Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

889 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)1.0%—Mitsubishielectric Melsec-q SeriesAIMitsubishielectric Melsec-l SeriesAI15/3/202417/6/2026
Integer Overflow or Wraparound vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to execute malicious code on a target product by sending a specially crafted packet.
AplazadaCrítica (9.8)1.1%—Mitsubishielectric Melsec-q SeriesAIMitsubishielectric Melsec-l SeriesAI15/3/202417/6/2026
Incorrect Pointer Scaling vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series and MELSEC-L Series CPU modules allows a remote unauthenticated attacker to read arbitrary information from a target product or execute malicious code on a target product by sending a specially crafted packet.
AplazadaAlta (7.2)0.88%—Omron Machine Automation Controller NJ SeriesAIOmron Machine Automation Controller NX SeriesAI12/3/202417/6/2026
Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege.…
ModificadaAlta (7.8)0.20%—Intel Realsense D400 Series Dynamic Calibration Tool14/11/202317/6/2026
Uncontrolled search path element in some Intel(R) RealSense(TM) Dynamic Calibration software before version 2.13.1.0 may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (4.4)0.23%—Intel Agilex 7 Fpga F-series 006 FirmwareIntel Agilex 7 Fpga F-series 008 FirmwareIntel Agilex 7 Fpga F-series 012 FirmwareIntel Agilex 7 Fpga F-series 014 Firmware+4414/11/202317/6/2026
Out-of-bounds write in firmware for some Intel(R) FPGA products before version 2.8.1 may allow a privileged user to potentially enable information disclosure via local access.
ModificadaMedia (5.4)0.41%—IBM Txseries FOR MultiplatformsIBM Cics TX3/11/202317/6/2026
IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted…
ModificadaAlta (8.8)0.29%—IBM Txseries FOR MultiplatformsIBM Cics TX3/11/202317/6/2026
IBM CICS TX Standard 11.1, Advanced 10.1, 11.1, and TXSeries for Multiplatforms 8.1, 8.2, 9.1 are vulnerable to cross-site request forgery which could allow an attacker to execute malicious and unauthorized actions transmitted from a user that the website trusts. IBM X-Force ID: 266057.
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitApache ActivemqApache Activemq Legacy Openwire ModuleDebian LinuxNetapp E-series Santricity Unified Manager+227/10/202317/6/2026
The Java OpenWire protocol marshaller is vulnerable to Remote Code Execution. This vulnerability may allow a remote attacker with network access to either a Java-based OpenWire broker or client to run arbitrary shell commands by manipulating serialized class types in the OpenWire protocol to cause either the client or…
ModificadaMedia (4.9)1.0%—IBM Txseries FOR MultiplatformsIBM Cics TX25/10/202317/6/2026
IBM TXSeries for Multiplatforms, 8.1, 8.2, and 9.1, CICS TX Standard CICS TX Advanced 10.1 and 11.1 could allow a privileged user to cause a denial of service due to uncontrolled resource consumption. IBM X-Force ID: 266016.
ModificadaMedia (6.1)0.41%—Rtautomation 460 Series Firmware27/9/202317/6/2026
Real Time Automation 460 Series products with versions prior to v8.9.8 are vulnerable to cross-site scripting, which could allow an attacker to run any JavaScript reference from the URL string. If this were to occur, the gateway's HTTP interface would redirect to the main page, which is index.htm.
ModificadaCrítica (9.8)1.3%—Rockwellautomation 1756-en2t Series A FirmwareRockwellautomation 1756-en2t Series B FirmwareRockwellautomation 1756-en2t Series C FirmwareRockwellautomation 1756-en2t Series D Firmware+2920/9/202317/6/2026
A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. To exploit this vulnerability, a threat actor would have to send a maliciously crafted CIP request to…
ModificadaAlta (7.5)1.2%—IBM Txseries FOR MultiplatformIBM Cics TX22/8/202317/6/2026
IBM GSKit-Crypto could allow a remote attacker to obtain sensitive information, caused by a timing-based side channel in the RSA Decryption implementation. By sending an overly large number of trial messages for decryption, an attacker could exploit this vulnerability to obtain sensitive information.
