Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
–

4320 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.3)0.18%—BMC Control-m/agent16/9/202517/6/2026
A path traversal in the Control-M/Agent can lead to a local privilege escalation when an attacker has access to the system running the Agent. This vulnerability impacts the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions. This vulnerability was fixed in 9.0.20.100…
AplazadaMedia (6.9)0.39%—BMC Control-m AgentAIBMC Control-m ServerAI16/9/202517/6/2026
The improper order of AUTHORIZED_CTM_IP validation in the Control-M/Agent, where the Control-M/Server IP address is validated only after the SSL/TLS handshake is completed, exposes the Control-M/Agent to vulnerabilities in the SSL/TLS implementation under certain non-default conditions (e.g. CVE-2025-55117 or…
AnalizadaCrítica (9.5)0.29%—BMC Control-m/agent16/9/202517/6/2026
If the Access Control List is enforced by the Control-M/Agent and the C router is in use (default in Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions; non-default but configurable using the JAVA_AR setting in newer versions), the verification stops at the first NULL…
AnalizadaAlta (7.6)0.22%—BMC Control-m/agent16/9/202517/6/2026
Out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 (and potentially earlier unsupported versions) that are configured to use the non-default Blowfish cryptography algorithm use a hardcoded key. An attacker with access to network traffic and to this key could decrypt network traffic between the Control-M/Agent…
AnalizadaMedia (5.7)0.13%—BMC Control-m/agent16/9/202517/6/2026
Certain files with overly permissive permissions were identified in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions as well as in newer versions which were upgraded from an affected version. These files contain keys and passwords relating to SSL files, keystore…
AplazadaMedia (5.7)0.14%—BMC Control-m/agentsAI16/9/202517/6/2026
Control-M/Agents use a kdb or PKCS#12 keystore by default, and the default keystore password is well known and documented. An attacker with read access to the keystore could access sensitive data using this password.
AnalizadaCrítica (9.5)0.35%—BMC Control-m/agent16/9/202517/6/2026
An authentication bypass vulnerability exists in the out-of-support Control-M/Agent versions 9.0.18 to 9.0.20 and potentially earlier unsupported versions when using an empty or default kdb keystore or a default PKCS#12 keystore. A remote attacker with access to a signed third-party or demo certificate for client…
AnalizadaMedia (6.5)0.26%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+19/9/202517/6/2026
Improper action enforcement in certain Zoom Workplace Clients for Windows may allow an unauthenticated user to conduct a disclosure of information via network access.
AnalizadaMedia (4.3)0.20%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+19/9/202517/6/2026
Incorrect authorization in certain Zoom Workplace Clients for Windows may allow an authenticated user to conduct an impact to integrity via network access.
AnalizadaAlta (7.4)0.31%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+29/9/202517/6/2026
Cross-site scripting in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.
AnalizadaAlta (7.5)0.27%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace+29/9/202517/6/2026
Uncontrolled resource consumption in certain Zoom Workplace Clients may allow an unauthenticated user to conduct a denial of service via network access.
AnalizadaMedia (6.5)0.32%—Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+19/9/202517/6/2026
Buffer overflow in certain Zoom Workplace Clients may allow an authenticated user to conduct a denial of service via network access.
AnalizadaAlta (8.2)0.41%—Rockwellautomation Controllogix 5580 Firmware9/9/20251/10/2026
A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable fault on the controller.
AplazadaMedia (6.3)0.27%—Johnsoncontrols Apogee PXC Series BacnetAIJohnsoncontrols Apogee PXC Series P2 EthernetAIJohnsoncontrols Talon TC Series BacnetAI9/9/202517/6/2026
A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices connected to the network allow unrestricted access to sensitive files, such as databases. This could allow an attacker to download…
AnalizadaCrítica (9.8)0.72%—Avigilon Access Control Manager8/9/202517/6/2026
A CSV injection vulnerability in the /id_profiles endpoint of Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via suuplying a crafted Excel file.
AnalizadaCrítica (9.8)2.9%💥 ExploitAvigilon Access Control Manager8/9/202517/6/2026
A Host Header Injection vulnerability in Avigilon ACM v7.10.0.20 allows attackers to execute arbitrary code via supplying a crafted URL.
AplazadaAlta (7.4)0.28%—Microsoft Windows Defender Application ControlAIMicrosoft Hypervisor-protected Code IntegrityAI8/9/202517/6/2026
The Microsoft vulnerable driver block list is implemented as Windows Defender Application Control (WDAC) policy. Entries that specify only the to-be-signed (TBS) part of the code signer certificate are properly blocked, but entries that specify the signing certificate's TBS hash along with a 'FileAttribRef' qualifier…
AplazadaMedia (6.5)0.20%—Kubernetes Secrets-store-sync-controllerAI5/9/202517/6/2026
Kubernetes secrets-store-sync-controller in versions before 0.0.2 discloses service account tokens in logs.
AnalizadaCrítica (9.3)0.52%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user.
AnalizadaAlta (8.6)0.22%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade.
AnalizadaCrítica (9.2)0.47%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters.
AnalizadaAlta (8.7)0.34%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously crash the application services.
AnalizadaMedia (5.1)0.20%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can inject a stored XSS to the floorplan web page.
AnalizadaAlta (7.7)0.26%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services.
AnalizadaAlta (8.8)0.36%—Copeland E3 Supervisory Controller Firmware2/9/202517/6/2026
E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can access any file from the E3 file system.