Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
4319 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.46% | — | Hydrosystem.poznan Control System | 9/4/2026 | 13/8/2026 | AlanWeb SCADA does not enforce authorization for some directories. This allows an unauthorized attacker to read all files in these directories and even execute some of them. Critically the attacker could run PHP scripts directly on the connected database. This issue was fixed in AlanWeb SCADA version 9.8.5 | |
| Analizada | Alta (8.1) | 0.38% | — | Coolercontrold | 8/4/2026 | 24/7/2026 | CORS misconfiguration in CoolerControl/coolercontrold <4.0.0 allows unauthenticated remote attackers to read data and send commands to the service via malicious websites | |
| Analizada | Media (6.1) | 0.37% | — | Coolercontrold | 8/4/2026 | 24/7/2026 | Stored XSS in log viewer in CoolerControl/coolercontrol-ui <4.0.0 allows unauthenticated attackers to take over the service via malicious JavaScript in poisoned log entries | |
| Analizada | Crítica (9.1) | 0.28% | — | Coolercontrold | 8/4/2026 | 24/7/2026 | Unauthenticated functionality in CoolerControl/coolercontrold <4.0.0 allows unauthenticated attackers to view and modify potentially sensitive data via HTTP requests | |
| Analizada | Alta (7.2) | 1.5% | — | Coolercontrold | 8/4/2026 | 24/7/2026 | Command injection in alerts in CoolerControl/coolercontrold <4.0.0 allows authenticated attackers to execute arbitrary code as root via injected bash commands in alert names | |
| Analizada | Alta (8.8) | 3.4% | — | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Authenticated user can upload a malicious file to the server and execute it, which leads to remote code execution. | |
| Analizada | Crítica (9.8) | 3.2% | 💥 Exploit | Progress Sharefile Storage Zones Controller | 2/4/2026 | 17/6/2026 | Customer Managed ShareFile Storage Zones Controller (SZC) allows an unauthenticated attacker to access restricted configuration pages. This leads to changing system configuration and potential remote code execution. | |
| Pendiente de análisis | Crítica (9.8) | 0.99% | — | Cisco Integrated Management ControllerAI | 1/4/2026 | 17/6/2026 | A vulnerability in the change password functionality of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to bypass authentication and gain access to the system as Admin. This vulnerability is due to incorrect handling of password change requests. An attacker could… | |
| Analizada | Media (5.3) | 0.36% | — | Ericsson Packet Core Controller | 1/4/2026 | 17/6/2026 | Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a vulnerability where an attacker sending a large volume of specially crafted messages may cause service degradation. | |
| Analizada | Crítica (9.2) | 0.94% | — | Gigabyte Control Center | 30/3/2026 | 17/6/2026 | Gigabyte Control Center developed by GIGABYTE has an Arbitrary File Write vulnerability. When the pairing feature is enabled, unauthenticated remote attackers can write arbitrary files to any location on the underlying operating system, leading to arbitrary code execution or privilege escalation. | |
| Pendiente de análisis | Alta (7.7) | 0.11% | — | UI Unifi Network ControllerAI | 27/3/2026 | 17/6/2026 | UniFi Network Controller before version 5.10.22 and 5.11.x before 5.11.18 contains an improper certificate verification vulnerability that allows adjacent network attackers to conduct man-in-the-middle attacks by presenting a false SSL certificate during SMTP connections. Attackers can intercept SMTP traffic and… | |
| Pendiente de análisis | Crítica (9) | 0.08% | — | UI Unifi Network ControllerAIUI UAPAIUI UAP ACAIUI USWAI+1 | 27/3/2026 | 17/6/2026 | Ubiquiti UniFi Network Controller prior to 5.10.12 (excluding 5.6.42), UAP FW prior to 4.0.6, UAP-AC, UAP-AC v2, and UAP-AC Outdoor FW prior to 3.8.17, USW FW prior to 4.0.6, USG FW prior to 4.4.34 uses AES-CBC encryption for device-to-controller communication, which contains cryptographic weaknesses that allow… | |
