Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

2318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.2)0.23%—Projectfloodlight Open SDN Controller1/11/202417/6/2026
Floodlight SDN Open Flow Controller v.1.2 has an issue that allows local hosts to build fake LLDP packets that allow specific clusters to be missed by Floodlight, which in turn leads to missed hosts inside and outside the cluster.
AplazadaAlta (8.4)0.19%—Yamaha Headphones ControllerAI24/10/202417/6/2026
Incorrect access control in the firmware update and download processes of Yamaha Headphones Controller v1.6.7 allows attackers to access sensitive information by analyzing the code and data within the APK file.
AnalizadaAlta (8.6)11%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+1716/10/202417/6/2026
BIG-IP monitor functionality may allow an attacker to bypass access control restrictions, regardless of the port lockdown settings. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AplazadaMedia (5.9)0.27%—Plainware ShiftcontrollerAI6/10/202417/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in plainware ShiftController Employee Shift Scheduling shiftcontroller allows Stored XSS.This issue affects ShiftController Employee Shift Scheduling: from n/a through <= 4.9.64.
AnalizadaMedia (6.1)0.39%—Plainware Shiftcontroller4/10/202417/6/2026
The ShiftController Employee Shift Scheduling plugin for WordPress is vulnerable to Reflected Cross-Site Scripting via URL keys in all versions up to, and including, 4.9.66 due to insufficient input sanitization and output escaping. This makes it possible for unauthenticated attackers to inject arbitrary web scripts…
AnalizadaAlta (8.6)0.29%—Cisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator2/10/202417/6/2026
A vulnerability in a logging function of Cisco Nexus Dashboard Insights could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because remote controller credentials are recorded in an internal log that is stored in the tech support file. An attacker could…
AnalizadaAlta (8.6)0.29%—Cisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator2/10/202417/6/2026
A vulnerability in a logging function of Cisco Nexus Dashboard Fabric Controller (NDFC) and Cisco Nexus Dashboard Orchestrator (NDO) could allow an attacker with access to a tech support file to view sensitive information. This vulnerability exists because HTTP proxy credentials could be recorded in an internal log…
AnalizadaMedia (5.4)0.45%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to upload or delete files on an affected device. This vulnerability exists because of missing authorization controls on the affected REST API endpoint. An attacker could exploit this…
AnalizadaAlta (8.8)0.95%—Cisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, remote attacker with low privileges to execute arbitrary code on an affected device. This vulnerability is due to improper path validation. An attacker could exploit this vulnerability by using the Secure Copy Protocol…
AnalizadaAlta (8.6)0.12%—Cisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the Cisco Nexus Dashboard Fabric Controller (NDFC) software, formerly Cisco Data Center Network Manager (DCNM), could allow an attacker with access to a backup file to view sensitive information. This vulnerability is due to the improper storage of sensitive information within config only and full…
AnalizadaMedia (5.5)0.76%—Cisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in Cisco Nexus Dashboard Fabric Controller (NDFC), formerly Cisco Data Center Network Manager (DCNM), could allow an authenticated, remote attacker with network-admin privileges to perform a command injection attack against an affected device. &nbsp; This vulnerability is due to insufficient validation…
AnalizadaMedia (5.4)0.36%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the REST API endpoints of Cisco Nexus Dashboard could allow an authenticated, low-privileged, remote attacker to perform limited Administrator actions on an affected device. This vulnerability is due to insufficient authorization controls on some REST API endpoints. An attacker could exploit this…
AnalizadaMedia (6.5)0.49%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in a specific REST API endpoint of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to learn sensitive information on an affected device. This vulnerability is due to insufficient authorization controls on the affected REST API endpoint. An attacker could exploit this…
AnalizadaMedia (5.4)0.36%—Cisco Nexus DashboardCisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the REST API endpoints of Cisco NDFC could allow an authenticated, low-privileged, remote attacker to read or write files on an affected device. This vulnerability exists because of missing authorization controls on some REST API endpoints. An attacker could exploit this vulnerability by sending…
AnalizadaAlta (8.8)1.1%—Cisco Nexus Dashboard Fabric Controller2/10/202417/6/2026
A vulnerability in the REST API and web UI of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an authenticated, low-privileged, remote attacker to perform a command injection attack against an affected device. &nbsp; This vulnerability is due to improper user authorization and insufficient validation of…
AnalizadaMedia (5.3)0.48%—Aimeos Frontend Controller26/9/202417/6/2026
aimeos/ai-controller-frontend is the Aimeos frontend controller package for e-commerce projects. Prior to versions 2024.4.2, 2023.10.9, 2022.10.8, 2021.10.8, and 2020.10.15, an insecure direct object reference allows an attacker to disable subscriptions and reviews of another customer. Versions 2024.4.2, 2023.10.9,…
AnalizadaCrítica (9.8)1.2%💥 PoCSPX Graphics Controller16/9/202417/6/2026
An issue in TuomoKu SPx-GC v.1.3.0 and before allows a remote attacker to execute arbitrary code via the child_process.js function.
