Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
4320 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.42% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to a server-side request forgery vulnerability which could allow an unauthenticated attacker to retrieve information from other servers. | |
| Analizada | Alta (8.7) | 0.57% | — | Assaabloy Control ID Idsecure | 24/6/2025 | 17/6/2026 | ControlID iDSecure On-premises versions 4.7.48.0 and prior are vulnerable to an improper authentication vulnerability which could allow an attacker to bypass authentication and gain permissions in the product. | |
| Aplazada | Media (6.6) | 12% | — | Aviatrix ControllerAI | 23/6/2025 | 17/6/2026 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 fail to sanitize user input prior to passing the input to command line utilities, allowing command injection via special characters in filenames | |
| Aplazada | Alta (7.8) | 0.48% | — | Aviatrix ControllerAI | 23/6/2025 | 17/6/2026 | Aviatrix Controller versions prior to 7.1.4208, 7.2.5090, and 8.0.0 do not enforce rate limiting on password reset attempts, allowing adversaries to brute force guess the 6-digit password reset PIN | |
| Aplazada | Crítica (9.3) | 1.6% | 💥 Exploit | Aquatronica Controller SystemAI | 20/6/2025 | 17/6/2026 | An information disclosure vulnerability exists in Aquatronica Controller System firmware versions <= 5.1.6 and web interface versions <= 2.0. The tcp.php endpoint fails to restrict unauthenticated access, allowing remote attackers to issue crafted POST requests and retrieve sensitive configuration data, including… | |
| Aplazada | Media (4.3) | 0.26% | — | Grandplugins Image Sizes ControllerAI | 20/6/2025 | 17/6/2026 | Missing Authorization vulnerability in GrandPlugins Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes image-sizes-controller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Image Sizes Controller, Create Custom Image Sizes, Disable Image Sizes: from n/a… | |
| Analizada | Alta (8.7) | 6.2% | 💥 PoC | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 17/6/2026 | Improper access control on the NetScaler Management Interface in NetScaler ADC and NetScaler Gateway | |
| En análisis | Crítica (9.3) | 100% | ⚠ Explotación activa💥 Exploit | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 17/6/2025 | 7/10/2026 | Insufficient input validation leading to memory overread when the NetScaler is configured as a Gateway (VPN virtual server, ICA Proxy, CVPN, RDP Proxy) OR AAA virtual server | |
| Aplazada | Alta (7.4) | 2.5% | — | Wifi-soft Unibox ControllerAI | 16/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Wifi-soft UniBox Controller up to 20250506. This affects an unknown part of the file /billing/pms_check.php. The manipulation of the argument ipaddress leads to os command injection. It is possible to initiate the attack remotely. The exploit has been… | |
| Aplazada | Alta (7.4) | 2.1% | — | Wifi-soft Unibox ControllerAI | 16/6/2025 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Wifi-soft UniBox Controller up to 20250506. Affected by this issue is some unknown functionality of the file /billing/test_accesscodelogin.php. The manipulation of the argument Password leads to os command injection. The attack may be launched… | |
| Aplazada | Alta (7.4) | 2.3% | — | Wifi-soft Unibox ControllerAI | 16/6/2025 | 17/6/2026 | A vulnerability classified as critical was found in Wifi-soft UniBox Controller up to 20250506. Affected by this vulnerability is an unknown functionality of the file /authentication/logout.php. The manipulation of the argument mac_address leads to os command injection. The attack can be launched remotely. The exploit… | |
| Analizada | Media (5.4) | 0.26% | — | Craftycontrol Crafty Controller | 15/6/2025 | 17/6/2026 | An input neutralization vulnerability in the Server Name form and API Key form components of Crafty Controller allows a remote, authenticated attacker to perform stored XSS via malicious form input. | |
