Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

2369 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.34%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1713/8/202517/6/2026
When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are…
AnalizadaAlta (8.8)0.62%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+112/8/202517/6/2026
Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access
AnalizadaMedia (5.1)0.11%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+112/8/202517/6/2026
Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access.
AnalizadaAlta (8.8)0.83%—Ivanti Virtual Application Delivery Controller12/8/202517/6/2026
Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password
AplazadaAlta (7)0.25%—Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAIOmron Sysmac StudioAI14/7/202517/6/2026
Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products.
AplazadaMedia (6.5)0.17%—Controller 7000 OnelinkAI10/7/202517/6/2026
Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for Controllers once they are connected. This issue…
AnalizadaCrítica (9.2)11%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway25/6/202517/6/2026
Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AplazadaMedia (6.6)12%—Aviatrix ControllerAI23/6/202517/6/2026
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames
AplazadaAlta (7.8)0.48%—Aviatrix ControllerAI23/6/202517/6/2026
Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN
AplazadaCrítica (9.3)1.6%💥 ExploitAquatronica Controller SystemAI20/6/202517/6/2026
An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including…
AplazadaMedia (4.3)0.26%—Grandplugins Image Sizes ControllerAI20/6/202517/6/2026
Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a…
AnalizadaCrítica (9.3)100%⚠ Explotación activa💥 ExploitCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/6/20254/8/2026
Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server
AnalizadaAlta (8.7)6.2%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway17/6/202517/6/2026
Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway
AplazadaAlta (7.4)2.5%—Wifi-soft Unibox ControllerAI16/6/202517/6/2026
A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/pms_check.php. The manipulation of the argument ipaddress leads to os command injection. It is possible to initiate the attack remotely. The exploit has been…
AplazadaAlta (7.4)2.1%—Wifi-soft Unibox ControllerAI16/6/202517/6/2026
A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functionality of the file /billing/test_accesscodelogin.php. The manipulation of the argument Password leads to os command injection. The attack may be launched…
AplazadaAlta (7.4)2.3%—Wifi-soft Unibox ControllerAI16/6/202517/6/2026
A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. The manipulation of the argument mac_address leads to os command injection. The attack can be launched remotely. The exploit…
AnalizadaMedia (5.4)0.26%—Craftycontrol Crafty Controller15/6/202517/6/2026
An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input.
AplazadaAlta (8.8)0.46%—Cisco Integrated Management ControllerAICisco UCS B-series ServersAICisco UCS C-series ServersAICisco UCS S-series ServersAI+14/6/202517/6/2026
A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient…
ModificadaCrítica (9.1)0.46%—Tinxy Wifi Lock Controller V1 RF Firmware30/5/20255/7/2026
Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication.
AnalizadaAlta (7.5)0.24%—Tinxy Wifi Lock Controller V1 RF Firmware30/5/202517/6/2026
Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext.
AnalizadaMedia (5.9)0.19%—Tinxy Wifi Lock Controller V1 RF Firmware30/5/202517/6/2026
Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack.
AnalizadaMedia (6.5)0.31%—IBM Cognos ControllerIBM Controller27/5/202517/6/2026
IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code.
AplazadaAlta (8.8)0.29%—Ericsson RAN Compute AND Site Controller 6610AI22/5/202517/6/2026
Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where improper input validation could be exploited leading to arbitrary code execution.
AplazadaAlta (7.5)0.41%—Ericsson Packet Core ControllerAI16/5/202517/6/2026
Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation
AnalizadaMedia (6.1)0.29%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+214/5/202517/6/2026
Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access.
Orbitaley — Vulnerabilidades