Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
4320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.33% | — | Carrier Zone ControllerAIAutomatedlogic Zone ControllerAI | 27/11/2025 | 17/6/2026 | A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can leave it permanently unresponsive until a manual power cycle is performed. | |
| Aplazada | Alta (8.5) | 0.13% | — | Asus System Control InterfaceAI | 25/11/2025 | 17/6/2026 | A local privilege escalation vulnerability exists in the restore mechanism of ASUS System Control Interface. It can be triggered when an unprivileged actor copies files without proper validation into protected system paths, potentially leading to arbitrary files being executed as SYSTEM. For more information, please… | |
| Aplazada | Crítica (9.3) | 0.46% | — | Seiko Epson Epson WEB ControlAIEpson WebconfigAI | 21/11/2025 | 17/6/2026 | EPSON WebConfig and Epson Web Control for SEIKO EPSON Projector Products do not restrict excessive authentication attempts. An administrative user's password may be identified through a brute force attack. | |
| Analizada | Alta (7.5) | 0.69% | — | Haproxy Aloha ApplianceHaproxyHaproxy EnterpriseHaproxy Kubernetes Ingress Controller | 19/11/2025 | 17/6/2026 | Inefficient algorithm complexity in mjson in HAProxy allows remote attackers to cause a denial of service via specially crafted JSON requests. | |
| Analizada | Crítica (9.8) | 0.24% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+5 | 18/11/2025 | 17/6/2026 | A missing authentication enforcement vulnerability exists in the mutual TLS (mTLS) implementation used by System REST APIs and SOAP services in multiple WSO2 products. Due to improper validation of client certificate–based authentication in certain default configurations, the affected components may permit… | |
| Analizada | Alta (8.8) | 0.23% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Enterprise IntegratorWso2 Identity Server+5 | 18/11/2025 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability exists in multiple WSO2 products due to the use of the HTTP GET method for state-changing operations within admin services, specifically in the event processor of the Carbon console. Although the SameSite=Lax cookie attribute is used as a mitigation, it is ineffective… | |
| Aplazada | Baja (2.4) | 0.16% | — | Johnsoncontrols Command Centre ServerAIJohnsoncontrols T21 ReaderAI | 18/11/2025 | 17/6/2026 | Missing Release of Resource after Effective Lifetime (CWE-772) in the T21 Reader allows an attacker with physical access to the Reader to perform a denial-of-service attack against that specific reader, preventing cardholders from badging for entry. This issue affects Command Centre Server: 9.30 prior to… | |
| Aplazada | Alta (8.8) | 0.27% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the CvManager functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to memory corruption. An attacker can issue an api call to trigger this vulnerability. | |
| Aplazada | Alta (7.3) | 0.16% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.14% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.14% | — | Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (7.3) | 0.16% | — | Dell Controlvault3AIDell Controlvault3 PlusAIBroadcom Storage AdapterAI | 17/11/2025 | 17/6/2026 | Multiple out-of-bounds read and write vulnerabilities exist in the ControlVault WBDI Driver Broadcom Storage Adapter functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to memory corruption. An attacker can issue an… | |
| Aplazada | Alta (8.8) | 0.31% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A buffer overflow vulnerability exists in the CvManager_SBI functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to a arbitrary code execution. An attacker can issue an api call to trigger this vulnerability. | |
| Aplazada | Alta (8.7) | 0.24% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A hard-coded password vulnerability exists in the ControlVault WBDI Driver functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted ControlVault API call can lead to execute priviledged operation. An attacker can issue an api call to trigger this… | |
| Aplazada | Alta (8.7) | 0.22% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 17/11/2025 | 17/6/2026 | A privilege escalation vulnerability exists in the ControlVault WBDI Driver WBIO_USH_ADD_RECORD functionality of Dell ControlVault3 prior to 5.15.14.19 and Dell ControlVault3 Plus prior to 6.2.36.47. A specially crafted WinBioControlUnit call can lead to privilege escalation. An attacker can issue an api call to… | |
| Aplazada | Crítica (9.2) | 0.63% | — | General Industrial Controls Lynx+ GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device. | |
| Aplazada | Alta (7.1) | 0.21% | — | Jenkins Mission ControlAI | 14/11/2025 | 7/10/2026 | The Brightpick Mission Control web application exposes hardcoded credentials in its client-side JavaScript bundle to Brightpick AI's documentation portal. | |
| Aplazada | Alta (7.1) | 0.23% | — | Brightpick Internal Logic ControlAI | 14/11/2025 | 7/10/2026 | The Brightpick Internal Logic Control web interface is accessible without requiring user authentication. An unauthorized user could exploit this interface to manipulate robot control functions, including initiating or halting runners, assigning jobs, clearing stations, and deploying storage totes. | |
| Aplazada | Alta (8.7) | 0.31% | — | General Industrial Controls Lynx Plus GatewayAI | 14/11/2025 | 7/10/2026 | General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials. | |
| Aplazada | Alta (8.7) | 0.37% | — | General Industrial Controls Lynx+ GatewayAI | 14/11/2025 | 7/10/2026 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information. | |
| Aplazada | Alta (8.8) | 0.28% | — | General Industrial Controls Lynx Plus GatewayAI | 14/11/2025 | 7/10/2026 | General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login. | |
| Analizada | Alta (7.5) | 0.32% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 17/6/2026 | External control of file name or path in certain Zoom Clients may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Analizada | Alta (7.5) | 0.27% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 13/11/2025 | 7/10/2026 | Improper removal of sensitive information in certain Zoom Clients before version 6.5.10 may allow an unauthenticated user to conduct a disclosure of information via network access. | |
| Aplazada | Alta (8.7) | 0.91% | — | Tinycontrol LAN Controller V3AI | 12/11/2025 | 17/6/2026 | Tinycontrol LAN Controller v3 (LK3) firmware versions up to 1.58a (hardware v3.8) contain a missing authentication vulnerability in the stm.cgi endpoint. A remote, unauthenticated attacker can send crafted requests to forcibly reboot the device or restore factory settings, leading to a denial of service and… | |
| Analizada | Crítica (9.8) | 1.2% | — | Magdesign Pocketvj Control Panel Firmware | 5/11/2025 | 17/6/2026 | PocketVJ CP PocketVJ-CP-v3 pvj version 3.9.1 contains an unauthenticated remote code execution vulnerability in the submit_opacity.php component. The application fails to sanitize user input in the opacityValue POST parameter before passing it to a shell command, allowing remote attackers to execute arbitrary commands… |