Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.4) | 0.17% | — | IBM Business Automation WorkflowAI | 15/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional could allow an authenticated attacker to trigger restricted import actions due to missing authorization controls. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 15/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation 26.0.0 through 26.0.0 Interim Fix 001, 25.0.0 through 25.0.0 Interim Fix 005, 24.0.1 through 24.0.1 Interim Fix 008, and 24.0.0 through 24.0.0 Interim Fix 009 is vulnerable to an XPath injection vulnerability, which could allow an authenticated attacker to exfiltrate sensitive… | |
| Analizada | Media (5.4) | 0.20% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to HTML injection. A remote attacker could inject malicious HTML code, which when viewed, would be executed in the victim's Web browser within the security context of the hosting site. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Analizada | Media (5.4) | 0.17% | — | IBM Cloud PAK FOR Business Automation | 15/9/2026 | 23/9/2026 | IBM Cloud Pak for Business Automation is vulnerable to stored cross-site scripting. This vulnerability allows an authenticated user to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. | |
| Pendiente de análisis | Media (6.5) | 0.22% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow an authenticated user to cause a denial of service due to uncontrolled resource consumption. | |
| Pendiente de análisis | Media (5.4) | 0.18% | — | IBM Cloud PAK FOR Business AutomationAI | 14/9/2026 | 16/9/2026 | IBM Cloud Pak for Business Automation could allow a remote attacker to bypass authorization and invoke restricted endpoints due to improper validation of HTTP headers. | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Pendiente de análisis | Alta (7.1) | 0.28% | — | IBM Business Automation WorkflowAI | 14/9/2026 | 16/9/2026 | IBM Business Automation Workflow containers and traditional may use programming model artifacts that are vulnerable to XML Entity Injection attacks by default. | |
| Aplazada | Crítica (9) | 0.27% | — | Sage AR Automation APIAICash CollectAI | 9/9/2026 | 9/9/2026 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Administrative functions do not properly verify user privileges, allowing authenticated low-privileged users to create administrator accounts and obtain elevated privileges. | |
| Aplazada | Crítica (9) | 0.27% | — | Sage AR Automation APIAI | 9/9/2026 | 9/9/2026 | Cash Collect contains an improper authorization vulnerability in the Sage AR Automation API. Insufficient tenant-level authorization checks allow authenticated users to access administrative resources belonging to other tenants by specifying a valid non predictable tenant identifier. | |
| Aplazada | Media (6.1) | 0.24% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | URL redirection to untrusted site ('open redirect') vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Phishing. This issue affects Library Information and Document Automation Program: from v22.1… | |
| Aplazada | Media (5.3) | 0.19% | — | Yordam Informatics Technology Consulting Training AND Electronic Systems Industry AND Trade Library Information AND Document Automation ProgramAI | 9/9/2026 | 9/9/2026 | Server-Side request forgery (SSRF) vulnerability in Yordam Informatics Technology Consulting, Training, and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Server Side Request Forgery. This issue affects Library Information and Document Automation Program: before… | |
| Pendiente de análisis | Alta (8.7) | 0.51% | — | Inductiveautomation IgnitionAI | 4/9/2026 | 8/9/2026 | In Ignition 8.1.53 and earlier, the Gateway "Create Project Role(s)" setting shipped blank, which permitted any authenticated user to create projects (if they can execute gateway scripts). Ignition 8.1.54 restricts project creation to Designer sessions and no longer relies on this setting. The 8.3 series is not… | |
| Aplazada | Media (6.1) | 0.15% | — | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows XSS Targeting HTML Attributes. This issue affects Library… | |
| Aplazada | Media (6.1) | 0.25% | 💥 PoC | Yordam Information Technology Consulting Training AND Electronic Systems Industry AND Trade INC Library Information AND Document Automation ProgramAI | 4/9/2026 | 8/9/2026 | Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Yordam Information Technology Consulting, Training and Electronic Systems Industry and Trade Inc. Library Information and Document Automation Program allows Content Spoofing. This issue affects Library Information and… | |
| Aplazada | Alta (7) | 0.34% | — | BR Industrial Automation Gmbh Mapp AuditAIBR Industrial Automation Gmbh Mapp ServicesAI | 3/9/2026 | 3/9/2026 | Use of Weak Credentials vulnerability in B&R Industrial Automation GmbH mapp Audit used in mapp Services. This issue affects mapp Audit used in mapp Services: before 6.8.0. | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Pendiente de análisis | Media (6.4) | 0.30% | — | Redhat Ansible Automation PlatformAIAnsible AWXAI | 1/9/2026 | 24/9/2026 | A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A… | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Rockwellautomation Rslinx ClassicAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Rockwellautomation Rslinx ClassicAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Rockwellautomation Rslinx ClassicAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover. | |
| Pendiente de análisis | Crítica (9.2) | 0.43% | — | Rockwellautomation Rslinx ClassicAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover | |
| Pendiente de análisis | Alta (8.5) | 0.11% | — | Rockwellautomation Factorytalk Activation ManagerAI | 1/9/2026 | 1/9/2026 | A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack… | |
| Pendiente de análisis | Media (4.8) | 0.16% | — | Rockwellautomation Factorytalk Historian Machine EditionAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive. |