Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 0.27% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 264939. | |
| Analizada | Crítica (9.8) | 0.46% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to SQL injection. A remote attacker could send specially crafted SQL statements, which could allow the attacker to view, add, modify or delete information in the back-end database. IBM X-Force ID: 262183. | |
| Analizada | Media (5.3) | 0.36% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 is vulnerable to injection attacks in application logging by not sanitizing user provided data. IBM X-Force ID: 251463. | |
| Analizada | Media (5.3) | 0.43% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote attacker to obtain sensitive information when a stack trace is returned in the browser. IBM X-Force ID: 245403. | |
| Analizada | Media (5.3) | 0.46% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 could allow a remote user to enumerate usernames due to differentiating error messages on existing usernames. IBM X-Force ID: 199181. | |
| Analizada | Media (4.3) | 0.37% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 does not set the secure attribute on authorization tokens or session cookies. Attackers may be able to get the cookie values by sending a http:// link to a user or by planting this link in a site the user goes to. The cookie will be sent to the insecure link and the… | |
| Analizada | Alta (7.5) | 0.27% | — | IBM Cognos Controller | 3/5/2024 | 17/6/2026 | IBM Cognos Controller 10.4.1, 10.4.2, and 11.0.0 uses weaker than expected cryptographic algorithms that could allow an attacker to decrypt highly sensitive information. IBM X-Force ID: 190837. | |
| Analizada | Media (6.5) | 0.49% | — | Infinitumform GEO Controller | 1/5/2024 | 17/6/2026 | The Geo Controller WordPress plugin before 8.6.5 unserializes user input via some of its AJAX actions and REST API routes, which could allow unauthenticated users to perform PHP Object Injection when a suitable gadget is present on the blog. | |
| Aplazada | Alta (8.7) | 33% | 💥 PoC | Cisco Integrated Management ControllerAI | 24/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with Administrator-level privileges to perform command injection attacks on an affected system and elevate their privileges to root. This vulnerability is due to… | |
| Aplazada | Alta (8.8) | 1.2% | — | Cisco Integrated Management ControllerAI | 24/4/2024 | 17/6/2026 | A vulnerability in the CLI of the Cisco Integrated Management Controller (IMC) could allow an authenticated, local attacker to perform command injection attacks on the underlying operating system and elevate privileges to root. To exploit this vulnerability, the attacker must have read-only or higher privileges on an… | |
| Analizada | Media (5.3) | 0.23% | — | Tormach Pathpilot Controller | 22/4/2024 | 17/6/2026 | An issue in the communication protocol of Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) via crafted commands. | |
| Analizada | Media (4.4) | 0.39% | — | Tormach Pathpilot Controller | 22/4/2024 | 17/6/2026 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to overwrite the hardcoded IP address in the device memory, disrupting network connectivity between the router and the controller. | |
| Analizada | Alta (8.2) | 0.44% | — | Tormach Pathpilot Controller | 22/4/2024 | 17/6/2026 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the Hostmot2 configuration cookie in the device memory. | |
| Analizada | Media (6.5) | 0.25% | — | Tormach Pathpilot Controller | 22/4/2024 | 17/6/2026 | Incorrect access control in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to access the G code's shared folder and view sensitive information. | |
| Analizada | Alta (7.5) | 0.52% | — | Tormach Pathpilot Controller | 22/4/2024 | 17/6/2026 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to cause a Denial of Service (DoS) by disrupting the communication between the PathPilot controller and the CNC router via overwriting the card's name in the device memory. | |
| Analizada | Media (6.5) | 0.42% | — | Tormach Pathpilot Controller | 22/4/2024 | 17/6/2026 | An issue in Tormach xsTECH CNC Router, PathPilot Controller v2.9.6 allows attackers to erase a critical sector of the flash memory, causing the machine to lose network connectivity and suffer from firmware corruption. | |
| Aplazada | Media (5.9) | 0.44% | — | Honeywell ControllerAI | 17/4/2024 | 17/6/2026 | Controller denial of service due to improper handling of a specially crafted message received by the controller. See Honeywell Security Notification for recommendations on upgrading and versioning. | |
| Analizada | Media (6.3) | 0.51% | — | Projectfloodlight Open SDN Controller | 12/4/2024 | 17/6/2026 | An issue in Floodlight SDN OpenFlow Controller v.1.2 allows a remote attacker to cause a denial of service via the datapath id component. | |
| Analizada | Media (5.5) | 0.27% | — | Linux KernelDebian LinuxNetapp 8300 FirmwareNetapp 8700 Firmware+6 | 3/4/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: ipv6: sr: fix possible use-after-free and null-ptr-deref The pernet operations structure for the subsystem must be registered before registering the generic netlink family. | |
| Analizada | Media (5.5) | 0.26% | — | Linux KernelDebian LinuxNetapp A1K FirmwareNetapp A70 Firmware+25 | 3/4/2024 | 17/6/2026 | In the Linux kernel, the following vulnerability has been resolved: arp: Prevent overflow in arp_req_get(). syzkaller reported an overflown write in arp_req_get(). [0] When ioctl(SIOCGARP) is issued, arp_req_get() looks up an neighbour entry and copies neigh->ha to struct arpreq.arp_ha.sa_data. The arp_ha here is… | |
| Analizada | Alta (7.5) | 0.80% | — | Cisco Nexus Dashboard Fabric Controller | 3/4/2024 | 17/6/2026 | A vulnerability in the Out-of-Band (OOB) Plug and Play (PnP) feature of Cisco Nexus Dashboard Fabric Controller (NDFC) could allow an unauthenticated, remote attacker to read arbitrary files. This vulnerability is due to an unauthenticated provisioning web server. An attacker could exploit this vulnerability through… | |
| Analizada | Alta (8.8) | 0.26% | — | Cisco Nexus DashboardCisco Nexus Dashboard Fabric ControllerCisco Nexus Dashboard InsightsCisco Nexus Dashboard Orchestrator | 3/4/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Nexus Dashboard and Cisco Nexus Dashboard hosted services could allow an unauthenticated, remote attacker to conduct a cross-site request forgery (CSRF) attack on an affected system. This vulnerability is due to insufficient CSRF protections for the… | |
| Aplazada | Media (6.5) | 0.35% | — | Infinitum Form GEO ControllerAI | 29/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in INFINITUM FORM Geo Controller allows Stored XSS.This issue affects Geo Controller: from n/a through 8.6.4. | |
| Aplazada | Crítica (9) | 0.60% | — | Infinitum Form GEO ControllerAI | 28/3/2024 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in INFINITUM FORM Geo Controller.This issue affects Geo Controller: from n/a through 8.6.4. | |
| Analizada | Alta (7.4) | 0.29% | — | Cisco Wireless LAN Controller SoftwareCisco IOS XE | 27/3/2024 | 17/6/2026 | A vulnerability in the handling of encrypted wireless frames of Cisco Aironet Access Point (AP) Software could allow an unauthenticated, adjacent attacker to cause a denial of service (DoS) condition on the affected device. This vulnerability is due to incomplete cleanup of resources when dropping certain malformed… |