Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
4320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.24% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 17/6/2026 | Easy Hosting Control Panel EHCP v20.04.1.b was discovered to contain a SQL injection vulnerability via the id parameter in the Change Settings function. | |
| Analizada | Media (6.3) | 0.20% | — | Ehcp Easy Hosting Control Panel | 8/8/2025 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability in the List All FTP User Function in EHCP v20.04.1.b allows authenticated attackers to execute arbitrary JavaScript via injecting a crafted payload into the ftpusername parameter. | |
| Analizada | Media (4.8) | 0.13% | — | BMC Control-m/server | 7/8/2025 | 17/6/2026 | BMC Control-M/Server 9.0.21.300 displays cleartext database credentials in process lists and logs. An authenticated attacker with shell access could observe these credentials and use them to log in to the database server. For example, when Control-M/Server on Windows has a database connection on, it runs… | |
| Modificada | Baja (1.3) | 0.28% | — | Intelbras Incontrol WEB | 4/8/2025 | 17/6/2026 | A weakness has been identified in Intelbras InControl 2.21.60.9. This vulnerability affects unknown code of the file /v1/operador/ of the component JSON Endpoint. Executing manipulation can lead to information disclosure. It is possible to launch the attack remotely. A high complexity level is associated with this… | |
| Aplazada | Alta (7.5) | 0.55% | — | Codesys Control RuntimeAI | 4/8/2025 | 17/6/2026 | An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition. | |
| Aplazada | Alta (8.3) | 0.22% | — | Codesys ControlAI | 4/8/2025 | 17/6/2026 | A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if… | |
| Aplazada | Alta (8.2) | 0.20% | — | HCL Bigfix Remote Control ServerAI | 29/7/2025 | 17/6/2026 | Improper access restrictions in HCL BigFix Remote Control Server WebUI (versions 10.1.0.0248 and lower) allow non-admin users to view unauthorized information on certain web pages. | |
| Analizada | Media (6.3) | 0.28% | — | Vivaldigroup Icontrol+ ServerVivaldigroup Vivaldi Domotica Icontrol Firmware | 29/7/2025 | 17/6/2026 | A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser session. | |
| Aplazada | Media (4.5) | 0.11% | — | Malwarebytes Binisoft Windows Firewall ControlAI | 28/7/2025 | 17/6/2026 | In Malwarebytes Binisoft Windows Firewall Control before 6.16.0.0, the installer is vulnerable to local privilege escalation. | |
| Analizada | Baja (2.1) | 0.43% | — | Jingmen Zeyou Large File Upload Control | 26/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Jingmen Zeyou Large File Upload Control up to 6.3. Affected is an unknown function of the file /index.jsp. The manipulation of the argument ID leads to sql injection. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Aplazada | Baja (3.7) | 0.33% | — | Akamai Rate ControlAI | 25/7/2025 | 17/6/2026 | Akamai Rate Control alpha before 2025 allows attackers to send requests above the stipulated thresholds because the rate is measured separately for each edge node. | |
| Aplazada | Crítica (9.3) | 2.3% | 💥 Exploit | DG Remote Control ServerAI | 23/7/2025 | 17/6/2026 | Remote Control Server, maintained by Steppschuh, 3.1.1.12 allows unauthenticated remote code execution when authentication is disabled, which is the default configuration. The server exposes a custom UDP-based control protocol that accepts remote keyboard input events without verification. An attacker on the same… | |
| Analizada | Media (5.3) | 0.22% | — | Extremenetworks Extremecontrol | 21/7/2025 | 17/6/2026 | In ExtremeControl before 25.5.12, a cross-site scripting (XSS) vulnerability was discovered in a login interface of the affected application. The issue stems from improper handling of user-supplied input within HTML attributes, allowing an attacker to inject script code that may execute in a user's browser under… | |
| Analizada | Baja (1.9) | 0.13% | — | Eluktronics Control Center | 20/7/2025 | 17/6/2026 | A vulnerability classified as problematic was found in Eluktronics Control Center 5.23.51.41. Affected by this vulnerability is an unknown functionality of the component REG File Handler. The manipulation leads to insufficient verification of data authenticity. It is possible to launch the attack on the local host.… | |
