Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
4300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.57% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause external control of a file name or path. A successful exploit of this vulnerability might lead to code execution, escalation of privileges, data tampering, and denial of service. | |
| Analizada | Alta (8.1) | 0.44% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an XML injection. A successful exploit of this vulnerability might lead to data tampering and denial of service. | |
| Analizada | Crítica (9.8) | 0.42% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause an improper authentication issue. A successful exploit of this vulnerability might lead to escalation of privileges, information disclosure, and data tampering. | |
| Analizada | Crítica (9.8) | 0.23% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause improper certificate validation. A successful exploit of this vulnerability might lead to information disclosure, data tampering, and denial of service. | |
| En análisis | Alta (8.8) | 0.20% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of a hard-coded password. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Analizada | Media (6.5) | 0.58% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker may cause uncontrolled resource consumption. A successful exploit of this vulnerability may lead to denial of service. | |
| Analizada | Crítica (9.8) | 0.45% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause missing authentication for a critical function. A successful exploit of this vulnerability might lead to data tampering, denial of service, and information disclosure. | |
| Analizada | Crítica (9.8) | 0.67% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause use of hard-coded credentials. A successful exploit of this vulnerability might lead to escalation of privileges, data tampering, denial of service, and information disclosure. | |
| Analizada | Media (6.5) | 0.58% | — | Nvidia Infra Controller | 22/9/2026 | 29/9/2026 | NVIDIA Infrastructure Controller for Linux contains a vulnerability where an attacker could cause uncontrolled resource consumption. A successful exploit of this vulnerability might lead to denial of service. | |
| Pendiente de análisis | Media (5.9) | 0.16% | — | IBM ControllerAI | 18/9/2026 | 19/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 transmits data in clear text that could allow an attacker to obtain sensitive information using man in the middle techniques. | |
| Pendiente de análisis | Media (5.4) | 0.25% | — | IBM ControllerAI | 18/9/2026 | 18/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow an authenticated user to bypass input validation due to improper validation of client-side input of file size. | |
| Pendiente de análisis | Media (5.3) | 0.24% | — | IBM ControllerAI | 18/9/2026 | 19/9/2026 | IBM Controller 11.0.0 through 11.0.1 FP7, and 11.1.0 through 11.1.3 FP1 could allow a remote attacker to obtain sensitive information when a detailed technical error message is returned in the browser. This information could be used in further attacks against the system. | |
| Aplazada | Crítica (9.2) | 0.29% | — | ABB Freelance Controller DCPAIABB Freelance Controller Ac700AIABB Freelance Controller Ac800AIABB Freelance Controller Ac900AI | 18/9/2026 | 18/9/2026 | Improper handling of length parameter inconsistency vulnerability in ABB Freelance Controller DCP, ABB Freelance Controller AC700, ABB Freelance Controller AC800, and ABB Freelance Controller AC900. This issue affects Freelance Controller DCP: through 2013, 2013 SP1, 2016, 2016 SP1, 2019, and 2019 SP1; Freelance… | |
| Aplazada | Crítica (9.2) | 0.12% | — | Mitsubishielectric GX Works3AIMitsubishielectric Motion Control SettingAI | 17/9/2026 | 18/9/2026 | Incorrect Implementation of Authentication Algorithm Vulnerability in Mitsubishi Electric GX Works3 and Motion Control Setting allows a local attacker to successfully authenticate even with an invalid block password by executing the affected product and modifying part of the executable module in memory, and thereby… | |
| Aplazada | Alta (7.5) | 0.46% | — | Controlid IdsecureAI | 16/9/2026 | 18/9/2026 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/dguardintegration/dguardVersion endpoint dereferences DGuard integration login state that may be unset, raising an unhandled null reference exception. The exception is thrown from an asynchronous method that… | |
| Aplazada | Alta (7.5) | 0.66% | — | Controlid IdsecureAI | 16/9/2026 | 18/9/2026 | Control iD iDSecure versions prior to 4.8.3.0 are affected by an unauthenticated Denial of Service. The /api/license/restartService endpoint is reachable without authentication and invokes an internal routine that terminates the iDSecure service process and relaunches it by way of a generated batch script. An… | |
| Pendiente de análisis | Media (6.8) | 0.47% | — | Zope AccesscontrolAI | 16/9/2026 | 30/9/2026 | Zope AccessControl provides a general security framework for use in Zope. Prior to 7.4, applications that allow untrusted users to create and execute AccessControl-controlled Python code do not safely guard str.format and str.format_map when those methods are reached through a str subclass. In both ImplPython.py and… | |
| Aplazada | Alta (8.8) | 0.42% | — | Oracle Fusion Middleware ControlAI | 15/9/2026 | 17/9/2026 | Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Fusion Middleware… | |
| Aplazada | Media (5.4) | 0.21% | — | Oracle Fusion Middleware ControlAI | 15/9/2026 | 21/9/2026 | Vulnerability in the Oracle Fusion Middleware Control product of Oracle Fusion Middleware (component: Framework). Supported versions that are affected are 12.2.1.4.0 and 14.1.2.0.0. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Fusion Middleware… | |
| Aplazada | Media (5.3) | 0.45% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | |
| Aplazada | Alta (8.7) | 1.9% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.1) | 0.26% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Crítica (9.3) | 0.37% | — | Avideo LogincontrolAIWwbn AvideoAI | 11/9/2026 | 11/9/2026 | AVideo through commit c3edcc274c389816d434acadac07ee78eaf330c1 contains a stored cross-site scripting vulnerability in the LoginControl plugin that fails to HTML-encode PGP public keys echoed into a textarea element. An authenticated attacker can inject malicious JavaScript by submitting a crafted public key, which… | |
| Aplazada | Media (6.9) | 0.47% | — | Tp-link Omada ControllerAI | 11/9/2026 | 11/9/2026 | An information disclosure vulnerability in the SAML Single Sign-On (SSO) functionality of Omada Controller allows an authenticated user with SAML configuration privileges to access sensitive information due to insufficient validation of user-supplied SAML metadata. Successful exploitation could result in unauthorized… | |
| Aplazada | Alta (7.1) | 0.29% | — | Hikvision Hikcentral Access ControlAI | 10/9/2026 | 10/9/2026 | There is an Vulnerability in some HikCentral Access Control versions. Authenticated low-privilege users can invoke API interfaces that their role is not authorized to access. |