ModificadaAlta (7.5)1.0%—IBM Txseries FOR Multiplatform14/8/202317/6/2026
IBM TXSeries for Multiplatforms 8.1, 8.2, and 9.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service. IBM X-Force ID: 262905.
ModificadaAlta (8.8)1.0%—Steelseries GG20/7/202317/6/2026
An issue was discovered in SteelSeries GG 36.0.0. An attacker can change values in an unencrypted database that is writable for all users on the computer, in order to trigger code execution with higher privileges.
ModificadaAlta (7.5)1.0%—Steelseries GG20/7/202317/6/2026
Attackers can exploit an open API listener on SteelSeries GG 36.0.0 to create a sub-application that will be executed automatically from a controlled location, because of a path traversal vulnerability.
ModificadaAlta (7.5)0.70%—Biges Bullwark Momentum Series13/7/202317/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in Bullwark allows Path Traversal. This issue affects Bullwark: before BLW-2016E-960H.
ModificadaCrítica (9.8)5.5%—Rockwellautomation 1756-en2f Series A FirmwareRockwellautomation 1756-en2f Series B FirmwareRockwellautomation 1756-en2f Series C FirmwareRockwellautomation 1756-en2t Series A Firmware+812/7/202317/6/2026
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target system through maliciously crafted CIP messages. This includes the ability to modify, deny, and…
ModificadaBaja (3.1)0.63%—IBM Txseries FOR MultiplatformIBM Cics TX8/6/202317/6/2026
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to.…
ModificadaMedia (5.4)0.51%—IBM Txseries FOR MultiplatformIBM Cics TX8/6/202317/6/2026
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a…
ModificadaBaja (3.7)0.38%—IBM Cics TXIBM Txseries FOR Multiplatforms7/6/202317/6/2026
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could transmit sensitive information in query parameters that could be intercepted using man in the middle techniques. IBM X-Force ID: 257105.
ModificadaMedia (6.5)0.80%—IBM Cics TXIBM Txseries FOR Multiplatforms7/6/202317/6/2026
IBM TXSeries for Multiplatforms 8.1, 8.2, 9.1, CICS TX Standard, 11.1, CICS TX Advanced 10.1, and 11.1 could allow a privileged user to obtain highly sensitive information by enabling debug mode. IBM X-Force ID: 257104.
ModificadaAlta (7.8)0.18%—Intel Agilex 7 Fpga F-series 019 FirmwareIntel Agilex 7 Fpga F-series 023 FirmwareIntel Agilex 7 Fpga F-series 006 FirmwareIntel Agilex 7 Fpga F-series 008 Firmware+4410/5/202317/6/2026
Improper input validation in firmware for some Intel(R) FPGA products before version 2.7.0 Hotfix may allow an authenticated user to potentially enable escalation of privilege via local access.
ModificadaMedia (5.3)1.3%💥 PoCEclipse JettyDebian LinuxNetapp Active IQ Unified ManagerNetapp E-series Santricity OS Controller+218/4/202317/6/2026
Jetty is a java based web server and servlet engine. Nonstandard cookie parsing in Jetty may allow an attacker to smuggle cookies within other cookies, or otherwise perform unintended behavior by tampering with the cookie parsing mechanism. If Jetty sees a cookie VALUE that starts with `"` (double quote), it will…
ModificadaMedia (5.5)0.18%—Intel ON Event Series16/2/202317/6/2026
Insufficiently protected credentials in the Intel(R) ON Event Series Android application before version 2.0 may allow an authenticated user to potentially enable information disclosure via local access.
AnalizadaAlta (7.5)0.53%—CertifiNetapp E-series Performance AnalyzerNetapp Management Services FOR Element SoftwareManagement Services FOR Netapp HCI7/12/202217/6/2026
Certifi is a curated collection of Root Certificates for validating the trustworthiness of SSL certificates while verifying the identity of TLS hosts. Certifi 2022.12.07 removes root certificates from "TrustCor" from the root store. These are in the process of being removed from Mozilla's trust store. TrustCor's root…
Orbitaley — Vulnerabilidades