Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

3560 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.4)0.34%—Inductiveautomation Ignition12/3/202617/6/2026
A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code.
AnalizadaCrítica (9.3)0.98%—Bukts BUK Ts-g GAS Station Automation System10/3/202610/8/2026
Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data…
AnalizadaAlta (7.2)0.24%—Schneider-electric Ecostruxure Automation Expert10/3/202623/6/2026
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent…
AnalizadaAlta (7.8)0.31%—Microsoft Azure Automation Hybrid Worker Windows Extension10/3/202617/6/2026
Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally.
AnalizadaAlta (7.5)0.32%—IBM Infosphere Information Server3/3/202617/6/2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server.
AnalizadaMedia (5.3)0.20%—IBM Infosphere Information Server3/3/202617/6/2026
IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file.
AnalizadaMedia (6.7)0.17%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside27/2/202617/6/2026
A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to…
AnalizadaMedia (6.7)0.20%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside27/2/202617/6/2026
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By…
AnalizadaMedia (6.7)0.17%—Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside27/2/202617/6/2026
A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of…
ModificadaAlta (8.8)1.3%—Systeminformation19/2/202615/7/2026
systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue.
ModificadaAlta (7.8)1.5%—Systeminformation19/2/202615/7/2026
systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In `lib/wifi.js`, the…
AplazadaMedia (5.3)0.25%—Doruk Communication AND Automation Industry AND Trade INC WispotterAI18/2/202617/6/2026
Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and Trade Inc. Wispotter allows Password Brute Forcing, Brute Force. This issue affects Wispotter: from 1.0 before v2025.10.08.1.
AplazadaMedia (6.5)0.32%—EKA Software Computer Information Advertising Services LTD Real Estate ScriptAI17/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS). This issue affects Real Estate…
AplazadaCrítica (9.8)0.41%—NTN Information Processing Services Computer Software Hardware Industry AND Trade Smart PanelAI12/2/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before 20251215.
AplazadaAlta (8.3)0.12%—PAN Software & Information Technologies LTD Pancafe PROAI11/2/202617/6/2026
Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issue affects PanCafe Pro: from < 3.3.2 through 23092025.
AplazadaMedia (5.3)0.30%—Wamate Confirm Order ConfirmationAI11/2/202617/6/2026
The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level…
AplazadaAlta (8.8)0.43%—Birtech Information Technologies Industry AND Trade SensawayAI9/2/202617/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server. This issue affects Sensaway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable…
AplazadaMedia (6.5)0.28%—Birtech Information Technologies Industry AND Trade SensewayAI9/2/202617/6/2026
Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix…
AplazadaCrítica (9.8)0.47%—Xpoda Turkiye Information Technology INC Password ModuleAI9/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection. This issue affects Password Module: through 11022026.
AplazadaAlta (7.3)0.33%—Birtech Information Technologies Industry AND Trade SensewayAI9/2/202617/6/2026
Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities.…
AplazadaAlta (8.6)0.33%—Zirve Information Technologies INC E-taxpayer Accounting WebsiteAI9/2/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Accounting Website allows Reflected XSS. This issue affects e-Taxpayer Accounting Website: through 07082025.
AplazadaAlta (8.5)0.21%—Rockwell Factorytalk Activation ServiceAIRockwellautomation Studio 5000 Logix DesignerAI5/2/202617/6/2026
Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject…
AnalizadaBaja (2.3)0.18%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+174/2/202617/6/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaCrítica (9.8)0.50%💥 PoCMartcode Software INC Delta Course AutomationAI4/2/202617/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection. This issue affects Delta Course Automation: through 04022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any…
AnalizadaAlta (8.1)0.25%—IBM Cloud PAK FOR Business Automation3/2/202617/6/2026
IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length.