Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▼ 488 respecto a la semana anterior
Críticas / altas1301▼ 189 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
2318 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.6) | 0.63% | — | Cisco IOS XECisco Business Access PointsCisco Wireless LAN Controller Software | 27/3/2024 | 17/6/2026 | A vulnerability in the IP packet processing of Cisco Access Point (AP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to insufficient input validation of certain IPv4 packets. An attacker could exploit this… | |
| Aplazada | Alta (7.1) | 0.33% | — | Indianic Widgets ControllerAI | 27/3/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in IndiaNIC Widgets Controller allows Reflected XSS.This issue affects Widgets Controller: from n/a through 1.1. | |
| Aplazada | Alta (7.2) | 0.88% | — | Omron Machine Automation Controller NJ SeriesAIOmron Machine Automation Controller NX SeriesAI | 12/3/2024 | 17/6/2026 | Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege.… | |
| Analizada | Media (5.4) | 0.36% | — | Cisco Appdynamics Controller | 6/3/2024 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco AppDynamics Controller could allow an authenticated, remote attacker to perform a reflected cross-site scripting (XSS) attack against a user of the interface of an affected device. This vulnerability is due to insufficient validation of user-supplied input… | |
| Analizada | Media (6.5) | 2.2% | — | Cisco Appdynamics Controller | 6/3/2024 | 17/6/2026 | A vulnerability in the file upload functionality of Cisco AppDynamics Controller could allow an authenticated, remote attacker to conduct directory traversal attacks on an affected device. This vulnerability is due to insufficient validation of user-supplied input. An attacker could exploit this vulnerability by… | |
| Aplazada | Media (6.2) | 0.17% | — | Gallagher Controller 7000AI | 5/3/2024 | 17/6/2026 | Missing release of resource after effective lifetime (CWE-772) in the Controller 7000 resulted in HBUS connected T-Series readers to not automatically recover after coming under attack over the RS-485 interface, resulting in a persistent denial of service. This issue affects: All variants of the Gallagher Controller… | |
| Analizada | Alta (8.4) | 0.21% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 23/2/2024 | 17/6/2026 | Improper access control in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.2) | 0.21% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 23/2/2024 | 17/6/2026 | Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.2) | 0.21% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 23/2/2024 | 17/6/2026 | Improper neutralization in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Alta (7.2) | 0.20% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 23/2/2024 | 17/6/2026 | Insufficient control flow management in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (5.3) | 0.55% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 23/2/2024 | 17/6/2026 | Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Analizada | Alta (7.2) | 0.20% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 23/2/2024 | 17/6/2026 | Uncaught exception in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable escalation of privilege via local access. | |
| Analizada | Media (6) | 0.23% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 23/2/2024 | 17/6/2026 | Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow a privileged user to potentially enable denial of service via local access. | |
| Analizada | Alta (8.6) | 0.77% | — | Intel Ethernet Controller I225-it FirmwareIntel Ethernet Controller I225-lm FirmwareIntel Ethernet Controller I225-v FirmwareIntel Ethernet Adapter Complete Driver | 23/2/2024 | 17/6/2026 | Improper input validation in some Intel(R) Ethernet Adapters and Intel(R) Ethernet Controller I225 Manageability firmware may allow an unauthenticated user to potentially enable denial of service via network access. | |
| Analizada | Media (6.5) | 0.27% | — | Silabs Z-wave Pc-based Controller | 21/2/2024 | 17/6/2026 | Malformed S2 Nonce Get Command Class packets can be sent to crash PC Controller v5.54.0 and earlier. | |
| Analizada | Media (6.5) | 0.25% | — | Silabs Z-wave Pc-based Controller | 21/2/2024 | 17/6/2026 | Malformed Device Reset Locally Command Class packets can be sent to the controller, causing the controller to assume the end device has left the network. After this, frames sent by the end device will not be acknowledged by the controller. This vulnerability exists in PC Controller v5.54.0, and earlier. | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | When a virtual server is enabled with VLAN group and SNAT listener is configured, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (7.5) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | When SSL Client Certificate LDAP or Certificate Revocation List Distribution Point (CRLDP) authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Media (6) | 0.17% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | When running in Appliance mode, an authenticated attacker assigned the Administrator role may be able to bypass Appliance mode restrictions utilizing iAppsLX templates on a BIG-IP system. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (7.5) | 0.52% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+9 | 14/2/2024 | 17/6/2026 | When HTTP/2 is configured on BIG-IP or BIG-IP Next SPK systems, undisclosed responses can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (7.2) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | When BIG-IP is deployed in high availability (HA) and an iControl REST API token is updated, the change does not sync to the peer device. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated | |
| Analizada | Alta (8.7) | 0.83% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | When running in appliance mode, an authenticated remote command injection vulnerability exists in an undisclosed iControl REST endpoint on multi-bladed systems. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which have reached End of Technical Support (EoTS) are not… | |
| Analizada | Media (6.7) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip Analytics+8 | 14/2/2024 | 17/6/2026 | BIG-IP or BIG-IQ Resource Administrators and Certificate Managers who have access to the secure copy (scp) utility but do not have access to Advanced shell (bash) can execute arbitrary commands with a specially crafted command string. This vulnerability is due to an incomplete fix for CVE-2020-5873. Note: Software… | |
| Analizada | Alta (7.5) | 74% | 💥 PoC | Netapp HCI Baseboard Management ControllerNetapp Active IQ Unified ManagerNetapp Bootstrap OSPowerdns Recursor+4 | 14/2/2024 | 17/6/2026 | The Closest Encloser Proof aspect of the DNS protocol (in RFC 5155 when RFC 9276 guidance is skipped) allows remote attackers to cause a denial of service (CPU consumption for SHA-1 computations) via DNSSEC responses in a random subdomain attack, aka the "NSEC3" issue. The RFC 5155 specification implies that an… | |
| Modificada | Alta (7.5) | 0.81% | — | Craftycontrol Crafty Controller | 3/2/2024 | 17/6/2026 | A host header injection vulnerability in the HTTP handler component of Crafty Controller allows a remote, unauthenticated attacker to trigger a Denial of Service (DoS) condition via a modified host header |