Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2350 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.44% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+19 | 15/10/2025 | 17/6/2026 | When a TCP profile with Multipath TCP (MPTCP) enabled is configured on a virtual server, undisclosed traffic along with conditions beyond the attacker's control can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.43% | — | F5 Big-ip Next Cloud-native Network FunctionsF5 Big-ip Next Service Proxy FOR KubernetesF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall Manager+19 | 15/10/2025 | 17/6/2026 | When an iRule containing the HTTP::respond command is configured on a virtual server, undisclosed requests can cause an increase in memory resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.5) | 0.39% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 15/10/2025 | 30/9/2026 | A vulnerability exists in the iHealth command that may allow an authenticated attacker with at least a resource administrator role to bypass tmsh restrictions and gain access to a bash shell. For BIG-IP systems running in Appliance mode, a successful exploit can allow the attacker to cross a security boundary. Note:… | |
| Aplazada | Media (6.4) | 0.26% | — | Haproxy Kubernetes Ingress ControllerAI | 8/10/2025 | 17/6/2026 | HAProxy Kubernetes Ingress Controller before 3.1.13, when the config-snippets feature flag is used, accepts config snippets from users with create/update permissions. This can result in obtaining an ingress token secret as a response. The fixed versions of HAProxy Enterprise Kubernetes Ingress Controller are… | |
| Analizada | Alta (7.5) | 0.23% | — | IBM Cognos ControllerIBM Controller | 26/9/2025 | 17/6/2026 | IBM Cognos Controller 11.0.0 through 11.0.1, and IBM Controller 11.1.0 through 11.1.1 could allow an attacker to obtain sensitive information due to the use of hardcoded cryptographic keys for signing session cookies. | |
| Aplazada | Media (5) | 0.21% | — | Satellite Management ControllerAI | 23/9/2025 | 17/6/2026 | Improper input validation in Satellite Management Controller (SMC) may allow an attacker with privileges to manipulate Redfish® API commands to remove files from the local root directory, potentially resulting in data corruption. | |
| Aplazada | Crítica (9.8) | 0.42% | — | Aikaan Cloud ControllerAI | 22/9/2025 | 17/6/2026 | AiKaan Cloud Controller uses a single hardcoded SSH private key and the username `proxyuser` for remote terminal access to all managed IoT/edge devices. When an administrator initiates "Open Remote Terminal" from the AiKaan dashboard, the controller sends this same static private key to the target device. The device… | |
| Aplazada | Media (6.7) | 0.15% | — | Nvidia HGX Management ControllerAINvidia DGX Gb200AINvidia DGX Gb300AINvidia DGX B300AI | 17/9/2025 | 17/6/2026 | NVIDIA HGX & DGX GB200, GB300, B300 contain a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of… | |
| Analizada | Media (6.5) | 0.26% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Media (4.3) | 0.20% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access. | |
| Analizada | Alta (7.4) | 0.31% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 9/9/2025 | 17/6/2026 | Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 9/9/2025 | 17/6/2026 | Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 9/9/2025 | 17/6/2026 | Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access. | |
| Aplazada | Media (6.5) | 0.20% | — | Kubernetes Secrets-store-sync-controllerAI | 5/9/2025 | 17/6/2026 | Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs. | |
| Analizada | Crítica (9.3) | 0.52% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user. | |
| Analizada | Alta (8.6) | 0.22% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade. | |
| Analizada | Crítica (9.2) | 0.47% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters. | |
| Analizada | Alta (8.7) | 0.34% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously crash the application services. | |
| Analizada | Media (5.1) | 0.20% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can inject a stored XSS to the floorplan web page. | |
| Analizada | Alta (7.7) | 0.26% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services. | |
| Analizada | Alta (8.8) | 0.36% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can access any file from the E3 file system. | |
| Analizada | Media (5.3) | 0.31% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash. | |
| Analizada | Media (6.9) | 0.34% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 5/10/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS. | |
| Aplazada | Media (5.4) | 0.22% | — | Cisco Integrated Management ControllerAICisco UCS ManagerAI | 27/8/2025 | 17/6/2026 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to… | |
| Aplazada | Alta (7.1) | 0.45% | — | Cisco Integrated Management ControllerAICisco UCS ManagerAI | 27/8/2025 | 17/6/2026 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit… |