Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.3) | 0.22% | — | ABB ANCAIABB Anc-lAIABB Anc-miniAI | 30/4/2025 | 17/6/2026 | : Use of GET Request Method With Sensitive Query Strings vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4. | |
| Aplazada | Alta (8.5) | 0.25% | — | ABB ANCAIABB Anc-lAIABB Anc-miniAI | 30/4/2025 | 17/6/2026 | : Modification of Assumed-Immutable Data (MAID) vulnerability in ABB ANC, ABB ANC-L, ABB ANC-mini.This issue affects ANC: through 1.1.4; ANC-L: through 1.1.4; ANC-mini: through 1.1.4. | |
| Analizada | Alta (8.4) | 0.10% | — | ABB Automation Builder | 30/4/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0. | |
| Analizada | Alta (8.5) | 0.15% | — | ABB Automation Builder | 30/4/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0. | |
| Modificada | Media (6) | 0.35% | — | Zabbix | 2/4/2025 | 17/6/2026 | Zabbix server is vulnerable to a DoS vulnerability due to uncontrolled resource exhaustion. An attacker can send specially crafted requests to the server, which will cause the server to allocate an excessive amount of memory and perform CPU-intensive decompression operations, ultimately leading to a service crash. | |
| Modificada | Alta (7.5) | 0.36% | — | Zabbix | 2/4/2025 | 17/6/2026 | The endpoint /zabbix.php?action=export.valuemaps suffers from a Cross-Site Scripting vulnerability via the backurl parameter. This is caused by the reflection of user-supplied data without appropriate HTML escaping or output encoding. As a result, a JavaScript payload may be injected into the above endpoint causing it… | |
| Modificada | Baja (2.1) | 0.29% | — | Zabbix | 2/4/2025 | 17/6/2026 | Zabbix API user.get returns all users that share common group with the calling user. This includes media and other information, such as login attempts, etc. | |
| Modificada | Baja (2.3) | 0.33% | — | Zabbix | 2/4/2025 | 17/6/2026 | Execution time for an unsuccessful login differs when using a non-existing username compared to using an existing one. | |
| Analizada | Alta (8.6) | 40% | — | Zabbix | 2/4/2025 | 17/6/2026 | A low privilege (regular) Zabbix user with API access can use SQL injection vulnerability in include/classes/api/CApiService.php to execute arbitrary SQL commands via the groupBy parameter. | |
| Aplazada | Media (6.1) | 0.21% | — | RabbitmqAIVmware Tanzu RabbitmqAI | 25/3/2025 | 17/6/2026 | RabbitMQ is a messaging and streaming broker. Versions prior to 4.0.3 are vulnerable to a sophisticated attack that could modify virtual host name on disk and then make it unrecoverable (with other on disk file modifications) can lead to arbitrary JavaScript code execution in the browsers of management UI users. When… | |
| Aplazada | Alta (8.7) | 0.33% | — | ABB Rtu500AI | 25/3/2025 | 17/6/2026 | A vulnerability exists in RTU IEC 61850 client and server functionality that could impact the availability if renegotiation of an open IEC61850 TLS connection takes place in specific timing situations, when IEC61850 communication is active. Precondition is that IEC61850 as client or server are configured using TLS on… | |
| Aplazada | Alta (8.7) | 0.40% | — | ABB Rtu500AI | 25/3/2025 | 17/6/2026 | A vulnerability exists in RTU500 IEC 60870-5-104 controlled station functionality and IEC 61850 functionality, that allows an attacker performing a specific attack sequence to restart the affected CMU. This vulnerability only applies, if secure communication using IEC 62351-3 (TLS) is enabled. | |
| Aplazada | Media (6.9) | 0.24% | — | ABB Rtu500AI | 25/3/2025 | 17/6/2026 | A vulnerability exists in RTU500 IEC 60870-4-104 controlled station functionality, that allows an authenticated and authorized attacker to perform a CMU restart. The vulnerability can be triggered if certificates are updated while in use on active connections. The affected CMU will automatically recover itself if an… | |
| Aplazada | Media (5.9) | 0.34% | — | ABB Rtu500AI | 25/3/2025 | 17/6/2026 | A vulnerability exists in the RTU500 web server component that can cause a denial of service to the RTU500 CMU application if a specially crafted message sequence is executed on a WebSocket connection. An attacker must be properly authenticated and the test mode function of RTU500 must be enabled to exploit this… | |
| Aplazada | Media (6.5) | 0.27% | — | Vivek Marakana Tabbed Login WidgetAI | 11/3/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vivek Marakana Tabbed Login Widget tabbed-login allows Stored XSS.This issue affects Tabbed Login Widget: from n/a through <= 1.1.2. | |
| Analizada | Media (6.5) | 0.11% | — | Qualcomm Aqt1000 FirmwareQualcomm Ar8035 FirmwareQualcomm Fastconnect 6200 FirmwareQualcomm Fastconnect 6700 Firmware+188 | 3/3/2025 | 17/6/2026 | Transient DOS during hypervisor virtual I/O operation in a virtual machine. | |
| Modificada | Media (6.5) | 0.67% | — | Phpjabbers Event Ticketing System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Event Ticketing System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Modificada | Media (5.4) | 0.29% | — | Phpjabbers Meeting Room Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Meeting Room Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters of index.php page. | |
| Modificada | Media (5.4) | 0.35% | — | Phpjabbers Event Ticketing System | 20/2/2025 | 17/6/2026 | PHPJabbers Event Ticketing System v1.0 is vulnerable to Reflected Cross-Site Scripting (XSS) in "lid" parameter in index. | |
| Modificada | Alta (8.8) | 0.64% | — | Phpjabbers Meeting Room Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Meeting Room Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Media (6.5) | 0.44% | — | Phpjabbers Cinema Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Cinema Booking System v1.0 is vulnerable to Multiple Stored Cross-Site Scripting (XSS) in the "title, name" parameters. | |
| Modificada | Media (5.3) | 0.59% | — | Phpjabbers Cinema Booking System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Cinema Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Modificada | Alta (8.8) | 0.83% | — | Phpjabbers Cinema Booking System | 20/2/2025 | 17/6/2026 | PHPJabbers Cinema Booking System v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. | |
| Modificada | Media (4.3) | 0.42% | — | Phpjabbers Meeting Room Booking System | 20/2/2025 | 17/6/2026 | A lack of rate limiting in the 'Forgot Password' feature of PHPJabbers Meeting Room Booking System v1.0 allows attackers to send an excessive amount of email for a legitimate user, leading to a possible Denial of Service (DoS) via a large amount of generated e-mail messages. | |
| Modificada | Media (6.5) | 0.51% | — | Phpjabbers Cleaning Business Software | 20/2/2025 | 17/6/2026 | PHPJabbers Cleaning Business Software v1.0 is vulnerable to CSV Injection vulnerability which allows an attacker to execute remote code. The vulnerability exists due to insufficient input validation on Languages section Labels any parameters field in System Options that is used to construct CSV file. |