| Pendiente de análisis | Alta (8.6) | 0.35% | — | Cisco IOS XE Wireless Controller SoftwareAI | 25/3/2026 | 17/6/2026 | A vulnerability in the processing of Control and Provisioning of Wireless Access Points (CAPWAP) packets of Cisco IOS XE Wireless Controller Software for the Catalyst CW9800 Family could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Pendiente de análisis | Crítica (9.3) | 0.57% | — | Pharoscontrols Mosaic Show ControllerAI | 24/3/2026 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in Pharos Controls Mosaic Show Controller firmware version 2.15.3 could allow an unauthenticated attacker to bypass authentication and execute arbitrary commands with root privileges. | |
| Pendiente de análisis | Alta (7.5) | 0.57% | — | Codesys ControlAI | 24/3/2026 | 17/6/2026 | An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition. | |
| Pendiente de análisis | Alta (8.8) | 0.43% | — | Codesys Control Runtime SystemAI | 24/3/2026 | 17/6/2026 | A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution. | |
| Analizada | Crítica (9.3) | 4.0% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 23/3/2026 | 17/6/2026 | Insufficient input validation in NetScaler ADC and NetScaler Gateway when configured as a SAML IDP leading to memory overread | |
| Pendiente de análisis | Alta (7.7) | 0.15% | — | Johnsoncontrols WebctrlAI | 21/3/2026 | 17/6/2026 | Under certain conditions, an attacker could bind to the same port used by WebCTRL. This could allow the attacker to craft and send malicious packets and impersonate the WebCTRL service without requiring code injection into the WebCTRL software. | |
| Pendiente de análisis | Crítica (9.1) | 0.20% | — | BacnetAIWiresharkAIJohnsoncontrols WebctrlAI | 21/3/2026 | 17/6/2026 | Service information is not encrypted when transmitted as BACnet packets over the wire, and can be sniffed, intercepted, and modified by an attacker. Valuable information such as the File Start Position and File Data can be sniffed from network traffic using Wireshark's BACnet dissector filter. The proprietary format… | |
| Analizada | Alta (8.8) | 0.60% | 💥 PoC | Kubernetes Nginx Ingress Controller | 19/3/2026 | 17/6/2026 | A security issue was discovered in ingress-nginx where a combination of Ingress annotations can be used to inject configuration into nginx. This can lead to arbitrary code execution in the context of the ingress-nginx controller, and disclosure of Secrets accessible to the controller. (Note that in the default… | |
| Pendiente de análisis | Media (4.9) | 0.49% | — | Integrated Dell Remote Access Controller 9AI | 18/3/2026 | 17/6/2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.174, 15G and 16G versions prior to 7.10.90.00, contain an Exposure of Sensitive System Information Due to Uncleared Debug Information vulnerability. A high privileged attacker with remote access could potentially exploit this vulnerability,… | |
| Pendiente de análisis | Media (5.3) | 0.28% | — | Integrated Dell Remote Access Controller 9AIIntegrated Dell Remote Access Controller 10AI | 18/3/2026 | 17/6/2026 | Dell Integrated Dell Remote Access Controller 9, 14G versions prior to 7.00.00.181, 15G and 16G versions prior to 7.20.10.50 and Dell Integrated Dell Remote Access Controller 10, 17G versions prior to 1.20.25.00, contain a Process Control vulnerability. A high privileged attacker with adjacent network access could… | |
| Aplazada | Alta (8.6) | 0.18% | — | Tinycontrol TcpduAITinycontrol Lk3.5AITinycontrol Lk3.9AITinycontrol LK4AI | 16/3/2026 | 17/6/2026 | Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 allow a low privileged user to read an administrator's password by directly accessing a specific resource inaccessible via a graphical interface. This issue has been fixed in firmware versions: 1.36 (for tcPDU), 1.67 (for LK3.5 - hardware… | |
| Aplazada | Alta (8.7) | 0.27% | — | Tinycontrol TcpduAITinycontrol LK3 5AITinycontrol LK3 9AITinycontrol LK4AI | 16/3/2026 | 17/6/2026 | Tinycontrol devices such as tcPDU and LAN Controllers LK3.5, LK3.9 and LK4 have two separate authentication mechanisms - one solely for interface management and one for protecting all other server resources. When the latter is turned off (which is a default setting), an unauthenticated attacker on the local network… | |
| Pendiente de análisis | Media (6.9) | 0.11% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for… |