Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2693▼ 77 respecto a la semana anterior
Críticas / altas1446▲ 303 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

706 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.2)0.28%—Wikimedia CentralauthAI30/9/202630/9/2026
External control of system or configuration setting vulnerability in The Wikimedia Foundation MediaWiki CentralAuth extension allows Code Injection. This issue affects MediaWiki CentralAuth extension: 1.46, 1.45, and 1.43.
Pendiente de análisisMedia (6.1)0.15%—Wikimedia CentralnoticeAI29/9/202630/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralNotice extension allows Stored XSS. This issue affects Mediawiki - CentralNotice extension: before 1.46.1, 1.45.5, 1.43.10.
Pendiente de análisisMedia (6.1)0.15%—Wikimedia CentralauthAI29/9/202630/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in The Wikimedia Foundation Mediawiki - CentralAuth extension allows Stored XSS. This issue affects Mediawiki - CentralAuth extension: before 1.46.1, 1.45.5, 1.43.10.
Pendiente de análisisAlta (7.5)0.26%—Wikimedia CentralauthAI29/9/202630/9/2026
Exposure of Sensitive Information to an Unauthorized Actor vulnerability in Wikimedia Foundation Mediawiki - CentralAuth Extension allows Excavation. This issue affects Mediawiki - CentralAuth Extension: from * before 1.46.1, 1.45.5, 1.43.10.
Pendiente de análisisAlta (8.8)0.88%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations.
Pendiente de análisisAlta (8.8)2.0%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution.
Pendiente de análisisAlta (8.8)7.0%—Zohocorp Manageengine DDI CentralAI28/9/202629/9/2026
Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host.
Pendiente de análisisAlta (8.8)4.7%—Manageengine DDI CentralAI28/9/202629/9/2026
ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution.
Pendiente de análisisAlta (7.2)3.6%—Manageengine DDI CentralAI28/9/202629/9/2026
ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution.
AplazadaAlta (7.1)0.29%—Hikvision Hikcentral Access ControlAI10/9/202610/9/2026
There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access.
Pendiente de análisisAlta (8.4)0.10%—Waves CentralAI8/9/202614/9/2026
Waves Central for macOS contains a local privilege escalation in the privileged helper service. The helper authorizes connecting XPC clients by comparing the caller's code-signing certificate chain for equality with its own, rather than validating the caller against a pinned code requirement (application identifier…
Pendiente de análisisMedia (6.3)0.38%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2600.15 are vulnerable to Privilege Escalation Due to Outdated Component
Pendiente de análisisMedia (5)0.29%—Zoho Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.5.2605.01 are vulnerable to Local privilege escalation due to loading a dll from an untrusted path.
Pendiente de análisisMedia (6.3)0.38%—Zohocorp Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions below 11.4.2540.23 are vulnerable to Privilege Escalation During JAR Extraction
Pendiente de análisisMedia (5.7)0.35%—Zohocorp Manageengine Endpoint CentralAI7/9/20268/9/2026
Zohocorp ManageEngine Endpoint Central versions before 11.5.2605.01 are vulnerable to local privilege escalation due to Agent upgrade.
AnalizadaCrítica (10)13%⚠ Explotación activaN-able N-central6/9/20269/9/2026
N-central is vulnerable to a pre-auth remote code execution This issue affects N-central: before 2026.3.1.14.
Pendiente de análisisMedia (6.9)1.1%—N-centralAI5/9/20268/9/2026
A vulnerability in the N-central internal API access control filter allows unauthorised access to internal APIs. This is fixed in N-central 2026.3 HF3 and 2026.4
Pendiente de análisisAlta (7.7)1.3%—N-able N-centralAI5/9/20268/9/2026
An authentication bypass in N-central < 2026.3 HF 3 leads to authentication bypass in internal only APIs
AplazadaMedia (5.4)0.18%—Phpcentral LoginAI19/8/20269/9/2026
Grav Login Plugin adds login, basic ACL, and session wide messages to Grav. Prior to 3.8.11, the Grav Login plugin login.regenerate2FASecret task accepts a top-level GET request through the TaskServiceProvider task: URI parameter without requiring a login-form nonce, an Origin check, or a Referer check. Under the…
AnalizadaMedia (6.5)0.84%—Microsoft Dynamics 365 Business Central 2024Microsoft Dynamics 365 Business Central 2025Microsoft Dynamics 365 Business Central 202611/8/202613/8/2026
Missing authorization in Dynamics Business Central allows an authorized attacker to disclose information over a network.
Pendiente de análisisCrítica (9.8)3.3%—Manageengine DDI CentralAI11/8/202631/8/2026
An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover.
Pendiente de análisisMedia (6.8)0.34%—Stackrox Rhacs CentralAIStackroxAI10/8/202614/8/2026
A flaw was found in StackRox/RHACS Central's Auth Machine-to-Machine (M2M) token exchange. When an administrator configures M2M role mappings, the system uses unanchored regular expressions for matching claim values. This allows an attacker with a valid OpenID Connect (OIDC) token, whose claim value is a superstring…
AnalizadaAlta (8.2)15%⚠ Explotación activaN-able N-central2/8/20264/8/2026
An incomplete patch for CVE-2026-18556 allows for authentication bypass and account takeover in N-central Versions through 2026.3.1
AnalizadaAlta (8.2)7.9%⚠ Explotación activaN-able N-central1/8/20265/8/2026
Authentication bypass using an alternate path or channel vulnerability in N-able N-central allows Authentication Bypass. This issue affects N-central: through 2026.1.
Pendiente de análisisAlta (8.6)0.22%—MeshcentralAI30/7/20269/9/2026
MeshCentral 1.1.21 contains a cross-site WebSocket hijacking protection bypass vulnerability that allows unauthenticated remote attackers to hijack authenticated administrator sessions by exploiting an unconditional early return in the CheckWebServerOriginName() function within webserver.js when self-signed…