Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

69 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)64%—Inductiveautomation Ignition3/5/202417/6/2026
Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this…
AnalizadaAlta (8.8)0.62%—Inductiveautomation Ignition3/5/202417/6/2026
Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a…
AnalizadaAlta (8.8)62%—Inductiveautomation Ignition3/5/202417/6/2026
Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The…
AnalizadaMedia (6.5)1.3%—Inductiveautomation Ignition3/5/202417/6/2026
Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The…
AnalizadaAlta (8.8)60%—Inductiveautomation Ignition3/5/202417/6/2026
Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability.…
AnalizadaAlta (8.8)1.2%—Inductiveautomation Ignition3/5/202417/6/2026
Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability…
AnalizadaAlta (7.2)1.9%—Inductiveautomation Ignition3/5/202417/6/2026
Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Although authentication is required to exploit this vulnerability, the…
AnalizadaCrítica (9)1.2%—Inductiveautomation Ignition3/5/202417/6/2026
Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must…
ModificadaAlta (8.8)0.24%—Saleswonder Webinarignition15/4/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition.This issue affects WebinarIgnition: from n/a through <= 3.05.8.
ModificadaCrítica (9.8)0.57%—Saleswonder Webinarignition31/12/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream &…
ModificadaAlta (8.8)0.62%—Saleswonder Webinarignition29/12/202317/6/2026
Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through…
AnalizadaMedia (4.8)0.39%—Saleswonder Webinarignition7/4/202317/6/2026
Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saleswonder.Biz Webinar ignition plugin <= 2.14.2 versions.
ModificadaCrítica (9.8)1.0%—Inductiveautomation Ignition5/8/202217/6/2026
Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup.
ModificadaAlta (7.8)0.71%—Inductiveautomation Ignition25/7/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaAlta (7.8)0.70%—Inductiveautomation Ignition25/7/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the…
ModificadaAlta (7.8)39%—Inductiveautomation Ignition25/7/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within the authenticateAdSso method. The issue results from the lack of…
ModificadaAlta (7.8)43%—Inductiveautomation Ignition25/7/202217/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within…
ModificadaCrítica (9.8)60%—Inductiveautomation Ignition25/7/202217/6/2026
This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from…
ModificadaAlta (8.8)0.97%—Inductiveautomation Ignition20/7/202217/6/2026
The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code.
ModificadaAlta (7.2)2.7%—Inductiveautomation Ignition16/7/202217/6/2026
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script.
ModificadaCrítica (9.8)2.0%—Inductiveautomation Ignition15/7/202217/6/2026
An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy.
ModificadaMedia (6.5)1.3%—Redhat IgnitionRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora17/5/202217/6/2026
A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible…
ModificadaMedia (5.3)0.89%—Inductiveautomation Ignition1/4/202217/6/2026
Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server
ModificadaCrítica (9.8)1.7%—Facade Ignition17/11/202117/6/2026
The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control.
ModificadaCrítica (9.1)3.9%—Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+612/4/202117/6/2026
Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes…