Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
4320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.9) | 0.11% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Out-of-Bounds Read vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to a disclosure of kernel information or a system crash. Refer to the "Security Update for… | |
| Pendiente de análisis | Media (6.8) | 0.10% | — | Asus Business System Control Interface DriverAI | 12/3/2026 | 17/6/2026 | An Incorrect Permission Assignment vulnerability exists in the ASUS Business System Control Interface driver. This vulnerability can be triggered by an unprivileged local user sending a specially crafted IOCTL request, potentially leading to unauthorized access to sensitive hardware resources and kernel information… | |
| Analizada | Alta (7) | 0.33% | — | Schneider-electric Ecostruxure Foxboro DCS Control Software | 10/3/2026 | 24/6/2026 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file. | |
| Analizada | Baja (1.9) | 0.18% | 💥 PoC | Qianxin QAX Internet Control Gateway | 9/3/2026 | 17/6/2026 | A weakness has been identified in Qi-ANXIN QAX Virus Removal up to 2025-10-22. The affected element is the function ZwTerminateProcess in the library QKSecureIO_Imp.sys of the component Mini Filter Driver. Executing a manipulation can lead to improper access controls. The attack is restricted to local execution. The… | |
| Modificada | Media (6.9) | 0.23% | — | Johnsoncontrols Frick Controls Quantum HD Firmware | 27/2/2026 | 24/8/2026 | A Hardcoded Email Credentials Saved as Plaintext in Firmware (CWE-256: Plaintext Storage of a Password) vulnerability in Frick Controls Quantum HD version 10.22 and prior lead to unauthorized access, exposure of sensitive information, and potential misuse or system compromise This issue affects Frick Controls Quantum… | |
| Analizada | Alta (8.7) | 0.92% | — | Johnsoncontrols Frick Controls Quantum HD Firmware | 27/2/2026 | 17/6/2026 | Unauthenticated Remote Code Execution and Information Disclosure due to Local File Inclusion (LFI) vulnerability in Johnson Controls Frick Controls Quantum HD allow an unauthenticated attacker to execute arbitrary code on the affected device, leading to full system compromise. This issue affects Frick Controls Quantum… | |
| Analizada | Alta (8.8) | 0.64% | — | Johnsoncontrols Frick Controls Quantum HD Firmware | 27/2/2026 | 17/6/2026 | Unauthenticated Remote Code Execution i.e Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device… | |
| Analizada | Alta (8.8) | 0.40% | — | Johnsoncontrols Frick Controls Quantum HD Firmware | 27/2/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue… | |
| Analizada | Alta (8.8) | 0.40% | — | Johnsoncontrols Frick Controls Quantum HD Firmware | 27/2/2026 | 17/6/2026 | Improper Control of Generation of Code ('Code Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows Code Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before authentication occurs.This issue… | |
| Analizada | Alta (8.8) | 1.5% | — | Johnsoncontrols Frick Controls Quantum HD Firmware | 27/2/2026 | 17/6/2026 | Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Johnson Controls Frick Controls Quantum HD allows OS Command Injection. Insufficient validation of input in certain parameters may permit unexpected actions, which could impact the security of the device before… | |
| Analizada | Crítica (10) | 88% | ⚠ Explotación activa💥 PoC | Cisco Catalyst Sd-wan ManagerCisco Sd-wan Vbond OrchestratorCisco Sd-wan Vsmart Controller | 25/2/2026 | 17/6/2026 | A vulnerability in the peering authentication in Cisco Catalyst SD-WAN Controller, formerly SD-WAN vSmart, Cisco Catalyst SD-WAN Manager, formerly SD-WAN vManage, and Cisco Catalyst SD-WAN Validator, formerly SD-WAN vBond, could allow an unauthenticated, remote attacker to bypass authentication and obtain… | |
| Aplazada | Media (5.5) | 0.09% | — | Cisco Application Policy Infrastructure ControllerAI | 25/2/2026 | 17/6/2026 | A vulnerability in the Object Model CLI component of Cisco Application Policy Infrastructure Controller (APIC) could allow an authenticated, local attacker to cause an affected device to reload unexpectedly, resulting in a denial of service (DoS) condition. To exploit this vulnerability, the attacker must have valid… | |
| Modificada | Alta (7.2) | 0.70% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway | 19/2/2026 | 18/6/2026 | A malicious actor with administrative privileges can upload an arbitrary file to a user-controlled location within the deployment via a system REST API. Successful uploads may lead to remote code execution. By leveraging the vulnerability, a malicious actor may perform Remote Code Execution by uploading a specially… | |
| Aplazada | Alta (8.4) | 0.20% | — | Control Center PROAI | 18/2/2026 | 17/6/2026 | Control Center PRO 6.2.9 contains a stack-based buffer overflow vulnerability in the user creation module's username field that allows attackers to overwrite Structured Exception Handler (SEH). Attackers can craft a malicious payload exceeding 664 bytes to inject shellcode and potentially execute arbitrary code on… | |
| Analizada | Media (6) | 0.26% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Out-of-bounds read in the firmware for some 100GbE Intel(R) Ethernet Network Adapter E810 before version cvl fw 1.7.6, cpk 1.3.7 within Ring 0: Bare Metal OS may allow a denial of service. Network adversary with an authenticated user combined with a low complexity attack may enable denial of service. This result may… | |
| Analizada | Media (5.6) | 0.10% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service.… | |
| Analizada | Media (6.7) | 0.12% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur… | |
| Analizada | Media (6.7) | 0.12% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Alta (8.5) | 0.18% | — | Alps Pointing-device ControllerAI | 5/2/2026 | 17/6/2026 | Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the… | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.2) | 0.39% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+1 | 4/2/2026 | 17/6/2026 | A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response… | |
| Aplazada | Crítica (9.3) | 1.3% | — | AircontrolAI | 30/1/2026 | 17/6/2026 | AirControl 1.4.2 contains a pre-authentication remote code execution vulnerability that allows unauthenticated attackers to execute arbitrary system commands through malicious Java expression injection. Attackers can exploit the /.seam endpoint by crafting a specially constructed URL with embedded Java expressions to… | |
| Aplazada | Crítica (9.5) | 1.5% | — | Johnsoncontrols Metasys Application AND Data ServerAIJohnsoncontrols Metasys Extended Application AND Data ServerAIJohnsoncontrols Lcs8500AIJohnsoncontrols Nae8500AI+2 | 30/1/2026 | 17/6/2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects | |
| Analizada | Alta (8.8) | 0.75% | — | Craftycontrol Crafty Controller | 30/1/2026 | 17/6/2026 | An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. | |
| Analizada | Alta (8.8) | 0.66% | — | Craftycontrol Crafty Controller | 30/1/2026 | 17/6/2026 | An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. |