| Analizada | Alta (7.1) | 1.7% | — | Eluktronics Control Center | 20/7/2025 | 17/6/2026 | A vulnerability classified as critical has been found in Eluktronics Control Center 5.23.51.41. Affected is an unknown function of the file \AiStoneService\MyControlCenter\Command of the component Powershell Script Handler. The manipulation leads to command injection. Attacking locally is a requirement. The exploit… | |
| Aplazada | Alta (7) | 0.25% | — | Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAIOmron Sysmac StudioAI | 14/7/2025 | 17/6/2026 | Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products. | |
| Aplazada | Media (6.5) | 0.17% | — | Controller 7000 OnelinkAI | 10/7/2025 | 17/6/2026 | Improper Certificate Validation (CWE-295) in the Controller 7000 OneLink implementation could allow an unprivileged attacker to perform a limited denial of service or perform privileged overrides during the initial configuration of the Controller, there is no risk for Controllers once they are connected. This issue… | |
| Analizada | Baja (2) | 0.34% | — | Intelbras Incontrol WEB | 4/7/2025 | 17/6/2026 | A vulnerability was found in Intelbras InControl up to 2.21.60.9. It has been declared as problematic. This vulnerability affects unknown code of the file /v1/operador/. The manipulation leads to csv injection. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The… | |
| Analizada | Crítica (9.4) | 0.81% | — | GFI Kerio Control | 2/7/2025 | 17/6/2026 | A remote code execution vulnerability in GFI Kerio Control 9.4.5 allows attackers with administrative access to upload and execute arbitrary code through the firmware upgrade feature. The system upgrade mechanism accepts unsigned .img files, which can be modified to include malicious scripts within the upgrade.sh or… | |
| Analizada | Crítica (10) | 0.76% | — | GFI Kerio Control | 2/7/2025 | 17/6/2026 | A missing authentication vulnerability in the GFIAgent component of GFI Kerio Control 9.4.5 allows unauthenticated remote attackers to perform privileged operations. The GFIAgent service, responsible for integration with GFI AppManager, exposes HTTP services on ports 7995 and 7996 without proper authentication. The… | |
| Analizada | Crítica (9.5) | 0.70% | 💥 PoC | GFI Kerio Control | 2/7/2025 | 17/6/2026 | An authentication bypass vulnerability exists in GFI Kerio Control 9.4.5 due to insecure default proxy configuration and weak access control in the GFIAgent service. The non-transparent proxy on TCP port 3128 can be used to forward unauthenticated requests to internal services such as GFIAgent, bypassing firewall… | |
| Analizada | Baja (2.1) | 0.44% | — | Intelbras Incontrol WEB | 27/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Intelbras InControl 2.21.60.9. This issue affects some unknown processing of the file /v1/operador/ of the component HTTP PUT Request Handler. The manipulation leads to permission issues. The attack may be initiated remotely. The exploit has been… | |
| Aplazada | Crítica (9.4) | 3.9% | — | Wifisky 7-layer Flow Control RouterAI | 26/6/2025 | 17/6/2026 | A remote command injection vulnerability exists in the confirm.php interface of the WIFISKY 7-layer Flow Control Router via a specially-crafted HTTP GET request to the t parameter. Insufficient input validation allows unauthenticated attackers to execute arbitrary OS commands. Exploitation evidence was observed by the… | |
| Analizada | Crítica (9.2) | 11% | ⚠ Explotación activa💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 25/6/2025 | 17/6/2026 | Memory overflow vulnerability leading to unintended control flow and Denial of Service in NetScaler ADC and NetScaler Gateway when configured as Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Analizada | Crítica (9.3) | 0.48% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to SQL injections which could allow an attacker to leak arbitrary information and insert arbitrary SQL syntax into SQL queries. |