CVE-2025-11367
- EPSS 0.94%
- Veröffentlicht 12.11.2025 15:34:54
- Zuletzt bearbeitet 14.11.2025 19:31:50
The N-central Software Probe < 2025.4 is vulnerable to Remote Code Execution via deserialization
CVE-2025-11366
- EPSS 0.18%
- Veröffentlicht 12.11.2025 15:33:25
- Zuletzt bearbeitet 14.11.2025 19:32:19
N-central < 2025.4 is vulnerable to authentication bypass via path traversal
CVE-2025-11700
- EPSS 52.71%
- Veröffentlicht 12.11.2025 15:30:38
- Zuletzt bearbeitet 15.12.2025 15:15:47
N-central versions < 2025.4 are vulnerable to multiple XML External Entities injection leading to information disclosure
CVE-2025-9316
- EPSS 81.35%
- Veröffentlicht 12.11.2025 15:27:25
- Zuletzt bearbeitet 12.11.2025 16:19:12
N-central < 2025.4 can generate sessionIDs for unauthenticated users This issue affects N-central: before 2025.4.
CVE-2025-10231
- EPSS 0.01%
- Veröffentlicht 10.09.2025 13:34:41
- Zuletzt bearbeitet 22.09.2025 18:25:11
An Incorrect File Handling Permission bug exists on the N-central Windows Agent and Probe that, in the right circumstances, can allow a local low-level user to run commands with elevated permissions.
CVE-2025-7051
- EPSS 0.05%
- Veröffentlicht 21.08.2025 17:34:31
- Zuletzt bearbeitet 08.09.2025 16:15:50
On N-central, it is possible for any authenticated user to read, write and modify syslog configuration across customers on an N-central server. This vulnerability is present in all deployments of N-central prior to 2025.2.
CVE-2025-8875
- EPSS 2.61%
- Veröffentlicht 14.08.2025 14:56:11
- Zuletzt bearbeitet 27.10.2025 14:58:50
Deserialization of Untrusted Data vulnerability in N-able N-central allows Local Execution of Code.This issue affects N-central: before 2025.3.1.
CVE-2025-8876
- EPSS 7.85%
- Veröffentlicht 14.08.2025 14:53:55
- Zuletzt bearbeitet 27.10.2025 14:58:04
Improper Input Validation vulnerability in N-able N-central allows OS Command Injection.This issue affects N-central: before 2025.3.1.
CVE-2024-8510
- EPSS 0.2%
- Veröffentlicht 17.03.2025 19:01:36
- Zuletzt bearbeitet 05.09.2025 17:15:48
N-central is vulnerable to a path traversal that allows unintended access to the Apache Tomcat WEB-INF directory. Customer data is not exposed. This vulnerability is present in all deployments of N-central prior to N-central 2024.6.
CVE-2024-5322
- EPSS 0.11%
- Veröffentlicht 01.07.2024 21:15:04
- Zuletzt bearbeitet 08.09.2025 16:17:52
The N-central server is vulnerable to session rebinding of already authenticated users when using Entra SSO, which can lead to authentication bypass. This vulnerability is present in all Entra-supported deployments of N-central prior to 2024.3.