Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.4) | 0.24% | — | IBM Cloud PAK FOR Business Automation | 2/2/2026 | 17/6/2026 | IBM Cloud Pak for Business Automation 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 007 is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the… | |
| Analizada | Alta (7.1) | 0.52% | — | IBM Business Automation Workflow | 2/2/2026 | 17/6/2026 | IBM Business Automation Workflow containers V25.0.0 through V25.0.0-IF007, V24.0.1 - V24.0.1-IF007, V24.0.0 - V24.0.0-IF007 and IBM Business Automation Workflow traditional V25.0.0, V24.0.1, V24.0.0 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit… | |
| Analizada | Media (5.5) | 0.10% | — | IBM Business Automation Workflow | 20/1/2026 | 17/6/2026 | IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system calls. | |
| Analizada | Media (5.5) | 0.13% | — | IBM Business Automation Workflow | 20/1/2026 | 17/6/2026 | IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map. | |
| Analizada | Alta (8.7) | 0.64% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.48% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.39% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive. | |
| Analizada | Alta (8.7) | 0.60% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.60% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.60% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots | |
| Analizada | Alta (8.7) | 0.48% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot. | |
| Analizada | Alta (8.7) | 0.60% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.48% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible. | |
| Aplazada | Alta (8.9) | 0.36% | — | Br-automation Automation RuntimeAI | 19/1/2026 | 17/6/2026 | An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on… | |
| Aplazada | Crítica (9.1) | 0.23% | — | Beckhoff Automation StudioAI | 19/1/2026 | 17/6/2026 | An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges. | |
| Modificada | Media (6.5) | 0.40% | — | Connectwise Professional Service Automation | 16/1/2026 | 17/6/2026 | In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values. | |
| Modificada | Media (5.4) | 0.28% | — | Connectwise Professional Service Automation | 16/1/2026 | 17/6/2026 | In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed. | |
| Analizada | Media (5.1) | 0.28% | — | Juniper Paragon Automation | 15/1/2026 | 17/6/2026 | A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface… | |
| Aplazada | Crítica (9.1) | 0.51% | — | SAP Landscape TransformationAI | 13/1/2026 | 17/6/2026 | SAP Landscape Transformation allows an attacker with admin privileges to exploit a vulnerability in the function module exposed via RFC. This flaw enables the injection of arbitrary ABAP code/OS commands into the system, bypassing essential authorization checks. This vulnerability effectively functions as a backdoor,… | |
| Aplazada | Alta (8.5) | 0.42% | — | Redhat Ansible Automation PlatformAI | 8/1/2026 | 17/6/2026 | A flaw was found in Ansible Automation Platform (AAP). Read-only scoped OAuth2 API Tokens in AAP, are enforced at the Gateway level for Gateway-specific operations. However, this vulnerability allows read-only tokens to perform write operations on backend services (e.g., Controller, Hub, EDA). If this flaw were… | |
| Aplazada | Crítica (9.8) | 0.69% | — | WP Cost EstimationAI | 8/1/2026 | 17/6/2026 | The WP Cost Estimation plugin for WordPress is vulnerable to arbitrary file uploads and deletion due to missing file type validation in the lfb_upload_form and lfb_removeFile AJAX actions in versions up to, and including, 9.642. This makes it possible for unauthenticated attackers to upload arbitrary files on the… | |
| Aplazada | Media (6.5) | 0.61% | — | WP Cost EstimationAI | 8/1/2026 | 17/6/2026 | The WP Cost Estimation plugin for WordPress is vulnerable to Upload Directory Traversal in versions before 9.660 via the uploadFormFiles function. This allows attackers to overwrite any file with a whitelisted type on an affected site. | |
| Modificada | Crítica (9.6) | 1.3% | 💥 PoC | Redhat Build OF Apache CamelRedhat Data GridRedhat FuseRedhat Jboss Enterprise Application Platform+4 | 7/1/2026 | 6/10/2026 | A flaw was found in the Undertow HTTP server core, which is used in WildFly, JBoss EAP, and other Java applications. The Undertow library fails to properly validate the Host header in incoming HTTP requests.As a result, requests containing malformed or malicious Host headers are processed without rejection, enabling… | |
| Aplazada | Alta (7.1) | 0.18% | — | Tumult Hype AnimationsAI | 5/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Tumult Inc Tumult Hype Animations allows DOM-Based XSS.This issue affects Tumult Hype Animations: from n/a through 1.9.11. | |
| Analizada | Media (6.5) | 0.43% | — | Apache Spatial Information System | 5/1/2026 | 7/10/2026 | Improper Restriction of XML External Entity Reference vulnerability in Apache SIS. It is possible to write XML files in such a way that, when parsed by Apache SIS, an XML file reveals to the attacker the content of a local file on the server running Apache SIS. This vulnerability impacts the following SIS services:… |