Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

4319 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.5)0.90%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202629/6/2026
When running in Appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.3)0.40%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202629/6/2026
When Bidirectional Forwarding Detection (BFD) is configured in Static and Dynamic routing protocols, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to stop processing BFD packets and cause the configured routing protocol to fail over. Note: Software versions which have reached End of Technical…
AnalizadaAlta (8.5)0.41%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202629/6/2026
A vulnerability exists in BIG-IP scripted monitors that may allow an authenticated attacker with the Resource Administrator or Administrator role to execute arbitrary system commands with higher privileges. In appliance mode deployments, a successful exploit can allow the attacker to cross a security boundary. Note:…
AnalizadaAlta (8.5)0.26%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1813/5/202629/6/2026
A vulnerability exists in BIG-IP and BIG-IQ systems where a highly privileged, authenticated attacker with at least the Certificate Manager role can modify configuration objects that allow running arbitrary commands. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaMedia (6.9)0.89%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/5/202629/6/2026
When running in Appliance mode, a directory traversal vulnerability exists in an undisclosed iControl REST endpoint that may allow an authenticated attacker with administrator role privileges to cross a security boundary and delete files. Note: Software versions which have reached End of Technical Support (EoTS) are…
AplazadaAlta (7.5)0.33%—Striso-control-firmwareAI13/5/202617/6/2026
striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function AuxJack.
AplazadaAlta (7.5)0.33%—Striso-control-firmwareAI13/5/202617/6/2026
striso-control-firmware 54c9722 is vulnerable to Buffer Overflow in function ThreadReadButtons.
AnalizadaAlta (8.8)0.17%—Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway11/5/202617/6/2026
The software fails to enforce role-based access controls for certain Gateway API invocations. Users with the 'Internal/Everyone' role can invoke these APIs, bypassing intended permission checks. This same vulnerability also affects Internal Service APIs, potentially exposing them in WSO2 APIM 3.x versions. A malicious…
AnalizadaAlta (7.5)0.19%—Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway11/5/202617/6/2026
In Webhook API invocations, the component accepts user-supplied input for HTTP request headers without sufficient validation or sanitization, allowing these headers to be injected into HTTP responses. By exploiting this vulnerability, a malicious actor can inject or overwrite arbitrary HTTP response headers. This can…
Pendiente de análisisAlta (7.3)3.6%💥 ExploitControl WEB PanelAISoftaculousAISitepadAI8/5/202617/6/2026
An issue was discovered in Control Web Panel (CWP) before 0.9.8.1209. User input passed via the "key" GET parameter to /admin/index.php (when the "api" parameter is set) is not properly sanitized before being used to execute OS commands. This can be exploited by unauthenticated attackers to inject and execute…
Pendiente de análisisMedia (6.8)0.14%—Asus System Control InterfaceAI8/5/202617/9/2026
An Out-of-bounds Read vulnerability in the IOCTL handler in ASUS System Control Interface allows a local user to cause system crash (BSOD) via a read size that exceeds the buffer size.Refer to the ' Security Update for MyASUS ' section on the ASUS Security Advisory for more information.
Pendiente de análisisAlta (8.4)0.11%—Johnsoncontrols Ac2000AI6/5/202624/8/2026
An Uncontrolled Search Path Element vulnerability in JohnsonControls AC2000 on Windows allows Leveraging/Manipulating Configuration File Search Paths. This issue affects AC2000: from 10.6 before release 10, from 11.0 before release 9, from 12 before release 3.
Pendiente de análisisNinguna (0)0.31%—Cisco Crosswork Network ControllerAICisco Network Services OrchestratorAI6/5/202617/6/2026
Following the initial publication of the Security Advisory about a denial of service (DoS) condition in Cisco Crosswork Network Controller and Cisco Network Services Orchestrator (NSO), additional information has been made available to the Cisco Product Security Incident Response Team (PSIRT). Upon further analysis,…
Pendiente de análisisAlta (8.8)0.10%—FAN ControlAI27/4/202617/6/2026
The Fan Control application V251 contains an improper privilege handling vulnerability in its Open File Dialog. The dialog processes user-supplied paths with elevated permissions, which can be exploited by a local attacker to perform actions with administrator-level privileges.
