Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1340▲ 76 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
60 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.5) | 0.20% | — | Genetec Security CenterAI | 24/9/2026 | 24/9/2026 | A flaw in the authorization mechanism for Media Gateway API in Genetec Security Center may allow a user with no playback privileges to generate video thumbnails. | |
| Analizada | Crítica (9.4) | 2.8% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A command injection vulnerability exists in Security Center where a remote, unauthenticated attacker could exploit this issue to execute arbitrary commands on the underlying operating system with the privileges of the service account. | |
| Analizada | Crítica (9.4) | 9.9% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | An authenticated command injection vulnerability exists in Security Center related to file upload processing. An attacker could exploit this issue by uploading a specially crafted file, potentially resulting in arbitrary command execution on the underlying operating system. | |
| Analizada | Alta (7.1) | 0.32% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A SQL injection vulnerability exists in Security Center that could allow an attacker to access unauthorized data from the application's database. | |
| Analizada | Alta (8.7) | 1.6% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | An input validation vulnerability exists in Security Center's file upload handling, where insufficient sanitization of uploaded filenames could contribute to a downstream command injection issue. | |
| Analizada | Media (5.3) | 0.30% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | An improper access control vulnerability exists where an authenticated non-administrative application user could potentially view settings outside of their assigned scope. | |
| Analizada | Media (6) | 0.26% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | An issue was identified in which CSRF tokens were generated using a predictable method, potentially reducing their effectiveness as a security control. This has been addressed by improving the randomness and entropy of token generation. | |
| Analizada | Alta (8.5) | 0.19% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A local privilege escalation vulnerability exists in Security Center. An attacker with write access to a specific configuration file could achieve arbitrary code execution with elevated privileges, without requiring further user or victim interaction. | |
| Analizada | Media (6.9) | 0.39% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A SQL injection vulnerability exists in Security Center that could allow an authenticated administrator to execute arbitrary SQL queries, potentially resulting in unauthorized access to sensitive data, including credentials. | |
| Analizada | Alta (8.6) | 0.39% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A privilege escalation vulnerability exists in Tenable Security Center that allows a user with "Security Manager" role and "manage user" permission on a single group to modify users belonging to other groups. This bypasses the intended access control restrictions and enables unauthorized cross-group user management. | |
| Analizada | Alta (8.6) | 2.1% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A command injection vulnerability exists in Tenable Security Center. An authenticated administrator could modify application configuration values to achieve arbitrary command execution on the underlying operating system when specific backend operations are triggered. | |
| Analizada | Crítica (9.4) | 1.9% | — | Tenable Security Center | 14/8/2026 | 19/8/2026 | A remote code execution vulnerability exists in Tenable Security Center's report generation functionality. An authenticated, non-administrative user could exploit this issue by supplying specially crafted input that is later processed unsafely during server-side report rendering, resulting in arbitrary code execution… | |
| Analizada | Alta (8.7) | 2.2% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | The audit file upload handler does not sanitize filenames, allowing shell metacharacters to flow into system command execution. This input validation failure enables command injection when chained with a related vulnerability. | |
| Analizada | Alta (7.1) | 0.32% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | Unsanitized user-supplied input in report filtering parameters is concatenated directly into SQL queries without proper escaping or parameterized queries, enabling blind SQL injection and unauthorized database read access. | |
| Analizada | Crítica (9.4) | 2.3% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | A filename supplied during file upload is not properly sanitized before being used in system command execution, allowing an attacker to inject shell metacharacters and achieve command injection via the audit file upload functionality. | |
| Analizada | Crítica (9.4) | 0.80% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | Unvalidated input in asset filter parameters allows shell metacharacters to escape command argument handling, resulting in remote code execution as a low-privileged OS user via the Analysis REST endpoint. | |
| Analizada | Crítica (9.4) | 0.32% | — | Tenable Security Center | 21/7/2026 | 18/8/2026 | An authenticated non-admin user can exploit a SQL injection flaw in the ticketing REST API to access sensitive data stored in the appliance database. | |
| Pendiente de análisis | Alta (7.5) | 0.50% | — | Genetec Security CenterAI | 6/7/2026 | 7/7/2026 | A flaw in the authentication mechanism for video stream requests in Genetec Security Center 5.14.0.0 prior to build 5.14.178.18 may allow an unauthenticated attacker to access live video streams. | |
| Pendiente de análisis | Alta (7.8) | 0.15% | — | Genetec Security CenterAI | 2/6/2026 | 22/7/2026 | A high security vulnerability affecting Security Center main server installations has been identified. It could allow an attacker with local OS privileges to the main server to access the Server Admin credentials. A third party hired by Genetec found the issue. There is currently no evidence of active exploitation.… | |
| Analizada | Media (5.7) | 0.37% | — | Tenable Security Center | 23/2/2026 | 17/6/2026 | An improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. | |
| Analizada | Baja (2.1) | 0.38% | — | Tenable Security Center | 23/2/2026 | 17/6/2026 | An Indirect Object Reference (IDOR) in Security Center allows an authenticated remote attacker to escalate privileges via the 'owner' parameter. | |
| Aplazada | Alta (7.4) | 1.7% | — | Tenable Security CenterAI | 17/2/2026 | 17/6/2026 | A Command Injection vulnerability exists where an authenticated, remote attacker could execute arbitrary code on the underlying server where Tenable Security Center is hosted. | |
| Aplazada | Crítica (9.8) | 0.36% | — | Genetec Security CenterAI | 30/10/2025 | 17/6/2026 | A critical severity vulnerability has been identified in the ALPR Manager role of Security Center that could allow attackers to gain administrative access to the Genetec Security Center system. The Genetec engineering team discovered this issue internally. There is currently no evidence that this vulnerability has… | |
| Aplazada | Media (4.3) | 0.19% | — | Tenable Security CenterAI | 8/10/2025 | 30/9/2026 | In Tenable Security Center versions prior to 6.7.0, an improper access control vulnerability exists where an authenticated user could access areas outside of their authorized scope. | |
| Aplazada | Baja (2.7) | 0.18% | — | Tenable Security CenterAI | 9/12/2024 | 17/6/2026 | An Improper Certificate Validation vulnerability exists in Tenable Security Center where an authenticated, privileged attacker could intercept email messages sent from Security Center via a rogue SMTP server. |