Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.8)0.71%—Microsoft Dynamics 365 Business Central17/9/202410/8/2026
Improper authorization in Dynamics 365 Business Central resulted in a vulnerability that allows an authenticated attacker to elevate privileges over a network.
AnalizadaCrítica (9.8)1.4%—Microsoft Dynamics 365 Business Central10/9/202410/8/2026
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
AnalizadaAlta (7.5)0.31%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle Android2/9/202417/6/2026
In wlan, there is a possible denial of service due to incorrect error handling. This could lead to remote denial of service with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08861558; Issue ID: MSV-1526.
ModificadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt2/9/202417/6/2026
In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944204; Issue ID: MSV-1560.
ModificadaMedia (4.4)0.10%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt2/9/202417/6/2026
In power, there is a possible out of bounds read due to a missing bounds check. This could lead to local information disclosure with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08944210; Issue ID: MSV-1561.
AnalizadaAlta (8.3)0.80%—Zohocorp Manageengine Endpoint Central30/8/202417/6/2026
Zohocorp ManageEngine Endpoint Central affected by Incorrect authorization vulnerability while isolating the devices.This issue affects Endpoint Central: before 11.3.2406.08 and before 11.3.2400.15
AplazadaAlta (7.5)14%💥 ExploitCentralsquare CrywolfAI26/8/202417/6/2026
A traversal vulnerability in GeneralDocs.aspx in CentralSquare CryWolf (False Alarm Management) through 2024-08-09 allows unauthenticated attackers to read files outside of the working web directory via the rpt parameter, leading to the disclosure of sensitive information.
AnalizadaAlta (8.8)7.0%—Zohocorp Manageengine OpmanagerZohocorp Manageengine Opmanager MSPZohocorp Manageengine Opmanager PlusZohocorp Manageengine Remote Monitoring AND Management Central23/8/202417/6/2026
Zohocorp ManageEngine OpManager and Remote Monitoring and Management versions 128329 and below are vulnerable to the authenticated remote code execution in the deploy agent option.
AnalizadaMedia (5.1)0.15%—F5 Big-ip Next Central Manager14/8/202417/6/2026
When generating QKView of BIG-IP Next instance from the BIG-IP Next Central Manager (CM), F5 iHealth credentials will be logged in the BIG-IP Central Manager logs. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (8.9)0.44%—F5 Big-ip Next Central Manager14/8/202417/6/2026
The Central Manager user session refresh token does not expire when a user logs out. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated
AnalizadaMedia (6.3)0.45%—F5 Big-ip Next Central Manager14/8/202417/6/2026
BIG-IP Next Central Manager may allow an attacker to lock out an account that has never been logged in. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaAlta (7.5)0.39%—Skteco Central Control Attendance MachineAI26/7/202417/6/2026
An issue in skteco.com Central Control Attendance Machine web management platform v.3.0 allows an attacker to obtain sensitive information via a crafted script to the csl/user component.
ModificadaCrítica (9.8)2.5%—Zohocorp Manageengine DDI Central17/7/202417/6/2026
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys.
ModificadaAlta (8.8)1.5%—Zohocorp Manageengine DDI Central17/7/202417/6/2026
Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder.
AnalizadaCrítica (9.1)0.41%—N-able N-central1/7/202417/6/2026
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.
ModificadaCrítica (9.8)1.9%💥 ExploitN-able N-central1/7/202417/6/2026
The N-central server is vulnerable to an authentication bypass of the user interface. This vulnerability is present in all deployments of N-central prior to 2024.2. This vulnerability was discovered through internal N-central source code review and N-able has not observed any exploitation in the wild.
ModificadaMedia (6.7)0.22%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle AndroidOpenwrt1/7/202417/6/2026
In gnss service, there is a possible out of bounds write due to improper input validation. This could lead to local escalation of privilege with System execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08719602; Issue ID: MSV-1412.
AnalizadaCrítica (9.8)0.29%—Linuxfoundation YoctoRdkcentral Rdk-bGoogle Android1/7/202417/6/2026
In gnss service, there is a possible escalation of privilege due to improper certificate validation. This could lead to remote escalation of privilege with no additional execution privileges needed. User interaction is not needed for exploitation. Patch ID: ALPS08720039; Issue ID: MSV-1424.
AplazadaMedia (4.3)0.21%—Decentralizejustice AnonymouslockerAIDecentralizejustice AnonbackendAI13/6/202417/6/2026
An issue in Annonshop.app DecentralizeJustice/anonymousLocker commit 2b2b4 to ba9fd and DecentralizeJustice/anonBackend commit 57837 to cd815 was discovered to store credentials in plaintext.
AplazadaMedia (6.5)0.39%—Annonshop APPAIDecentralizejustice AnonymouslockerAI13/6/202417/6/2026
An issue in Annonshop.app DecentralizeJustice/ anonymousLocker commit 2b2b4 allows attackers to send messages erroneously attributed to arbitrary users via a crafted HTTP request.
ModificadaAlta (8.8)3.4%—Microsoft Dynamics 365 Business Central11/6/202410/8/2026
Microsoft Dynamics 365 Business Central Remote Code Execution Vulnerability
ModificadaAlta (7.3)0.95%—Microsoft Dynamics 365 Business Central11/6/202421/7/2026
Microsoft Dynamics 365 Business Central Elevation of Privilege Vulnerability
AnalizadaCrítica (9.1)1.8%💥 ExploitApereo Central Authentication Service23/5/202417/6/2026
The does not validate a parameter before making a request to it, which could allow unauthenticated users to perform SSRF attack
AnalizadaMedia (6.8)0.23%—F5 Big-ip Next Central Manager8/5/202417/6/2026
An improper certificate validation vulnerability exists in BIG-IP Next Central Manager and may allow an attacker to impersonate an Instance Provider system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaAlta (7.4)0.55%—F5 Big-ip Next Central Manager8/5/202417/6/2026
BIG-IP Next Central Manager (CM) may allow an unauthenticated, remote attacker to obtain the BIG-IP Next LTM/WAF instance credentials. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
Orbitaley — Vulnerabilidades