Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.8)0.11%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt3/3/202517/6/2026
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09291294; Issue ID: MSV-2061.
AnalizadaAlta (7.1)0.39%—F5 Big-ip Next Central Manager5/2/202517/6/2026
When BIG-IP Next Central Manager is running, undisclosed requests to the BIG-IP Next Central Manager API can cause the BIG-IP Next Central Manager Node's Kubernetes service to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.7)0.16%—F5 Big-ip Next Central Manager5/2/202517/6/2026
When users log in through the webUI or API using local authentication, BIG-IP Next Central Manager may log sensitive information in the pgaudit log files. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (4.3)0.63%—Zohocorp Manageengine Endpoint Central5/2/202517/6/2026
ManageEngine Endpoint Central versions before 11.3.2440.09 are vulnerable to IDOR vulnerability which allows the attacker to change the username in the chat.
ModificadaMedia (6.6)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt3/2/202517/6/2026
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09403752; Issue ID: MSV-2434.
AnalizadaMedia (6.6)0.11%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt6/1/202517/6/2026
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09290940; Issue ID: MSV-2040.
AnalizadaMedia (6.6)0.11%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt6/1/202517/6/2026
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2041.
AnalizadaMedia (6.6)0.11%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt6/1/202517/6/2026
In V6 DA, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege, if an attacker has physical access to the device, with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09167056; Issue ID: MSV-2069.
AplazadaMedia (5.1)0.29%—Cpci85 Central Processing CommunicationAI10/12/202417/6/2026
A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V05.30). The affected devices contain a secure element which is connected via an unencrypted SPI bus. This could allow an attacker with physical access to the SPI bus to observe the password used for the secure element…
AnalizadaMedia (6.8)1.4%💥 PoCQnap Qsync Central6/12/202417/6/2026
A link following vulnerability has been reported to affect Qsync Central. If exploited, the vulnerability could allow remote attackers who have gained user access to traverse the file system to unintended locations. We have already fixed the vulnerability in the following versions: Qsync Central 4.4.0.16_20240819 (…
AplazadaAlta (7.1)0.16%—Ringcentral CommunicationsAI2/12/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in pbmacintyre RingCentral Communications rccp-free allows Stored XSS.This issue affects RingCentral Communications: from n/a through <= 1.7.0.
AnalizadaMedia (6.2)0.08%—Rdkcentral Rdk-bGoogle AndroidOpenwrt2/12/202417/6/2026
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09121847; Issue ID: MSV-1821.
AplazadaAlta (7.8)0.16%—Primx ZonecentralAI15/11/202417/6/2026
By default, dedicated folders of ZONECENTRAL for Windows up to 2024.3 or up to Q.2021.2 (ANSSI qualification submission) can be accessed by other users to misuse technical files and make them perform tasks with higher privileges. Configuration of ZONECENTRAL has to be modified to prevent this vulnerability.
AnalizadaMedia (5.3)0.62%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability was found in Apereo CAS 6.6. It has been classified as critical. This affects an unknown part of the file /login?service of the component 2FA. The manipulation leads to improper authentication. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.…
AnalizadaMedia (6.3)0.75%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability was found in Apereo CAS 6.6 and classified as problematic. Affected by this issue is some unknown functionality of the file /login?service. The manipulation leads to session expiration. The attack may be launched remotely. The complexity of an attack is rather high. The exploitation is known to be…
AnalizadaMedia (5.3)0.36%—Apereo Central Authentication Service14/11/202417/6/2026
A vulnerability has been found in Apereo CAS 6.6 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /login. The manipulation of the argument redirect_uri leads to open redirect. The attack can be launched remotely. The exploit has been disclosed to the public and may…
AnalizadaAlta (7.8)0.45%—Zohocorp Manageengine Endpoint Central7/11/202417/6/2026
Zohocorp ManageEngine EndPoint Central versions 11.3.2416.21 and below, 11.3.2428.9 and below are vulnerable to Arbitrary File Deletion in the agent installed machines.
AnalizadaMedia (6.2)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/11/202417/6/2026
In da, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS09124360; Issue ID: MSV-1823.
AnalizadaAlta (8.4)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/11/202417/6/2026
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772.
ModificadaAlta (7.2)0.45%—Hikvision Hikcentral Professional18/10/202417/6/2026
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
ModificadaBaja (2.1)0.29%—Hikvision Hikcentral Master18/10/202417/6/2026
There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
ModificadaMedia (5.5)0.55%—Hikvision Hikcentral Master18/10/202417/6/2026
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
AnalizadaMedia (6.3)0.11%—Cisco UCS Central Software16/10/202417/6/2026
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function.…
AnalizadaMedia (4.8)0.58%—F5 Big-iq Centralized Management16/10/202417/6/2026
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not…
AnalizadaMedia (6.8)0.11%—Moxa Mxview ONEMoxa Mxview ONE Central Manager21/9/202417/6/2026
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.