Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2493▼ 464 respecto a la semana anterior
Críticas / altas1281▼ 12 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)60▼ 468 respecto a la semana anterior
2298 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.57% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. | |
| Analizada | Alta (8.1) | 0.44% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service. | |
| Analizada | Crítica (9.8) | 0.42% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Crítica (9.8) | 0.23% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | |
| En análisis | Alta (8.8) | 0.20% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Analizada | Media (6.5) | 0.58% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service. | |
| Analizada | Crítica (9.8) | 0.45% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Analizada | Crítica (9.8) | 0.67% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure. | |
| Analizada | Media (6.5) | 0.58% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Pendiente de análisis | Media (5.9) | 0.16% | — | IBM ControllerAI | 18/9/2026 | 19/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | IBM ControllerAI | 18/9/2026 | 18/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size. | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | IBM ControllerAI | 18/9/2026 | 19/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Aplazada | Crítica (9.2) | 0.29% | — | ABB Freelance Controller DCPAIABB Freelance Controller Ac700AIABB Freelance Controller Ac800AIABB Freelance Controller Ac900AI | 18/9/2026 | 18/9/2026 | Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance… | |
| Aplazada | Media (5.3) | 0.45% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | |
| Aplazada | Alta (8.7) | 1.9% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.1) | 0.26% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (6.9) | 0.47% | — | Tp-link Omada ControllerAI | 11/9/2026 | 11/9/2026 | An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized… | |
| Aplazada | Media (5.3) | 0.46% | — | Flux Source ControllerAIKubernetesAIFlux Kustomize ControllerAIFlux Helm ControllerAI | 8/9/2026 | 30/9/2026 | The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influence the contents of a bucket referenced by a `Bucket` resource can cause… | |
| Aplazada | Media (6.9) | 0.67% | — | Tp-link Omada ControllerAI | 8/9/2026 | 21/9/2026 | An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the… | |
| Pendiente de análisis | Alta (8.7) | 0.50% | — | Nginx Ingress ControllerAI | 2/9/2026 | 3/9/2026 | When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to… | |
| Analizada | Baja (2.3) | 0.23% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 2/9/2026 | 15/9/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Infinitumform GEO ControllerAI | 27/8/2026 | 28/8/2026 | Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions. | |
| Pendiente de análisis | Alta (7.7) | 0.63% | — | Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI | 21/8/2026 | 29/9/2026 | A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's… | |
| Pendiente de análisis | Media (6.2) | 0.54% | — | Volsync Addon-controllerAIRedhat Openshift Lifecycle ManagerAI | 19/8/2026 | 8/9/2026 | A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful… | |
| Analizada | Crítica (9.3) | 23% | ⚠ Explotación activa | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 19/8/2026 | 10/9/2026 | Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21. |