AplazadaMedia (6.6)0.43%—Ansible Automation ControllerAI12/9/202417/6/2026
An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account.
AplazadaMedia (4.6)0.23%—Salto Controller 6000AISalto Controller 7000AI11/9/202417/6/2026
Incorrect Calculation of Buffer Size (CWE-131) in the Controller 6000 and Controller 7000 OSDP message handling, allows an attacker with physical access to Controller wiring to instigate a reboot leading to a denial of service. This issue affects: Controller 6000 and Controller 7000 9.10 prior to vCR9.10.240816a…
AplazadaMedia (6.5)0.34%—Gallagher Controller 6000AIGallagher Controller 7000AI11/9/202417/6/2026
Buffer Copy without Checking Size of Input (CWE-120) in the Controller 6000 and Controller 7000 diagnostic web interface allows an authorised and authenticated operator to reboot the Controller, causing a Denial of Service. Gallagher recommend the diagnostic web page is not enabled (default is off) unless advised by…
AplazadaMedia (6.1)0.28%—Controller 6000AIController 7000AI11/9/202417/6/2026
Improper Neutralization of Input During Web Page Generation (CWE-79) in the Controller 6000 and Controller 7000 diagnostic webpage allows an attacker to modify Controller configuration during an authenticated Operator's session. This issue affects: Controller 6000 and Controller 7000 9.10 prior to vCR9.10.240816a…
AplazadaAlta (7.5)0.59%—Forklift ControllerAI6/9/202417/6/2026
A vulnerability was found in Forklift Controller. There is no verification against the authorization header except to ensure it uses bearer authentication. Without an Authorization header and some form of a Bearer token, a 401 error occurs. The presence of a token value provides a 200 response with the requested…
ModificadaMedia (5.3)0.34%—Infinitumform GEO Controller5/9/202417/6/2026
The Geo Controller plugin for WordPress is vulnerable to unauthorized shortcode execution due to missing authorization and capability checks on the ajax__shortcode_cache function in all versions up to, and including, 8.6.9. This makes it possible for unauthenticated attackers to execute arbitrary shortcodes available…
ModificadaMedia (4.3)0.26%—Infinitumform GEO Controller5/9/202417/6/2026
The Geo Controller plugin for WordPress is vulnerable to unauthorized menu creation/deletion due to missing capability checks on the ajax__geolocate_menu and ajax__geolocate_remove_menu functions in all versions up to, and including, 8.7.3. This makes it possible for authenticated attackers, with Subscriber-level…
AnalizadaAlta (7.2)0.74%—Cisco Application Policy Infrastructure Controller28/8/202417/6/2026
A vulnerability in the software upgrade component of Cisco Application Policy Infrastructure Controller (APIC) and Cisco&nbsp;Cloud Network Controller, formerly Cisco Cloud APIC, could allow an authenticated, remote attacker with Administrator-level privileges to install a modified software image, leading to arbitrary…