Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.71% | — | PostgresqlAIGladinet CentrestackAI | 30/7/2026 | 30/7/2026 | CentreStack before 17.4 contains a SQL injection vulnerability in GladDBFiles.SearchEx() and SearchExUnder() that allows authenticated attackers to execute arbitrary SQL statements by supplying a crafted x-glad-filter request header through the jsondir API endpoint. Attackers can exploit unsanitized interpolation of… | |
| Aplazada | Alta (8.8) | 0.32% | — | Gladinet CentrestackAI | 30/7/2026 | 30/7/2026 | CentreStack before 17.2 contains an authentication bypass vulnerability that allows unauthenticated attackers to read, write, or delete arbitrary account settings by exploiting exposed API endpoints that lack authorization checks. Attackers can generate valid encrypted EntAcctId values using the static shared… | |
| Aplazada | Alta (8.7) | 0.49% | — | Gladinet CentrestackAI | 30/7/2026 | 30/7/2026 | CentreStack before 17.4 contains an XML external entity (XXE) injection vulnerability that allows unauthenticated attackers to exfiltrate arbitrary files by supplying a malicious URL to the SharePoint storage configuration handler. Attackers can send a crafted request to the unauthenticated StorageConfig endpoint… | |
| Aplazada | Alta (8.7) | 0.37% | — | Microsoft WindowsAIGladinet CentrestackAI | 30/7/2026 | 31/7/2026 | CentreStack before 17.3 contains an unauthenticated deserialization vulnerability in GSNamespace.dll that allows unauthenticated attackers to create arbitrary local OS user accounts by supplying a crafted base64-encoded XML string to exposed API endpoints. Attackers can send a malicious StorageConfigure parameter to… | |
| Aplazada | Media (6.9) | 0.43% | — | Gladinet CentrestackAI | 30/7/2026 | 30/7/2026 | CentreStack before 17.4 contains a session variable injection vulnerability that allows unauthenticated attackers to inject arbitrary session variables by embedding newline and tab characters into a crafted AccountName parameter posted to the SelectProvider.aspx endpoint. Attackers can exploit the lack of input… | |
| Aplazada | Crítica (9.3) | 0.69% | — | Gladinet CentrestackAI | 30/7/2026 | 30/7/2026 | CentreStack before 17.5 contains a hardcoded cryptographic key vulnerability that allows unauthenticated attackers to forge arbitrary encrypted tokens by exploiting a static SysNumber value used as entropy for AccessTicket.Encrypt() and AccessTicket.Decrypt() across all installations. Attackers can use the hardcoded… | |
| Analizada | Alta (7.1) | 53% | ⚠ Explotación activa | Gladinet CentrestackGladinet Triofox | 12/12/2025 | 17/6/2026 | Gladinet CentreStack and Triofox prior to version 16.12.10420.56791 used hardcoded values for their implementation of the AES cryptoscheme. This degrades security for public exposed endpoints that may make use of it and may offer arbitrary local file inclusion when provided a specially crafted request without… | |
| Analizada | Alta (7.5) | 92% | ⚠ Explotación activa | Gladinet CentrestackGladinet Triofox | 9/10/2025 | 17/6/2026 | In the default installation and configuration of Gladinet CentreStack and TrioFox, there is an unauthenticated Local File Inclusion Flaw that allows unintended disclosure of system files. Exploitation of this vulnerability has been observed in the wild. This issue impacts Gladinet CentreStack and Triofox: All versions… | |
| Analizada | Crítica (9.8) | 94% | ⚠ Explotación activa | Gladinet Centrestack | 3/4/2025 | 17/6/2026 | Gladinet CentreStack through 16.1.10296.56315 (fixed in 16.4.10315.56368) has a deserialization vulnerability due to the CentreStack portal's hardcoded machineKey use, as exploited in the wild in March 2025. This enables threat actors (who know the machineKey) to serialize a payload for server-side deserialization to… | |
| Aplazada | Media (5.4) | 0.38% | — | Gladinet CentrestackAI | 22/11/2024 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in Gladinet CentreStack v13.12.9934.54690 allows attackers to inject malicious JavaScript into the web browser of a victim via the sessionId parameter at /portal/ForgotPassword.aspx. | |
| Aplazada | Crítica (9.8) | 1.0% | — | Gladinet CentrestackAI | 22/11/2024 | 17/6/2026 | An LDAP injection vulnerability in the login page of Gladinet CentreStack v13.12.9934.54690 allows attackers to access sensitive data or execute arbitrary commands via a crafted payload injected into the username field. | |
| Modificada | Alta (7.2) | 1.1% | — | Gladinet Centrestack | 31/3/2023 | 17/6/2026 | An unrestricted file upload vulnerability in the administrative portal branding component of Gladinet CentreStack before 13.5.9808 allows authenticated attackers to execute arbitrary code by uploading malicious files to the server. | |
| Modificada | Crítica (9.8) | 1.2% | — | Gladinet Centrestack | 31/3/2023 | 17/6/2026 | An authentication bypass vulnerability in the Password Reset component of Gladinet CentreStack before 13.5.9808 allows remote attackers to set a new password for any valid user account, without needing the previous known password, resulting in a full authentication bypass. |