Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4531 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.1) | 0.55% | — | Autodesk Fusion | 22/1/2026 | 17/6/2026 | A maliciously crafted HTML payload, stored in a part’s attribute and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute arbitrary code in the context of the current… | |
| Modificada | Alta (8.1) | 0.69% | — | Autodesk Fusion | 22/1/2026 | 17/6/2026 | A maliciously crafted HTML payload in a design name, when displayed during the delete confirmation dialog and clicked by a user, can trigger a Stored Cross-site Scripting (XSS) vulnerability in the Autodesk Fusion desktop application. A malicious actor may leverage this vulnerability to read local files or execute… | |
| Aplazada | Alta (7) | 0.16% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 22/1/2026 | 17/6/2026 | Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to access stored passwords in a recoverable format which makes them… | |
| Analizada | Media (5.5) | 0.10% | — | IBM Business Automation Workflow | 20/1/2026 | 17/6/2026 | IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation could allow a local user with access to the container to execute OS system calls. | |
| Analizada | Media (5.5) | 0.13% | — | IBM Business Automation Workflow | 20/1/2026 | 17/6/2026 | IBM Business Automation Workflow containers 25.0.0 through 25.0.0 Interim Fix 002, 24.0.1 through 24.0.1 Interim Fix 005, and 24.0.0 through 24.0.0 Interim Fix 006. IBM Cloud Pak for Business Automation and IBM Business Automation Workflow containers may disclose sensitve configuration information in a config map. | |
| Analizada | Alta (8.7) | 0.64% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.48% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.39% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive. | |
| Analizada | Alta (8.7) | 0.60% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.60% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.60% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots | |
| Analizada | Alta (8.7) | 0.48% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot. | |
| Analizada | Alta (8.7) | 0.60% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds. | |
| Analizada | Alta (8.7) | 0.48% | — | Rockwellautomation Armorstart LT Firmware | 20/1/2026 | 17/6/2026 | A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible. | |
| Aplazada | Alta (8.9) | 0.36% | — | Br-automation Automation RuntimeAI | 19/1/2026 | 17/6/2026 | An Allocation of Resources Without Limits or Throttling vulnerability in the ANSL-Server component of B&R Automation Runtime versions prior to 6.5 and prior to R4.93 could be exploited by an unauthenti-cated attacker on the network to win a race condition, resulting in permanent denial-of-service (DoS) conditions on… | |
| Aplazada | Crítica (9.1) | 0.23% | — | Beckhoff Automation StudioAI | 19/1/2026 | 17/6/2026 | An Improper Certificate Validation vulnerability in the OPC-UA client and ANSL over TLS client used in Automation Studio versions before 6.5 could allow an unauthenticated attacker on the network to position themselves to intercept and interfere with data exchanges. | |
| Modificada | Media (6.5) | 0.40% | — | Connectwise Professional Service Automation | 16/1/2026 | 17/6/2026 | In ConnectWise PSA versions older than 2026.1, certain session cookies were not set with the HttpOnly attribute. In some scenarios, this could allow client-side scripts access to session cookie values. | |
| Modificada | Media (5.4) | 0.28% | — | Connectwise Professional Service Automation | 16/1/2026 | 17/6/2026 | In ConnectWise PSA versions older than 2026.1, Time Entry notes stored in the Time Entry Audit Trail may be rendered without applying output encoding to certain content. Under specific conditions, this may allow stored script code to execute in the context of a user’s browser when the affected content is displayed. | |
| Analizada | Media (5.1) | 0.28% | — | Juniper Paragon Automation | 15/1/2026 | 17/6/2026 | A clickjacking vulnerability exists in the web portal of Juniper Networks Paragon Automation (Pathfinder, Planner, Insights) due to the application's failure to set appropriate X-Frame-Options and X-Content-Type HTTP headers. This vulnerability allows an attacker to trick users into interacting with the interface… | |
| Analizada | Media (5.1) | 0.29% | — | Automattic Jetpack | 13/1/2026 | 17/6/2026 | Jetpack 11.4 contains a cross-site scripting vulnerability in the contact form module that allows attackers to inject malicious scripts through the post_id parameter. Attackers can craft malicious URLs with script payloads to execute arbitrary JavaScript in victims' browsers when they interact with the contact form… | |
| Analizada | Crítica (9.8) | 0.51% | — | Automai Botmanager | 12/1/2026 | 17/6/2026 | An issue in Automai BotManager v.25.2.0 allows a remote attacker to execute arbitrary code via the BotManager.exe component | |
| Analizada | Alta (8.8) | 0.54% | — | Automai Director | 12/1/2026 | 17/6/2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to execute arbitrary code via the update mechanism | |
| Analizada | Alta (8.2) | 0.30% | — | Automai Director | 12/1/2026 | 17/6/2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges and obtain sensitive information via a crafted js file | |
| Analizada | Crítica (9.9) | 0.34% | — | Automai Director | 12/1/2026 | 17/6/2026 | An issue in Automai Director v.25.2.0 allows a remote attacker to escalate privileges | |
| Aplazada | Alta (7.5) | 0.34% | — | Automattic Woocommerce SquareAI | 10/1/2026 | 17/6/2026 | The WooCommerce Square plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 5.1.1 via the get_token_by_id function due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to expose arbitrary Square "ccof" (credit… |