AplazadaMedia (5.1)0.16%—Efficientlab ControlioAI23/4/20267/10/2026
EfficientLab Controlio before v1.3.95 contains a DLL hijacking vulnerability caused by weak folder permissions in the installation directory. A local attacker can place a specially crafted DLL in this directory and achieve arbitrary code execution with highest privileges, because the affected service runs as NT…
AnalizadaCrítica (9)0.51%—Craftycontrol Crafty Controller21/4/202617/6/2026
An insecure direct object reference vulnerability in the Users API component of Crafty Controller allows a remote, authenticated attacker to perform user modification actions via improper API permissions validation.
AplazadaMedia (6.4)0.26%—Image Source Control LiteAI20/4/202617/6/2026
The Image Source Control Lite – Show Image Credits and Captions plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the 'Image Source' attachment field in all versions up to, and including, 3.9.1 due to insufficient input sanitization and output escaping. This makes it possible for authenticated…
AnalizadaCrítica (9.8)0.28%—BMC Control-m/managed File Transfer10/4/202617/6/2026
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A set of default debug user credentials is hardcoded in cleartext within the application package. If left unchanged, these credentials can be easily obtained and may allow unauthorized access to the MFT API debug interface.
AnalizadaAlta (7.5)0.27%—BMC Control-m/managed File Transfer10/4/202617/6/2026
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. An API management endpoint allows unauthenticated users to obtain both an API identifier and its corresponding secret value. With these exposed secrets, an attacker could invoke privileged API operations, potentially leading to unauthorized access.
AnalizadaAlta (8.8)0.40%—BMC Control-m/managed File Transfer10/4/202617/6/2026
An issue was discovered in BMC Control-M/MFT 9.0.20 through 9.0.22. A SQL injection vulnerability in the MFT API's debug interface allows an authenticated attacker to inject malicious queries due to improper input validation and unsafe dynamic SQL handling. Successful exploitation can enable arbitrary file read/write…
AplazadaBaja (3.1)0.18%—Fluxcd Notification-controllerAI9/4/202617/6/2026
Flux notification-controller is the event forwarder and notification dispatcher for the GitOps Toolkit controllers. Prior to 1.8.3, the gcr Receiver type in Flux notification-controller does not validate the email claim of Google OIDC tokens used for Pub/Sub push authentication. This allows any valid Google-issued…
Pendiente de análisisMedia (5.4)0.20%—Deepin Dde-control-centerAIPlugin-deepinidAI9/4/202617/6/2026
dde-control-center is the control panel of DDE, the Deepin Desktop Environment. plugin-deepinid is a plugin in dde-control-center, which provides the deepinid cloud service. Prior to 6.1.80, plugin-deepinid is configured to skip TLS certificate verification when fetching the user's avatar from openapi.deepin.com or…
Pendiente de análisisCrítica (9.3)0.44%—Contemporary Controls Basc 20TAI9/4/20267/10/2026
An attacker could use data obtained by sniffing the network traffic to forge packets in order to make arbitrary requests to Contemporary Controls BASC 20T.
ModificadaMedia (6.9)0.40%—Hydrosystem.poznan Control System9/4/202613/8/2026
AlanWeb SCADA saves sensitive information into a log file. Critically, user credentials are logged allowing the attacker to obtain further authorized access into the system. Combined with vulnerability CVE-2026-34184, these sensitive information could be accessed by an unauthorized user. This issue was fixed in…
ModificadaAlta (8.7)0.47%—Hydrosystem.poznan Control System9/4/202613/8/2026
AlanWeb SCADA is vulnerable to SQL Injection across most scripts and input parameters. Because no protections are in place, an authenticated attacker can inject arbitrary SQL commands, potentially gaining full control over the database. This issue was fixed in AlanWeb SCADA version 9.8.5