Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.88% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Insufficient access control in HA failover endpoint leading to destructive PostgreSQL database operations. | |
| Pendiente de análisis | Alta (8.8) | 2.0% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central versions before 6201 are vulnerable to Arbitrary file write via HA Failover Config sync upload leading to remote code execution. | |
| Pendiente de análisis | Alta (8.8) | 7.0% | — | Zohocorp Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | Zohocorp ManageEngine DDI Central 6.2.0 build below 6201 had a Keepalived configuration injection vulnerability in the HA configuration workflow. This issue could allow an authenticated operator-level user to modify the Keepalived configuration and potentially execute commands as root on the DDI Central host. | |
| Pendiente de análisis | Alta (8.8) | 4.7% | — | Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | ManageEngine DDI Central versions below 6201 are vulnerable to PowerShell command injection in Windows DNS SPF/TXT record push leading to remote code execution. | |
| Pendiente de análisis | Alta (7.2) | 3.6% | — | Manageengine DDI CentralAI | 28/9/2026 | 29/9/2026 | ManageEngine DDI Central versions below 6201 are vulnerable to Command injection in Windows DNS Query Resolution Policy name field leading to remote code execution. | |
| Pendiente de análisis | Crítica (9.8) | 3.3% | — | Manageengine DDI CentralAI | 11/8/2026 | 31/8/2026 | An authentication bypass in ManageEngine DDI Central's password-reset workflow allows account takeover. | |
| Modificada | Crítica (9.8) | 2.5% | — | Zohocorp Manageengine DDI Central | 17/7/2024 | 17/6/2026 | Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to agent takeover vulnerability due to the hard-coded sensitive keys. | |
| Modificada | Alta (8.8) | 1.5% | — | Zohocorp Manageengine DDI Central | 17/7/2024 | 17/6/2026 | Zohocorp ManageEngine DDI Central versions 4001 and prior were vulnerable to directory traversal vulnerability which allows the user to upload new files to the server folder. |