Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.85% | — | Ksix Zigbee Gateway ModuleAIKsix Door SensorAIKsix Motion SensorAI | 15/4/2025 | 17/6/2026 | A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless… | |
| Aplazada | Media (5.3) | 0.63% | — | Comotion Course Booking SystemAI | 4/4/2025 | 17/6/2026 | Missing Authorization vulnerability in ComMotion Course Booking System course-booking-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Course Booking System: from n/a through <= 6.1. | |
| Aplazada | Alta (7.1) | 0.39% | — | Emotionalonlinestorytelling Oracle Cards LiteAI | 1/4/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinestorytelling Oracle Cards Lite oracle-cards allows Reflected XSS.This issue affects Oracle Cards Lite: from n/a through <= 1.2.1. | |
| Aplazada | Crítica (9.3) | 2.9% | — | Commotion Course Booking SystemAI | 15/1/2025 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course Booking System course-booking-system allows SQL Injection.This issue affects Course Booking System: from n/a through <= 6.0.6. | |
| Aplazada | Alta (7) | 0.18% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic Step 7 SafetyAISiemens Simatic WinccAI+8 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4), SIMATIC STEP 7 V17 (All versions < V17 Update… | |
| Aplazada | Alta (8.4) | 0.22% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+7 | 10/12/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4),… | |
| Aplazada | Alta (8.4) | 0.49% | — | B&R Mapp CockpitAIB&R Mapp ViewAIB&R Mapp ServicesAIB&R Mapp MotionAI+1 | 2/12/2024 | 17/6/2026 | An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based… | |
| Aplazada | Alta (7) | 0.22% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+7 | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 5), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP… | |
| Aplazada | Media (5.4) | 0.32% | — | Creative Motion Clearfy CacheAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4. | |
| Aplazada | Media (4.3) | 0.39% | — | Creativemotion Social Slider FeedAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2. | |
| Aplazada | Media (6.5) | 0.50% | — | Creative Motion Robin Image OptimizerAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in Creative Motion Robin image optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robin image optimizer: from n/a through 1.6.9. | |
| Aplazada | Media (6.5) | 0.49% | — | Creativemotion Titan Anti-spam SecurityAI | 1/11/2024 | 17/6/2026 | Missing Authorization vulnerability in CreativeMotion Titan Anti-spam & Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Titan Anti-spam & Security: from n/a through 7.3.6. | |
| Aplazada | Alta (7) | 0.21% | — | Siemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAISiemens Simatic WinccAI+7 | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 7), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2), SIMATIC STEP 7 V16 (All versions < V16 Update 7), SIMATIC STEP 7 V17 (All versions < V17 Update 7), SIMATIC… | |
| Aplazada | Media (4.3) | 0.19% | — | Creative Motion Clearfy CacheAI | 17/5/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1. | |
| Modificada | Alta (7.5) | 0.54% | — | Seweurodrive Movitools Motionstudio | 1/2/2024 | 17/6/2026 | When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur. | |
| Modificada | Alta (7.8) | 0.26% | — | Mitsubishielectric GX Works3Mitsubishielectric Melsoft IQ AppportalMitsubishielectric Melsoft NavigatorMitsubishielectric Motion Control Setting | 30/11/2023 | 17/6/2026 | Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure,… | |
| Modificada | Media (4.6) | 0.28% | — | Siemens Simotion D425-2 DP FirmwareSiemens Simotion D425-2 Dp/pn FirmwareSiemens Simotion D435-2 DP FirmwareSiemens Simotion D435-2 Dp/pn Firmware+9 | 13/6/2023 | 17/6/2026 | A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >= V5.4 < V5.5 SP1), SIMOTION D410-2 DP (All versions >= V5.4 < V5.5 SP1), SIMOTION D410-2 DP/PN (All versions >= V5.4 < V5.5 SP1), SIMOTION D425-2 DP (All versions >= V5.4 < V5.5 SP1), SIMOTION… | |
| Modificada | Alta (7.8) | 0.31% | — | Genymotion Desktop | 13/2/2023 | 17/6/2026 | Genymotion Desktop v3.3.2 was discovered to contain a DLL hijacking vulnerability that allows attackers to escalate privileges and execute arbitrary code via a crafted DLL. | |
| Modificada | Media (5.5) | 0.21% | — | Omron Cx-motion PRO | 30/1/2023 | 17/6/2026 | Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed. | |
| Modificada | Alta (7.8) | 0.20% | — | Omron Cx-motion-mch Firmware | 17/1/2023 | 17/6/2026 | CX-Motion-MCH v2.32 and earlier contains an access of uninitialized pointer vulnerability. Having a user to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution. | |
| Modificada | Media (6.5) | 0.89% | — | Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs | 26/12/2022 | 17/6/2026 | In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root. | |
| Modificada | Media (5.5) | 0.23% | — | Pilz PAS 4000Pliz PascalPliz PasconnectPliz Pasmotion+1 | 24/11/2022 | 17/6/2026 | A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability. | |
| Modificada | Alta (7.5) | 0.69% | — | Softmotions Iowow | 21/10/2022 | 17/6/2026 | IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer overflow vulnerability that allows for Denial of Service (DOS) when it parses scientific notation numbers present in JSON. A patch for this issue is available at commit… | |
| Modificada | Alta (7.8) | 0.25% | — | Genymobile Genymotion Desktop | 13/9/2022 | 17/6/2026 | Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate privileges and execute arbitrary code via a crafted binary. | |
| Modificada | Alta (7.5) | 1.2% | — | Rice Open Motion Planning Library | 17/6/2022 | 17/6/2026 | Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior. |