Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 485 respecto a la semana anterior
Críticas / altas1305▼ 185 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.34% | — | Inductiveautomation Ignition | 12/3/2026 | 17/6/2026 | A privileged Ignition user, intentionally or otherwise, imports an external file with a specially crafted payload, which executes embedded malicious code. | |
| Analizada | Crítica (9.3) | 0.98% | — | Bukts BUK Ts-g GAS Station Automation System | 10/3/2026 | 10/8/2026 | Nefteprodukttekhnika BUK TS-G Gas Station Automation System 2.9.1 on Linux contains a SQL Injection vulnerability (CWE-89) in the system configuration module. A remote attacker can send specially crafted HTTP POST requests to the /php/request.php endpoint via the sql parameter in application/x-www-form-urlencoded data… | |
| Analizada | Alta (7.2) | 0.24% | — | Schneider-electric Ecostruxure Automation Expert | 10/3/2026 | 23/6/2026 | CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent… | |
| Analizada | Alta (7.8) | 0.31% | — | Microsoft Azure Automation Hybrid Worker Windows Extension | 10/3/2026 | 17/6/2026 | Improper authentication in Azure Arc allows an authorized attacker to elevate privileges locally. | |
| Analizada | Alta (7.5) | 0.32% | — | IBM Infosphere Information Server | 3/3/2026 | 17/6/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 An XML External Entity (XXE) vulnerability in IBM InfoSphere Information Server could allow attackers to retrieve sensitive information from the server. | |
| Analizada | Media (5.3) | 0.20% | — | IBM Infosphere Information Server | 3/3/2026 | 17/6/2026 | IBM InfoSphere Information Server 11.7.0.0 through 11.7.1.6 is vulnerable to writing of sensitive Information in a log file. | |
| Analizada | Media (6.7) | 0.17% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 27/2/2026 | 17/6/2026 | A flaw was found in the Red Hat Ansible Automation Platform Gateway route creation component. This vulnerability allows credential theft via the creation of misleading routes using a double-slash (//) prefix in the gateway_path. A malicious or socially engineered administrator can configure a honey-pot route to… | |
| Analizada | Media (6.7) | 0.20% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 27/2/2026 | 17/6/2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Streams. This vulnerability allows an authenticated user to gain access to sensitive internal infrastructure headers (such as X-Trusted-Proxy and X-Envoy-*) and event stream URLs via crafted requests and job templates. By… | |
| Analizada | Media (6.7) | 0.17% | — | Redhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 27/2/2026 | 17/6/2026 | A flaw was found in the Red Hat Ansible Automation Platform, Event-Driven Ansible (EDA) Event Stream API. This vulnerability allows exposure of sensitive client credentials and internal infrastructure headers via the test_headers field when an event stream is in test mode. The possible outcome includes leakage of… | |
| Modificada | Alta (8.8) | 1.3% | — | Systeminformation | 19/2/2026 | 15/7/2026 | systeminformation is a System and OS information library for node.js. Versions prior to 5.31.0 are vulnerable to command injection via unsanitized `locate` output in `versions()`. Version 5.31.0 fixes the issue. | |
| Modificada | Alta (7.8) | 1.5% | — | Systeminformation | 19/2/2026 | 15/7/2026 | systeminformation is a System and OS information library for node.js. In versions prior to 5.30.8, a command injection vulnerability in the `wifiNetworks()` function allows an attacker to execute arbitrary OS commands via an unsanitized network interface parameter in the retry code path. In `lib/wifi.js`, the… | |
| Aplazada | Media (5.3) | 0.25% | — | Doruk Communication AND Automation Industry AND Trade INC WispotterAI | 18/2/2026 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts, Improper Authentication vulnerability in Doruk Communication and Automation Industry and Trade Inc. Wispotter allows Password Brute Forcing, Brute Force. This issue affects Wispotter: from 1.0 before v2025.10.08.1. | |
| Aplazada | Media (6.5) | 0.32% | — | EKA Software Computer Information Advertising Services LTD Real Estate ScriptAI | 17/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in EKA Software Computer Information Advertising Services Ltd. Real Estate Script V5 (With Doping Module – Store Module – New Language System) allows Cross-Site Scripting (XSS). This issue affects Real Estate… | |
| Aplazada | Crítica (9.8) | 0.41% | — | NTN Information Processing Services Computer Software Hardware Industry AND Trade Smart PanelAI | 12/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in NTN Information Processing Services Computer Software Hardware Industry and Trade Ltd. Co. Smart Panel allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects Smart Panel: before 20251215. | |
| Aplazada | Alta (8.3) | 0.12% | — | PAN Software & Information Technologies LTD Pancafe PROAI | 11/2/2026 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Pan Software & Information Technologies Ltd. PanCafe Pro allows Flooding. This issue affects PanCafe Pro: from < 3.3.2 through 23092025. | |
| Aplazada | Media (5.3) | 0.30% | — | Wamate Confirm Order ConfirmationAI | 11/2/2026 | 17/6/2026 | The WaMate Confirm – Order Confirmation plugin for WordPress is vulnerable to unauthorized access in all versions up to, and including, 2.0.1. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for authenticated attackers, with subscriber-level… | |
| Aplazada | Alta (8.8) | 0.43% | — | Birtech Information Technologies Industry AND Trade SensawayAI | 9/2/2026 | 17/6/2026 | Unrestricted Upload of File with Dangerous Type vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Sensaway allows Upload a Web Shell to a Web Server. This issue affects Sensaway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable… | |
| Aplazada | Media (6.5) | 0.28% | — | Birtech Information Technologies Industry AND Trade SensewayAI | 9/2/2026 | 17/6/2026 | Insecure Storage of Sensitive Information vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Retrieve Embedded Sensitive Data. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix… | |
| Aplazada | Crítica (9.8) | 0.47% | — | Xpoda Turkiye Information Technology INC Password ModuleAI | 9/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Xpoda Türkiye Information Technology Inc. Password Module allows SQL Injection. This issue affects Password Module: through 11022026. | |
| Aplazada | Alta (7.3) | 0.33% | — | Birtech Information Technologies Industry AND Trade SensewayAI | 9/2/2026 | 17/6/2026 | Improper Authentication vulnerability in Birtech Information Technologies Industry and Trade Ltd. Co. Senseway allows Authentication Abuse. This issue affects Senseway: through 09022026. NOTE: Because the product was developed using outdated technology, the manufacturer is unable to fix the relevant vulnerabilities.… | |
| Aplazada | Alta (8.6) | 0.33% | — | Zirve Information Technologies INC E-taxpayer Accounting WebsiteAI | 9/2/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Zirve Information Technologies Inc. E-Taxpayer Accounting Website allows Reflected XSS. This issue affects e-Taxpayer Accounting Website: through 07082025. | |
| Aplazada | Alta (8.5) | 0.21% | — | Rockwell Factorytalk Activation ServiceAIRockwellautomation Studio 5000 Logix DesignerAI | 5/2/2026 | 17/6/2026 | Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject… | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Aplazada | Crítica (9.8) | 0.50% | 💥 PoC | Martcode Software INC Delta Course AutomationAI | 4/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martcode Software Inc. Delta Course Automation allows SQL Injection. This issue affects Delta Course Automation: through 04022026. NOTE: The vendor was contacted early about this disclosure but did not respond in any… | |
| Analizada | Alta (8.1) | 0.25% | — | IBM Cloud PAK FOR Business Automation | 3/2/2026 | 17/6/2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 could allow an authenticated user to cause a denial of service or corrupt existing data due to the improper validation of input length. |