Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.5) | 0.41% | — | IBM Cloud PAK FOR Business Automation | 3/5/2025 | 17/6/2026 | IBM Cloud Pak for Business Automation 24.0.0 and 24.0.1 through 24.0.1 IF001 Authoring allows an authenticated user to bypass client-side data validation in an authoring user interface which could cause a denial of service. | |
| Analizada | Media (4.3) | 0.26% | — | IBM Business Automation Workflow | 3/5/2025 | 17/6/2026 | IBM Business Automation Workflow 24.0.0 and 24.0.1 through 24.0.1 IF001 Center may leak sensitive information due to missing authorization validation. | |
| Analizada | Media (6.1) | 0.26% | — | IBM Cloud PAK FOR Business Automation | 3/5/2025 | 17/6/2026 | IBM Cloud Pak for Business Automation 24.0.0 through 24.0.0 IF004 and 24.0.1 through 24.0.1 IF001 is vulnerable to cross-site scripting. This vulnerability allows an unauthenticated attacker to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials… | |
| Modificada | Media (6.1) | 0.24% | — | Yordam Library Automation System | 2/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Yordam Informatics Library Automation System allows Reflected XSS. This issue affects Library Automation System: before 21.6. | |
| Modificada | Crítica (9.8) | 0.49% | 💥 PoC | Mydata Ticket Sales Automation | 2/5/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Mydata Informatics Ticket Sales Automation allows Blind SQL Injection. This issue affects Ticket Sales Automation: before 03.04.2025 (DD.MM.YYYY). | |
| Analizada | Alta (8.4) | 0.10% | — | ABB Automation Builder | 30/4/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource, Cleartext Storage of Sensitive Information vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0. | |
| Analizada | Alta (8.5) | 0.15% | — | ABB Automation Builder | 30/4/2025 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB Automation Builder.This issue affects Automation Builder: through 2.8.0. | |
| Aplazada | Media (6.3) | 0.38% | — | Khc-invitation-automationAI | 29/4/2025 | 17/6/2026 | KHC-INVITATION-AUTOMATION is a GitHub automation script that automatically invites followers of a bot account to join your organization. In some commits on version 1.2, a vulnerability was identified where user data, including email addresses and Discord usernames, were exposed in API responses without proper access… | |
| Aplazada | Media (4.9) | 0.21% | — | Ankur Vishwakarma WP Avcl Automation HelperAI | 24/4/2025 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in Ankur Vishwakarma WP AVCL Automation Helper (formerly WPFlyLeads) woozap allows Server Side Request Forgery.This issue affects WP AVCL Automation Helper (formerly WPFlyLeads): from n/a through <= 3.4. | |
| Aplazada | Alta (7.1) | 0.29% | — | Movylo Marketing AutomationAI | 17/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Movylo Movylo Marketing Automation movylo-widget allows Reflected XSS.This issue affects Movylo Marketing Automation: from n/a through <= 2.0.7. | |
| Analizada | Alta (8.5) | 1.8% | — | Rockwellautomation Thinmanager | 15/4/2025 | 17/6/2026 | A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software. | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Thinmanager | 15/4/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit permissions from the parent directory. If exploited, a threat actor could inherit elevated privileges. | |
| Analizada | Media (4.3) | 0.22% | — | IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK | 14/4/2025 | 17/6/2026 | IBM Robotic Process Automation and Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.20 and 23.0.0 through 23.0.20 does not invalidate session after a logout which could allow an authenticated user to impersonate another user on the system. | |
| Analizada | Alta (8.5) | 0.31% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the… | |
| Analizada | Alta (8.5) | 0.31% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to write outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user… | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 8/4/2025 | 17/6/2026 | A local code execution vulnerability exists in the Rockwell Automation Arena® due to an uninitialized pointer. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can disclose information and execute arbitrary code on the system. To exploit the vulnerability a legitimate user… | |
| Aplazada | Media (6.5) | 0.17% | — | Automationdirect C-more ViewjetAI | 4/4/2025 | 17/6/2026 | Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker. |