Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 554 respecto a la semana anterior
Críticas / altas1325▼ 178 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 242 respecto a la semana anterior
4319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.2) | 6.5% | 💥 PoC | F5 DOSF5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance Manager+7 | 17/6/2026 | 14/9/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_proxy_v2_module and ngx_http_grpc_module modules. This vulnerability exists when the proxy_http_version to 2 or grpc_pass directives are used to proxy HTTP/2 traffic, the ignore_invalid_headers directive is set to off, and the… | |
| Aplazada | Media (6.5) | 0.44% | — | Control Panel Client Portal PROAI | 17/6/2026 | 17/6/2026 | CP Client Arbitrary File Download in Client Portal (Pro) <= 5.6.2 versions. | |
| Analizada | Media (5.3) | 0.20% | — | Hcltech Icontrol | 17/6/2026 | 6/10/2026 | HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity | |
| Aplazada | Media (6.3) | 0.26% | — | Subscriber Broken Access Control IN Classified ListingAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Access Control in Classified Listing <= 5.3.9 versions. | |
| Aplazada | Crítica (9.8) | 0.48% | — | IcontrolwpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. | |
| Aplazada | Alta (7.5) | 0.37% | — | Unauthenticated Broken Access Control IN User RegistrationAI | 15/6/2026 | 17/6/2026 | Unauthenticated Broken Access Control in User Registration <= 5.1.2 versions. | |
| Aplazada | Media (6.9) | 0.43% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, does not sufficiently validate the branch code when a new branch is created. The branch code is later used in multiple application functions, including filesystem path generation for uploaded files, profile pictures, and settings. An authenticated… | |
| Aplazada | Media (6.8) | 0.14% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a hard-coded cryptographic key in the SafeSystem.Infrastructure.Security.dll component. An attacker with access to the application files can reverse engineer the DLL and recover the hard-coded cryptographic key. This key can be used to… | |
| Aplazada | Media (6.9) | 0.47% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, exposes web-accessible file paths that are not protected by an authorization scheme. An unauthenticated attacker can directly access HTTP endpoints to download files from locations such as /Resources/CompanyId_[ID]/Audio/ and /SafeData/. | |
| Aplazada | Media (5.3) | 0.40% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains insufficient server-side file type validation in the /safe/contract/uploadcustomdocuments endpoint. The application validates uploaded files based on the user-controlled HTTP Content-Type value and accepts the upload if this value contains… | |
| Aplazada | Alta (7.1) | 0.45% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains a path traversal vulnerability in the documentName parameter of the /safe/selfservice/openselfservicedocument endpoint. The application constructs a file path using attacker-controlled input without sufficient validation, allowing an… | |
| Aplazada | Media (5.3) | 0.39% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an IP restriction bypass vulnerability in the login process. The application restricts user logins based on the IP address associated with a branch location, but the client IP address is derived from the HTTP X-Forwarded-For header when… | |
| Aplazada | Alta (8.6) | 0.40% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains missing authorization checks on multiple web application endpoints. An authenticated attacker with minimal privileges can access endpoints that are not visible in the frontend but remain directly reachable. This allows the attacker to… | |
| Aplazada | Alta (7.1) | 0.45% | — | Wertheim Safecontroller SoftwareAI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Software, AssemblyVersion 6.15.8328.28014, contains an incorrect authorization vulnerability in the WebSocket communication used by the SafeController WebMessageBroker. An authenticated attacker with valid low-privileged branch user credentials can manipulate WebSocket messages by… | |
| Aplazada | Alta (7.1) | 0.14% | — | Wertheim Safecontroller Family 65000AI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController Family 65000, Controller 65000 - AssemblyVersion 6.11.8130.22319, uses weak custom cryptographic algorithms with hard-coded cryptographic keys to protect communication. An attacker in an adversary-in-the-middle position can decrypt the data traffic. During reassessment, it was possible to… | |
| Aplazada | Alta (8.6) | 0.25% | — | Wertheim Safecontroller 5400AI | 15/6/2026 | 17/6/2026 | The Wertheim SafeController 5400, Controller 5400 - AssemblyVersion 6.11.8130.22320, uses RS-485 communication between the server and the microcontroller without cryptographic protection. An attacker with access to the communication path between the server and the microcontroller can sniff RS-485 messages and replay… | |
| Analizada | Alta (7.8) | 0.11% | — | Zoom Remote Control | 12/6/2026 | 29/6/2026 | Insufficient Verification of Data Authenticity in Remote Control for Zoom Contact Center for Windows before version 7.0.0 may allow an authenticated user to enable an escalation of privilege via local access. | |
| Pendiente de análisis | Alta (8.4) | 0.08% | — | Lenovo Thinkpad Embedded Controller FirmwareAI | 10/6/2026 | 7/10/2026 | During an internal security assessment, a potential vulnerability was discovered in some ThinkPad embedded controller firmware that could allow a privileged local user to perform arbitrary reads or writes to privileged memory regions. | |
| Analizada | Alta (7.1) | 0.17% | — | Ericsson Packet Core Controller | 5/6/2026 | 7/10/2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation. | |
| Analizada | Alta (7.8) | 25% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vsmart Controller | 4/6/2026 | 23/7/2026 | A vulnerability in the CLI of Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an authenticated, local attacker to execute arbitrary commands as root by supplying a crafted file to… | |
| Analizada | Alta (8.8) | 0.20% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . | |
| Analizada | Media (4.3) | 0.16% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems… | |
| Analizada | Media (5.3) | 0.16% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. | |
| Analizada | Media (4.3) | 0.10% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root. | |
| Analizada | Media (4.3) | 0.17% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type. |