply… | |
| Analizada | Alta (7.5) | 0.36% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modOSCE component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. | |
| Analizada | Alta (7.5) | 0.36% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Server-side Request Forgery (SSRF) vulnerability in Trend Micro Apex Central (on-premise) modTMSM component could allow an attacker to manipulate certain parameters leading to information disclosure on affected installations. | |
| Analizada | Crítica (9.8) | 2.1% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in Trend Micro Apex Central below version 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49219 but is in a different method. | |
| Analizada | Crítica (9.8) | 1.4% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An insecure deserialization operation in Trend Micro Apex Central below versions 8.0.7007 could lead to a pre-authentication remote code execution on affected installations. Note that this vulnerability is similar to CVE-2025-49220 but is in a different method. | |
| Analizada | Crítica (9.8) | 1.9% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget in versions below 8.0.6955 could allow an attacker to include arbitrary files to execute as PHP code and lead to remote code execution on affected installations. | |
| Analizada | Alta (7.5) | 0.30% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | An unrestricted file upload vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to upload arbitrary files on affected installations. | |
| Analizada | Crítica (9.8) | 1.8% | — | Trendmicro Apex Central | 17/6/2025 | 17/6/2026 | A Local File Inclusion vulnerability in a Trend Micro Apex Central widget below version 8.0.6955 could allow an attacker to gain remote code execution on affected installations. | |
| Analizada | Alta (8.7) | 0.47% | — | Qnap Qsync Central | 6/6/2025 | 17/6/2026 | An SQL injection vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to execute unauthorized code or commands. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6 ( 2025/03/20 ) and later | |
| Analizada | Baja (2.3) | 0.36% | — | Qnap Qsync Central | 6/6/2025 | 17/6/2026 | A use of externally-controlled format string vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to obtain secret data or modify memory. We have already fixed the vulnerability in the following version: Qsync Central 4.5.0.6… | |
| Analizada | Alta (8.7) | 0.43% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+20 | 7/5/2025 | 17/6/2026 | When a Stream Control Transmission Protocol (SCTP) profile is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.44% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+20 | 7/5/2025 | 17/6/2026 | When a BIG-IP HTTP/2 httprouter profile is configured on a virtual server, undisclosed responses can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Media (5.3) | 0.64% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6. It has been declared as problematic. This vulnerability affects unknown code of the file cas-5.2.6\core\cas-server-core-configuration-metadata-repository\src\main\java\org\apereo\cas\metadata\rest\CasConfigurationMetadataServerController.java. The manipulation of the… | |
| Analizada | Media (5.1) | 0.62% | — | Apereo Central Authentication Service | 27/4/2025 | 17/6/2026 | A vulnerability was found in Apereo CAS 5.2.6. It has been classified as problematic. This affects the function ResponseEntity of the file cas-5.2.6\webapp-mgmt\cas-management-webapp-support\src\main\java\org\apereo\cas\mgmt\services\web\ManageRegisteredServicesMultiActionController.java. The manipulation of the… |