Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 68 respecto a la semana anterior
Críticas / altas1421▲ 55 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
2299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.4) | 0.25% | — | Cisco IOSAICisco IOS XEAICisco Nx-osAICisco Wireless LAN ControllerAI | 7/5/2025 | 17/6/2026 | A vulnerability in the Switch Integrated Security Features (SISF) of Cisco IOS Software, Cisco IOS XE Software, Cisco NX-OS Software, and Cisco Wireless LAN Controller (WLC) AireOS Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on an affected device. This… | |
| Analizada | Media (6.5) | 0.40% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 8/4/2025 | 17/6/2026 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (6.5) | 0.42% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 8/4/2025 | 17/6/2026 | Null pointer dereference in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a denial of service via network access. | |
| Analizada | Media (5.5) | 0.16% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop | 8/4/2025 | 17/6/2026 | Insecure default variable initialization in some Zoom Workplace Apps for Windows may allow an authenticated user to conduct a loss of integrity via local access. | |
| Modificada | Media (5.2) | 0.24% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 8/4/2025 | 17/6/2026 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. | |
| Modificada | Media (5.2) | 0.26% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 8/4/2025 | 17/6/2026 | Cross site scripting in some Zoom Workplace Apps may allow an unauthenticated user to conduct a loss of integrity via adjacent network access. | |
| Aplazada | Media (4.7) | 0.46% | — | Wpfactory Scheduled Automatic Order Status Controller FOR WoocommerceAI | 27/3/2025 | 17/6/2026 | URL Redirection to Untrusted Site ('Open Redirect') vulnerability in WPFactory Scheduled & Automatic Order Status Controller for WooCommerce order-status-rules-for-woocommerce allows Phishing.This issue affects Scheduled & Automatic Order Status Controller for WooCommerce: from n/a through <= 3.7.1. | |
| Analizada | Media (4.7) | 0.20% | — | IBM Cognos ControllerIBM Controller | 26/3/2025 | 17/6/2026 | IBM Cognos Controller 11.0.0 through 11.1.0 is vulnerable to a Client-Side Desync (CSD) attack where an attacker could exploit a desynchronized browser connection that could lead to further cross-site scripting (XSS) attacks. | |
| Analizada | Crítica (9.8) | 0.64% | — | Dell Chassis Management Controller FOR Poweredge FX2 FirmwareDell Chassis Management Controller FOR Poweredge Vrtx Firmware | 21/3/2025 | 17/6/2026 | Dell Chassis Management Controller Firmware for Dell PowerEdge FX2, version(s) prior to 2.40.200.202101130302, and Dell Chassis Management Controller Firmware for Dell PowerEdge VRTX version(s) prior to 3.41.200.202209300499, contain(s) a Stack-based Buffer Overflow vulnerability. An unauthenticated attacker with… | |
| Analizada | Crítica (10) | 1.4% | — | Synology Unified ControllerSynology Replication ServiceSyncology Replication Service | 19/3/2025 | 17/6/2026 | Off-by-one error vulnerability in the transmission component in Synology Replication Service before 1.0.12-0066, 1.2.2-0353 and 1.3.0-0423 and Synology Unified Controller (DSMUC) before 3.1.4-23079 allows remote attackers to execute arbitrary code, potentially leading to a broader impact across the system via… | |
| Analizada | Alta (8.8) | 0.45% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 11/3/2025 | 17/6/2026 | Heap overflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (8.8) | 0.44% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 11/3/2025 | 17/6/2026 | Buffer underflow in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (8.8) | 0.44% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 11/3/2025 | 17/6/2026 | Use after free in some Zoom Workplace Apps may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (7.5) | 0.25% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 11/3/2025 | 17/6/2026 | Insufficient verification of data authenticity in some Zoom Workplace Apps may allow an unprivileged user to conduct a denial of service via network access. | |
| Aplazada | Alta (8.1) | 0.21% | — | Nvidia Hopper HGXAINvidia HGX Management ControllerAI | 5/3/2025 | 17/6/2026 | NVIDIA Hopper HGX for 8-GPU contains a vulnerability in the HGX Management Controller (HMC) that may allow a malicious actor with administrative access on the BMC to access the HMC as an administrator. A successful exploit of this vulnerability may lead to code execution, denial of service, escalation of privileges,… | |
| Analizada | Media (6.5) | 0.27% | — | IBM Controller | 1/3/2025 | 17/6/2026 | IBM Controller 11.0.0 through 11.0.1 and 11.1.0 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user accounts. | |
| Analizada | Media (5.7) | 0.10% | — | Cisco Application Policy Infrastructure Controller | 26/2/2025 | 17/6/2026 | A vulnerability in the system file permission handling of Cisco APIC could allow an authenticated, local attacker to overwrite critical system files, which could cause a DoS condition. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to a race condition… | |
| Analizada | Media (4.4) | 0.16% | — | Cisco Application Policy Infrastructure Controller | 26/2/2025 | 17/6/2026 | A vulnerability in the implementation of the internal system processes of Cisco APIC could allow an authenticated, local attacker to access sensitive information on an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… | |
| Analizada | Media (6.7) | 0.19% | — | Cisco Application Policy Infrastructure Controller | 26/2/2025 | 17/6/2026 | A vulnerability in the CLI of Cisco APIC could allow an authenticated, local attacker to execute arbitrary commands as root on the underlying operating system of an affected device. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to insufficient… | |
| Analizada | Media (4.8) | 0.28% | — | Cisco Application Policy Infrastructure Controller | 26/2/2025 | 17/6/2026 | A vulnerability in the web UI of Cisco APIC could allow an authenticated, remote attacker to perform a stored XSS attack on an affected system. To exploit this vulnerability, the attacker must have valid administrative credentials. This vulnerability is due to improper input validation in the web UI. An authenticated… | |
| Analizada | Media (6.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 25/2/2025 | 17/6/2026 | Incorrect ownership assignment in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access. | |
| Analizada | Media (6.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 25/2/2025 | 17/6/2026 | Incorrect user management in some Zoom Workplace Apps may allow a privileged user to conduct an information disclosure via network access. | |
| Analizada | Alta (7.5) | 0.37% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 25/2/2025 | 17/6/2026 | Business logic error in some Zoom Workplace Apps may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Alta (8.8) | 0.61% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Video Software Development KIT+3 | 25/2/2025 | 17/6/2026 | Buffer overflow in some Zoom Apps may allow an authenticated user to conduct an escalation of privilege via network access. | |
| Analizada | Alta (8.2) | 0.52% | — | IBM Cognos ControllerIBM Controller | 19/2/2025 | 17/6/2026 | IBM Cognos Controller 11.0.0 through 11.0.1 FP3 and IBM Controller 11.1.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. |