Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
706 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (7.2) | 0.28% | — | Wikimedia CentralauthAI | 30/9/2026 | 30/9/2026 | External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43. | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Wikimedia CentralnoticeAI | 29/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Media (6.1) | 0.15% | — | Wikimedia CentralauthAI | 29/9/2026 | 30/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Alta (7.5) | 0.26% | — | Wikimedia CentralauthAI | 29/9/2026 | 30/9/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: from * before 1.46.1, 1.45.5, 1.43.10. | |
| Pendiente de análisis | Alta (8.8) | 0.88% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations. | |
| Pendiente de análisis | Alta (8.8) | 2.0% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution. | |
| Pendiente de análisis | Alta (8.8) | 7.0% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host. | |
| Pendiente de análisis | Alta (8.8) | 4.7% | — | Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution. | |
| Pendiente de análisis | Alta (7.2) | 3.6% | — | Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution. | |
| Aplazada | Alta (7.1) | 0.29% | — | Hikvision Hikcentral Access ControlAI | 10/9/2026 | 10/9/2026 | There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access. | |
| Pendiente de análisis | Alta (8.4) | 0.10% | — | Waves CentralAI | 8/9/2026 | 14/9/2026 | Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier… | |
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zoho Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component | |
| Pendiente de análisis | Media (5) | 0.29% | — | Zoho Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path. | |
| Pendiente de análisis | Media (6.3) | 0.38% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction | |
| Pendiente de análisis | Media (5.7) | 0.35% | — | Zohocorp Manageengine Endpoint CentralAI | 7/9/2026 | 8/9/2026 | Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade. | |
| Analizada | Crítica (10) | 13% | ⚠ Explotación activa | N-able N-central | 6/9/2026 | 9/9/2026 | N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14. | |
| Pendiente de análisis | Media (6.9) | 1.1% | — | N-centralAI | 5/9/2026 | 8/9/2026 | A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4 | |
| Pendiente de análisis | Alta (7.7) | 1.3% | — | N-able N-centralAI | 5/9/2026 | 8/9/2026 | An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs | |
| Aplazada | Media (5.4) | 0.18% | — | Phpcentral LoginAI | 19/8/2026 | 9/9/2026 | Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level GET request through the TaskServiceProvider task: URI parameter without requiring a login-form nonce, an Origin check, or a Referer check. Under the… | |
| Analizada | Media (6.5) | 0.84% | — | Microsoft Dynamics 365 Business Central 2024Microsoft Dynamics 365 Business Central 2025Microsoft Dynamics 365 Business Central 2026 | 11/8/2026 | 13/8/2026 | Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network. | |
| Pendiente de análisis | Crítica (9.8) | 3.3% | — | Manageengine DDI CentralAI | 11/8/2026 | 31/8/2026 | An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. | |
| Pendiente de análisis | Media (6.8) | 0.34% | — | Stackrox Rhacs CentralAIStackroxAI | 10/8/2026 | 14/8/2026 | A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring… | |
| Analizada | Alta (8.2) | 15% | ⚠ Explotación activa | N-able N-central | 2/8/2026 | 4/8/2026 | An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1 | |
| Analizada | Alta (8.2) | 7.9% | ⚠ Explotación activa | N-able N-central | 1/8/2026 | 5/8/2026 | Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1. | |
| Pendiente de análisis | Alta (8.6) | 0.22% | — | MeshcentralAI | 30/7/2026 | 9/9/2026 | MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed… |