Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

746 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.4)0.09%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt4/11/202417/6/2026
In da, there is a possible out of bounds write due to a missing bounds check. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is needed for exploitation. Patch ID: ALPS09073261; Issue ID: MSV-1772.
ModificadaAlta (7.2)0.45%—Hikvision Hikcentral Professional18/10/202417/6/2026
There is a SQL injection vulnerability in some HikCentral Professional versions. This could allow an authenticated user to execute arbitrary SQL queries.
ModificadaBaja (2.1)0.29%—Hikvision Hikcentral Master18/10/202417/6/2026
There is an XSS vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could inject scripts into certain pages by building malicious data.
ModificadaMedia (5.5)0.55%—Hikvision Hikcentral Master18/10/202417/6/2026
There is a CSV injection vulnerability in some HikCentral Master Lite versions. If exploited, an attacker could build malicious data to generate executable commands in the CSV file.
AnalizadaMedia (6.3)0.11%—Cisco UCS Central Software16/10/202417/6/2026
A vulnerability in the backup feature of Cisco UCS Central Software could allow an attacker with access to a backup file to learn sensitive information that is stored in the full state and configuration backup files. This vulnerability is due to a weakness in the encryption method that is used for the backup function.…
AnalizadaMedia (4.8)0.58%—F5 Big-iq Centralized Management16/10/202417/6/2026
A stored cross-site scripting (XSS) vulnerability exists in an undisclosed page of the BIG-IQ Configuration utility that allows an attacker with the Administrator role to run JavaScript in the context of the currently logged-in user. Note: Software versions which have reached End of Technical Support (EoTS) are not…
AnalizadaMedia (6.8)0.11%—Moxa Mxview ONEMoxa Mxview ONE Central Manager21/9/202417/6/2026
The configuration file stores credentials in cleartext. An attacker with local access rights can read or modify the configuration file, potentially resulting in the service being abused due to sensitive information exposure.
AnalizadaAlta (8.8)0.71%—Microsoft Dynamics 365 Business Central17/9/202410/8/2026
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)1.4%—Microsoft Dynamics 365 Business Central10/9/202410/8/2026
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
AnalizadaAlta (7.5)0.31%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle Android2/9/202417/6/2026
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.
ModificadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt2/9/202417/6/2026
In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944204; Issue ID: MSV-1560.
ModificadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt2/9/202417/6/2026
In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944210; Issue ID: MSV-1561.
AnalizadaAlta (8.3)0.80%—Zohocorp Manageengine Endpoint Central30/8/202417/6/2026
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
AplazadaAlta (7.5)14%💥 ExploitCentralsquare CrywolfAI26/8/202417/6/2026
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
AnalizadaAlta (8.8)7.0%—Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSPZohocorp Manageengine Opmanager PlusZohocorp Manageengine Remote Monitoring AND Management Central23/8/202417/6/2026
Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
AnalizadaMedia (5.1)0.15%—F5 Big-ip Next Central Manager14/8/202417/6/2026
When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.9)0.44%—F5 Big-ip Next Central Manager14/8/202417/6/2026
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaMedia (6.3)0.45%—F5 Big-ip Next Central Manager14/8/202417/6/2026
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaAlta (7.5)0.39%—Skteco Central Control Attendance MachineAI26/7/202417/6/2026
An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component.
ModificadaCrítica (9.8)2.5%—Zohocorp Manageengine DDI Central17/7/202417/6/2026
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.
ModificadaAlta (8.8)1.5%—Zohocorp Manageengine DDI Central17/7/202417/6/2026
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.
ModificadaMedia (6.5)0.73%—Stonefly Storage Concentrator12/7/202417/6/2026
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows Directory Traversal by authenticated users. Using a crafted path parameter with the Online Help facility can expose sensitive system information.
AplazadaAlta (8.8)1.3%—Stonefly Storage ConcentratorAI12/7/202417/6/2026
StoneFly Storage Concentrator (SC and SCVM) before 8.0.4.26 allows remote authenticated users to achieve Command Injection via a Ping URL, leading to remote code execution.
AnalizadaCrítica (9.1)0.41%—N-able N-central1/7/202417/6/2026
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
ModificadaCrítica (9.8)1.9%💥 ExploitN-able N-central1/7/202417/6/2026
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.