Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.8)0.90%—Sparkle-project SparkleNetapp HCI Compute NodeNetapp Oncommand Workflow Automation4/2/202517/6/2026
A security issue was found in Sparkle before version 2.6.4. An attacker can replace an existing signed update with another payload, bypassing Sparkle’s (Ed)DSA signing checks.
AnalizadaAlta (7.8)0.28%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.28%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.31%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target…
AnalizadaAlta (7)0.38%—Rockwellautomation Factorytalk Assetcentre30/1/202517/6/2026
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.
AnalizadaAlta (7.3)0.33%—Rockwellautomation Factorytalk Assetcentre30/1/202517/6/2026
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.
AnalizadaCrítica (9.3)0.37%—Rockwellautomation Factorytalk Assetcentre30/1/202517/6/2026
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.
AplazadaAlta (7)0.39%—Rockwellautomation Datamosaix Private CloudAI28/1/202517/6/2026
A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this…
AnalizadaMedia (6.2)0.18%—IBM Automation Decision Services26/1/202517/6/2026
IBM Automation Decision Services 23.0.2 allows web pages to be stored locally which can be read by another user on the system.
AnalizadaMedia (5.4)0.21%—IBM Robotic Process Automation FOR Cloud PAK22/1/202517/6/2026
IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 is vulnerable to cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure…
AnalizadaMedia (4.8)1.0%—Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+721/1/202517/6/2026
Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u431-perf, 11.0.25, 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM for JDK: 17.0.13, 21.0.5, 23.0.1; Oracle GraalVM…
AnalizadaMedia (4.9)0.96%—Oracle Mysql ServerNetapp Active IQ Unified ManagerNetapp Oncommand InsightNetapp Oncommand Workflow Automation21/1/202517/6/2026
Vulnerability in the MySQL Server product of Oracle MySQL (component: Server: Optimizer). Supported versions that are affected are 8.0.36 and prior and 8.4.0. Easily exploitable vulnerability allows high privileged attacker with network access via multiple protocols to compromise MySQL Server. Successful attacks of…
AnalizadaMedia (6.5)0.33%—IBM Robotic Process AutomationIBM Robotic Process Automation FOR Cloud PAK18/1/202517/6/2026
IBM Robotic Process Automation 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 and IBM Robotic Process Automation for Cloud Pak 21.0.0 through 21.0.7.18 and 23.0.0 through 23.0.18 could allow an authenticated user to perform unauthorized actions as a privileged user due to improper validation of client-side…
AnalizadaMedia (6.7)0.15%—IBM Robotic Process Automation18/1/202517/6/2026
IBM Robotic Process Automation 21.0.0 through 21.0.7.17 and 23.0.0 through 23.0.18 could allow a local user to escalate their privileges. All files in the install inherit the file permissions of the parent directory and therefore a non-privileged user can substitute any executable for the nssm.exe service. A…
AplazadaAlta (8.2)0.34%—B R Automation Mapp ViewAIBr-automation Automation RuntimeAI15/1/202517/6/2026
A “Use of a Broken or Risky Cryptographic Algorithm” vulnerability in the SSL/TLS component used in B&R Automation Runtime versions before 6.1 and B&R mapp View versions before 6.1 may be abused by unauthenticated network-based attackers to masquerade as services on impacted devices.
AplazadaMedia (6.6)0.66%—Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAI14/1/202517/6/2026
Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products.
AnalizadaMedia (5.9)0.28%—IBM Robotic Process Automation12/1/202517/6/2026
IBM Robotic Process Automation 21.0.0 through 21.0.7.19 and 23.0.0 through 23.0.19 could allow a remote attacker to obtain sensitive data that may be exposed through certain crypto-analytic attacks.
AplazadaMedia (4.3)0.26%—Vmware Aria AutomationAI8/1/202517/6/2026
VMware Aria Automation contains a server-side request forgery (SSRF) vulnerability. A malicious actor with "Organization Member" access to Aria Automation may exploit this vulnerability enumerate internal services running on the host/network.
AnalizadaAlta (7.2)1.0%—IBM Websphere Automation30/12/202417/6/2026
IBM WebSphere Automation 1.7.5 could allow a remote privileged user, who has authorized access to the swagger UI, to execute arbitrary code. Using specially crafted input, the user could exploit this vulnerability to execute arbitrary code on the system.
AplazadaCrítica (9.9)0.61%—Arne Informatics Piramit AutomationAI25/12/202417/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Arne Informatics Piramit Automation allows Blind SQL Injection. This issue affects Piramit Automation: before 27.09.2024.
AnalizadaAlta (8.5)0.22%—Rockwellautomation Arena19/12/202417/6/2026
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute…
ModificadaAlta (8.5)0.25%—Rockwellautomation Arena19/12/202417/6/2026
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this…
AnalizadaAlta (8.5)0.34%—Rockwellautomation Arena19/12/202417/6/2026
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code.…
ModificadaAlta (8.5)0.23%—Rockwellautomation Arena19/12/202417/6/2026
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute…
AnalizadaMedia (4.6)0.24%—IBM Robotic Process Automation19/12/202417/6/2026
IBM Robotic Process Automation 21.0.1, 21.0.2, and 21.0.3 could allow a user with psychical access to the system to obtain sensitive information due to insufficiently protected credentials.