| Aplazada | Alta (8.8) | 2.6% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | An arbitrary free vulnerability exists in the cv_close functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an arbitrary free. An attacker can forge a fake session to trigger this vulnerability. | |
| Aplazada | Alta (8.1) | 2.6% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | A deserialization of untrusted input vulnerability exists in the cvhDecapsulateCmd functionality of Dell ControlVault3 prior to 5.15.10.14 and ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault response to a command can lead to arbitrary code execution. An attacker can compromise a ControlVault… | |
| Aplazada | Alta (8.8) | 2.1% | — | Dell Controlvault3AIDell Controlvault 3 PlusAI | 13/6/2025 | 17/6/2026 | An out-of-bounds write vulnerability exists in the cv_upgrade_sensor_firmware functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault 3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an out-of-bounds write. An attacker can issue an API call to trigger this… | |
| Aplazada | Alta (8.8) | 3.4% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the securebio_identify functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted malicious cv_object can lead to a arbitrary code execution. An attacker can issue an API call to trigger this… | |
| Aplazada | Alta (8.4) | 1.9% | — | Dell Controlvault3AIDell Controlvault3 PlusAI | 13/6/2025 | 17/6/2026 | An out-of-bounds read vulnerability exists in the cv_send_blockdata functionality of Dell ControlVault3 prior to 5.15.10.14 and Dell ControlVault3 Plus prior to 6.2.26.36. A specially crafted ControlVault API call can lead to an information leak. An attacker can issue an API call to trigger this vulnerability. | |
| Aplazada | Alta (8.7) | 0.73% | — | Acer ControlcenterAI | 13/6/2025 | 17/6/2026 | Acer ControlCenter contains Remote Code Execution vulnerability. The program exposes a Windows Named Pipe that uses a custom protocol to invoke internal functions. However, this Named Pipe is misconfigured, allowing remote users with low privileges to interact with it and access its features. One such feature enables… | |
| Analizada | Alta (7.8) | 0.38% | — | Ivanti Workspace Control | 10/6/2025 | 17/6/2026 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt stored SQL credentials. | |
| Analizada | Alta (7.3) | 0.36% | — | Ivanti Workspace Control | 10/6/2025 | 17/6/2026 | A hardcoded key in Ivanti Workspace Control before version 10.19.10.0 allows a local authenticated attacker to decrypt the stored environment password. | |
| Analizada | Alta (7.8) | 0.38% | — | Ivanti Workspace Control | 10/6/2025 | 17/6/2026 | A hardcoded key in Ivanti Workspace Control before version 10.19.0.0 allows a local authenticated attacker to decrypt stored SQL credentials. | |
| Aplazada | Alta (8.8) | 0.46% | — | Cisco Integrated Management ControllerAICisco UCS B-series ServersAICisco UCS C-series ServersAICisco UCS S-series ServersAI+1 | 4/6/2025 | 17/6/2026 | A vulnerability in the SSH connection handling of Cisco Integrated Management Controller (IMC) for Cisco UCS B-Series, UCS C-Series, UCS S-Series, and UCS X-Series Servers could allow an authenticated, remote attacker to access internal services with elevated privileges. This vulnerability is due to insufficient… | |
| Aplazada | Alta (7.8) | 0.23% | — | Solarwinds Dameware Mini Remote ControlAI | 2/6/2025 | 17/6/2026 | The SolarWinds Dameware Mini Remote Control was determined to be affected by Incorrect Permissions Local Privilege Escalation Vulnerability. This vulnerability requires local access and a valid low privilege account to be susceptible to this vulnerability. | |
| Modificada | Crítica (9.1) | 0.46% | — | Tinxy Wifi Lock Controller V1 RF Firmware | 30/5/2025 | 5/7/2026 | Tinxy WiFi Lock Controller v1 RF was discovered to be configured to transmit on an open Wi-Fi network, allowing attackers to join the network without authentication. | |
| Analizada | Alta (7.5) | 0.24% | — | Tinxy Wifi Lock Controller V1 RF Firmware | 30/5/2025 | 17/6/2026 | Tinxy WiFi Lock Controller v1 RF was discovered to store users' sensitive information, including credentials and mobile phone numbers, in plaintext. |