Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
2369 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/8/2025 | 17/6/2026 | When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Analizada | Alta (8.8) | 0.62% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 12/8/2025 | 17/6/2026 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | |
| Analizada | Media (5.1) | 0.11% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 12/8/2025 | 17/6/2026 | Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access. | |
| Analizada | Alta (8.8) | 0.83% | — | Ivanti Virtual Application Delivery Controller | 12/8/2025 | 17/6/2026 | Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password | |
| Aplazada | Alta (7) | 0.25% | — | Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAIOmron Sysmac StudioAI | 14/7/2025 | 17/6/2026 | Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products. | |
| Aplazada | Media (6.5) | 0.17% | — | Controller 7000 OnelinkAI | 10/7/2025 | 17/6/2026 | Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for Controllers once they are connected. This issue… | |
| Analizada | Crítica (9.2) | 11% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 25/6/2025 | 17/6/2026 | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Aplazada | Media (6.6) | 12% | — | Aviatrix ControllerAI | 23/6/2025 | 17/6/2026 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames | |
| Aplazada | Alta (7.8) | 0.48% | — | Aviatrix ControllerAI | 23/6/2025 | 17/6/2026 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN | |
| Aplazada | Crítica (9.3) | 1.6% | 💥 Exploit | Aquatronica Controller SystemAI | 20/6/2025 | 17/6/2026 | An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including… | |
| Aplazada | Media (4.3) | 0.26% | — | Grandplugins Image Sizes ControllerAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a… | |
| Analizada | Crítica (9.3) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 4/8/2026 | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Analizada | Alta (8.7) | 6.2% | 💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 17/6/2026 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway | |
| Aplazada | Alta (7.4) | 2.5% | — | Wifi-soft Unibox ControllerAI | 16/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/pms_check.php. The manipulation of the argument ipaddress leads to os command injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 2.1% | — | Wifi-soft Unibox ControllerAI | 16/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functionality of the file /billing/test_accesscodelogin.php. The manipulation of the argument Password leads to os command injection. The attack may be launched… | |
| Aplazada | Alta (7.4) | 2.3% | — | Wifi-soft Unibox ControllerAI | 16/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. The manipulation of the argument mac_address leads to os command injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.4) | 0.26% | — | Craftycontrol Crafty Controller | 15/6/2025 | 17/6/2026 | An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input. | |
| Aplazada | Alta (8.8) | 0.46% | — | Cisco Integrated Management ControllerAICisco UCS B-series ServersAICisco UCS C-series ServersAICisco UCS S-series ServersAI+1 | 4/6/2025 | 17/6/2026 | A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient… | |
| Modificada | Crítica (9.1) | 0.46% | — | Tinxy Wifi Lock Controller V1 RF Firmware | 30/5/2025 | 5/7/2026 | Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication. | |
| Analizada | Alta (7.5) | 0.24% | — | Tinxy Wifi Lock Controller V1 RF Firmware | 30/5/2025 | 17/6/2026 | Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext. | |
| Analizada | Media (5.9) | 0.19% | — | Tinxy Wifi Lock Controller V1 RF Firmware | 30/5/2025 | 17/6/2026 | Tinxy WiFi Lock Controller v1 RF was discovered to transmit sensitive information in plaintext, including control information and device credentials, allowing attackers to possibly intercept and access sensitive information via a man-in-the-middle attack. | |
| Analizada | Media (6.5) | 0.31% | — | IBM Cognos ControllerIBM Controller | 27/5/2025 | 17/6/2026 | IBM Controller 11.0.0, 11.0.1, and 11.1.0 application could allow an authenticated user to obtain sensitive credentials that may be inadvertently included within the source code. | |
| Aplazada | Alta (8.8) | 0.29% | — | Ericsson RAN Compute AND Site Controller 6610AI | 22/5/2025 | 17/6/2026 | Ericsson RAN Compute and Site Controller 6610 contains in certain configurations a high severity vulnerability where improper input validation could be exploited leading to arbitrary code execution. | |
| Aplazada | Alta (7.5) | 0.41% | — | Ericsson Packet Core ControllerAI | 16/5/2025 | 17/6/2026 | Ericsson Packet Core Controller (PCC) contains a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation | |
| Analizada | Media (6.1) | 0.29% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+2 | 14/5/2025 | 17/6/2026 | Cross-site scripting in some Zoom Workplace Apps may allow an authenticated user to impact app integrity via network access. |