Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2747▼ 495 respecto a la semana anterior
Críticas / altas1308▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

2318 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.66%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+81/2/202317/6/2026
In BIP-IP versions 17.0.x before 17.0.0.2, 16.1.x before 16.1.3.3, 15.1.x before 15.1.8.1, 14.1.x before 14.1.5.3, and all versions of 13.1.x, when OCSP authentication profile is configured on a virtual server, undisclosed requests can cause an increase in CPU resource utilization. Note: Software versions which have…
ModificadaMedia (5.9)0.53%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+81/2/202317/6/2026
In BIG-IP versions 17.0.x before 17.0.0.2, and 16.1.x beginning in 16.1.2.2 to before 16.1.3.3, when an HTTP profile is configured on a virtual server and conditions beyond the attacker’s control exist on the target pool member, undisclosed requests sent to the BIG-IP system can cause the Traffic Management…
ModificadaMedia (6.7)0.23%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+28330/1/202317/6/2026
A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+14330/1/202317/6/2026
An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaMedia (4.4)0.20%—Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+13230/1/202317/6/2026
An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory.
ModificadaAlta (7.5)1.0%—Citrix Application Delivery ControllerCitrix Gateway26/1/202317/6/2026
Unauthenticated denial of service
ModificadaMedia (6.5)0.99%—Citrix GatewayCitrix Application Delivery Controller26/1/202317/6/2026
Authenticated denial of service
ModificadaAlta (8.8)0.42%—Edgenexus Application Delivery Controller23/1/202317/6/2026
A Cross-Site Request Forgery (CSRF) in the management portal of JetNexus/EdgeNexus ADC 4.2.8 allows attackers to escalate privileges and execute arbitrary code via unspecified vectors.
ModificadaAlta (8.8)3.5%—Edgenexus Application Delivery Controller23/1/202317/6/2026
The management portal component of JetNexus/EdgeNexus ADC 4.2.8 was discovered to contain a command injection vulnerability. This vulnerability allows authenticated attackers to execute arbitrary commands through a specially crafted payload. This vulnerability can also be exploited from an unauthenticated context via…
ModificadaMedia (5.9)0.63%—Wago Pfc100 FirmwareWago Pfc200 FirmwareWago Touch Panel 600 Advanced FirmwareWago Touch Panel 600 Standard Firmware+319/1/202317/6/2026
The vulnerability allows a remote unauthenticated attacker to download a backup file, if one exists. That backup file might contain sensitive information like credentials and cryptographic material. A valid user has to create a backup after the last reboot for this attack to be successfull.
ModificadaAlta (7.1)0.28%—Linux KernelNetapp HCI Baseboard Management Controller17/1/202317/6/2026
A flaw was found in the Linux kernel. A NULL pointer dereference may occur while a slip driver is in progress to detach in sl_tx_timeout in drivers/net/slip/slip.c. This issue could allow an attacker to crash the system or leak internal kernel information.
ModificadaAlta (7.8)0.30%—Linux KernelNetapp HCI Baseboard Management ControllerDebian Linux13/1/202317/6/2026
In rndis_query_oid in drivers/net/wireless/rndis_wlan.c in the Linux kernel through 6.1.5, there is an integer overflow in an addition.
ModificadaMedia (6.8)0.29%—Siemens Simatic Drive Controller CPU 1504d TF FirmwareSiemens Simatic Drive Controller CPU 1507d TF FirmwareSiemens Simatic S7-1500 CPU 1510sp F-1 PN FirmwareSiemens Simatic S7-1500 CPU 1510sp-1 PN Firmware+6610/1/202317/6/2026
Affected devices do not contain an Immutable Root of Trust in Hardware. With this the integrity of the code executed on the device can not be validated during load-time. An attacker with physical access to the device could use this to replace the boot image of the device and execute arbitrary code.
ModificadaMedia (6.5)0.59%—Citrix Application Delivery Controller FirmwareCitrix Gateway26/12/202217/6/2026
In certain Citrix products, information disclosure can be achieved by an authenticated VPN user when there is a configured SSL VPN endpoint. This affects Citrix ADC and Citrix Gateway 13.0-58.30 and later releases before the CTX276688 update.
AnalizadaAlta (7.8)0.17%—Pilz PMCCodesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000+6026/12/202217/6/2026
In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device.
ModificadaAlta (7.8)0.16%—Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+2026/12/202217/6/2026
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.
AnalizadaCrítica (9.8)6.7%⚠ Explotación activa💥 PoCCitrix Application Delivery Controller FirmwareCitrix Gateway Firmware13/12/202217/6/2026
Unauthenticated remote arbitrary code execution
ModificadaAlta (7.5)0.74%—Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+9213/12/202217/6/2026
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
ModificadaAlta (7.5)0.63%—Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+8813/12/202217/6/2026
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
ModificadaAlta (7.5)0.74%—Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+9213/12/202217/6/2026
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
ModificadaAlta (7.5)0.90%—Siemens Simatic S7-plcsim Advanced FirmwareSiemens Simatic S7-1200 CPU 1211c FirmwareSiemens Simatic S7-1200 CPU 1212c FirmwareSiemens Simatic S7-1200 CPU 1212fc Firmware+9213/12/202217/6/2026
Affected devices don't process correctly certain special crafted packets sent to port 102/tcp, which could allow an attacker to cause a denial of service in the device.
ModificadaAlta (8.7)77%💥 ExploitF5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Application Acceleration Manager+77/12/202217/6/2026
In all versions of BIG-IP, when running in Appliance mode, an authenticated user assigned the Administrator role may be able to bypass Appliance mode restrictions, utilizing an undisclosed iControl REST endpoint. A successful exploit can allow the attacker to cross a security boundary. Note: Software versions which…
ModificadaAlta (8.8)92%💥 ExploitF5 Big-iq Centralized ManagementF5 Big-ip Advanced Firewall ManagerF5 Big-ip AnalyticsF5 Big-ip Access Policy Manager+87/12/202217/6/2026
In all versions, BIG-IP and BIG-IQ are vulnerable to cross-site request forgery (CSRF) attacks through iControl SOAP. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
ModificadaCrítica (9.8)1.1%—Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+951/12/202217/6/2026
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
ModificadaCrítica (9.8)0.64%—Citrix GatewayCitrix Application Delivery Controller Firmware8/11/202217/6/2026
User login brute force protection functionality bypass