Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.3) | 0.31% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash. | |
| Analizada | Media (6.9) | 0.34% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 5/10/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS. | |
| Aplazada | Crítica (9.3) | 1.1% | 💥 Exploit | Sunwayland ForcecontrolAI | 30/8/2025 | 16/6/2026 | Sunway ForceControl version 6.1 SP3 and earlier contains a stack-based buffer overflow vulnerability in the SNMP NetDBServer service, which listens on TCP port 2001. The flaw is triggered when the service receives a specially crafted packet using opcode 0x57 with an overly long payload. Due to improper bounds checking… | |
| Aplazada | Crítica (9.3) | 0.63% | — | Bian QUE Feijiu Intelligent Emergency AND Quality Control SystemAI | 27/8/2025 | 25/9/2026 | An unauthenticated SQL injection vulnerability exists in the GetLyfsByParams endpoint of Bian Que Feijiu Intelligent Emergency and Quality Control System, accessible via the /AppService/BQMedical/WebServiceForFirstaidApp.asmx interface. The backend fails to properly sanitize user-supplied input in the strOpid… | |
| Aplazada | Media (5.4) | 0.22% | — | Cisco Integrated Management ControllerAICisco UCS ManagerAI | 27/8/2025 | 17/6/2026 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker with low privileges to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to… | |
| Aplazada | Alta (7.1) | 0.45% | — | Cisco Integrated Management ControllerAICisco UCS ManagerAI | 27/8/2025 | 17/6/2026 | A vulnerability in the Virtual Keyboard Video Monitor (vKVM) connection handling of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to redirect a user to a malicious website. This vulnerability is due to insufficient verification of vKVM endpoints. An attacker could exploit… | |
| Analizada | Alta (8.8) | 8.2% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 26/8/2025 | 17/6/2026 | Memory overflow vulnerability leading to unpredictable or erroneous behavior and Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) with PCoIP Profile bounded to it | |
| Analizada | Crítica (9.2) | 20% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 26/8/2025 | 17/6/2026 | Memory overflow vulnerability leading to Remote Code Execution and/or Denial of Service in NetScaler ADC and NetScaler Gateway when NetScaler is configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server (OR) NetScaler ADC and NetScaler Gateway 13.1, 14.1, 13.1-FIPS and NDcPP: LB… | |
| Analizada | Media (6.1) | 0.29% | — | Ehcp Easy Hosting Control Panel | 22/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting in the Change Template function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the template parameter. | |
| Analizada | Media (6.1) | 0.24% | — | Ehcp Easy Hosting Control Panel | 22/8/2025 | 17/6/2026 | Reflected Cross-Site Scripting in the List MySQL Databases function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via the action parameter. | |
| Modificada | Media (5.4) | 0.23% | — | Ehcp Easy Hosting Control Panel | 21/8/2025 | 17/6/2026 | SQL Injection in the listdomains function in Easy Hosting Control Panel (EHCP) 20.04.1.b allows authenticated attackers to access or manipulate database contents via the arananalan POST parameter. | |
| Analizada | Media (6.5) | 0.26% | — | Ehcp Easy Hosting Control Panel | 19/8/2025 | 17/6/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the List All Email Addresses function. | |
| Modificada | Media (6.4) | 0.16% | — | Mechrevo Control Center GX V2 | 15/8/2025 | 7/10/2026 | A vulnerability has been found in Mechrevo Control Center GX V2 5.56.51.48. Affected is an unknown function of the file C:\Program Files\OEM\机械革命控制中心\AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. Such manipulation leads to uncontrolled search path. The attack needs to be performed… | |
| Modificada | Media (6.4) | 0.16% | — | Mechrevo Control Center GX V2 | 15/8/2025 | 7/10/2026 | A vulnerability was detected in Mechrevo Control Center GX V2 5.56.51.48. Impacted is an unknown function of the component reg File Handler. The manipulation results in uncontrolled search path. The attack needs to be approached locally. The attack requires a high level of complexity. The exploitability is considered… | |
| Aplazada | Alta (8.6) | 0.35% | — | Home-assistant Tapo ControlAI | 14/8/2025 | 17/6/2026 | HomeAssistant-Tapo-Control offers Control for Tapo cameras as a Home Assistant component. Prior to commit 2a3b80f, there is a code injection vulnerability in the GitHub Actions workflow .github/workflows/issues.yml. It does not affect users of the Home Assistant integration itself — it only impacts the GitHub Actions… | |
| Aplazada | Media (4.3) | 0.19% | — | Espec North America WEB ControllerAI | 14/8/2025 | 17/6/2026 | In ESPEC North America Web Controller 3 before 3.3.8, /api/v4/auth/ users session privileges are not revoked on logout. | |
| Aplazada | Media (4.3) | 0.19% | — | Espec North America WEB Controller 3AI | 14/8/2025 | 17/6/2026 | In ESPEC North America Web Controller 3 before 3.3.8, an attacker with physical access can gain elevated privileges because GRUB and the BIOS are unprotected. | |
| Aplazada | Crítica (9.8) | 0.43% | — | Espec North America WEB ControllerAI | 14/8/2025 | 17/6/2026 | In ESPEC North America Web Controller 3 before 3.3.4, /api/v4/auth/ with any invalid authentication request results in exposing a JWT secret. This allows for elevated permissions to the UI. | |
| Aplazada | Crítica (9.3) | 0.85% | — | Rockwellautomation Controllogix Ethernet ModulesAI | 14/8/2025 | 17/6/2026 | A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules. If a specific IP address is used to connect to the WDB agent, it can allow remote attackers to perform memory dumps, modify memory, and control execution flow. | |
| Aplazada | Alta (8.4) | 0.49% | 💥 Exploit | Netop Remote Control ClientAI | 13/8/2025 | 16/6/2026 | NetOp (now part of Impero Software) Remote Control Client v9.5 is vulnerable to a stack-based buffer overflow when processing .dws configuration files. If a .dws file contains a string longer than 520 bytes, the application fails to perform proper bounds checking, allowing an attacker to execute arbitrary code when… | |
| Analizada | Media (6.9) | 0.50% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+22 | 13/8/2025 | 17/6/2026 | An HTTP/2 implementation flaw allows a denial-of-service (DoS) that uses malformed HTTP/2 control frames in order to break the max concurrent streams limit (HTTP/2 MadeYouReset Attack). Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.7) | 0.34% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 13/8/2025 | 17/6/2026 | When a BIG-IP LTM Client SSL profile is configured on a virtual server with SSL Forward Proxy enabled and Anonymous Diffie-Hellman (ADH) ciphers enabled, undisclosed requests can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are… | |
| Analizada | Alta (8.8) | 0.62% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 12/8/2025 | 17/6/2026 | Untrusted search path in certain Zoom Clients for Windows may allow an unauthenticated user to conduct an escalation of privilege via network access | |
| Analizada | Media (5.1) | 0.11% | — | Zoom Meeting Software Development KITZoom RoomsZoom Rooms ControllerZoom Workplace Desktop+1 | 12/8/2025 | 17/6/2026 | Race condition in the installer for certain Zoom Clients for Windows may allow an unauthenticated user to impact application integrity via local access. | |
| Analizada | Alta (8.8) | 0.83% | — | Ivanti Virtual Application Delivery Controller | 12/8/2025 | 17/6/2026 | Missing authorization in the admin console of Ivanti Virtual Application Delivery Controller before version 22.9 allows a remote authenticated attacker to take over admin accounts by resetting the password |