Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

4530 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.43%—PX4 AutopilotAI2/9/202610/9/2026
PX4 Autopilot contains a heap buffer overflow vulnerability in the sd_bench command that writes a four-byte block number into a user-supplied sized allocation. Attackers can invoke sd_bench with a block size below four bytes to overflow the heap buffer and potentially execute code or crash the system.
Pendiente de análisisMedia (6.4)0.30%—Redhat Ansible Automation PlatformAIAnsible AWXAI1/9/202624/9/2026
A flaw was found in Ansible Automation Platform's automation-controller (AWX). The Bulk Job Launch API (POST /api/v2/bulk/job_launch/) authorizes the requested instance_groups with only a read-level permission check, whereas the standard single-job launch path requires use-level permission on the same field. A…
Pendiente de análisisAlta (8.7)0.43%—Rockwellautomation Rslinx ClassicAI1/9/20261/9/2026
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
Pendiente de análisisAlta (8.7)0.43%—Rockwellautomation Rslinx ClassicAI1/9/20261/9/2026
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover.
Pendiente de análisisAlta (8.7)0.43%—Rockwellautomation Rslinx ClassicAI1/9/20261/9/2026
A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover.
Pendiente de análisisCrítica (9.2)0.43%—Rockwellautomation Rslinx ClassicAI1/9/20261/9/2026
A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover
Pendiente de análisisAlta (8.5)0.11%—Rockwellautomation Factorytalk Activation ManagerAI1/9/20261/9/2026
A privilege escalation security issue exists within FactoryTalk® Activation Manager. The security issue stems from custom actions in the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack…
Pendiente de análisisMedia (4.8)0.16%—Rockwellautomation Factorytalk Historian Machine EditionAI1/9/20261/9/2026
A denial-of-service security issue exists within FactoryTalk® Historian Machine Edition. A network adjacent attacker who is authenticated could send crafted requests to the web interface, resulting in buffer overflow conditions that may cause the device to crash and become unresponsive.
Pendiente de análisisAlta (8.6)0.31%—Rockwellautomation Factorytalk Historian Machine EditionAI1/9/20261/9/2026
A security issue exists within FactoryTalk® Historian Machine Edition. An attacker with low-level authentication could exploit this vulnerability to achieve remote code execution on the affected device.
AplazadaCrítica (9.8)0.36%—Bird Home Automation Gmbh D1101v-fAI26/8/20268/9/2026
Bird Home Automation GmbH D1101V-F 000140 is vulnerable to Incorrect Access Control via the Key derivation process, password validation process.
AplazadaMedia (6.9)0.48%—AutomatischAI26/8/202623/9/2026
Automatisch reveals whether an address is registered through the response to its forgot-password request. The controller at packages/backend/src/controllers/internal/api/v1/users/forgot-password.js looks the address up and chains a not-found throw onto the query, so an address with no account raises an error that the…
AplazadaCrítica (9.3)0.28%—Danfoss Ic7-automation SPAIDanfoss Ic7-marineAIDanfoss Ic7-hybrid GR3AI26/8/20263/9/2026
Improper access control in debug and engineering interfaces in Danfoss iC7-Automation SP, iC7-Marine, and iC7-Hybrid GR3 allows attackers to gain read/write access to internal values, upload and execute unsigned applications, and upload unsigned EEPROM data and firmware via exposed service interfaces and software…
Pendiente de análisisMedia (6.1)0.15%—Drupal Search API AutocompleteAI25/8/202628/8/2026
Improper Neutralization of Input During Web Page Generation ("Cross-site Scripting") vulnerability in Drupal Search API Autocomplete allows Reflected XSS. This issue affects Search API Autocomplete versions: from 0.0.0 to 1.12.0.
AplazadaMedia (6.5)0.30%—AutomatorcwpAI24/8/202626/8/2026
Subscriber Broken Access Control in AutomatorWP <= 5.8.3 versions.
AnalizadaAlta (7.8)0.19%—Autodesk 3DS MAX24/8/202628/8/2026
A maliciously crafted FLT file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
AnalizadaAlta (7.8)0.13%—Autodesk 3DS MAX24/8/202628/8/2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force a Memory Corruption vulnerability. A malicious actor can leverage this vulnerability to execute arbitrary code in the context of the current process.
AnalizadaAlta (7.8)0.13%—Autodesk 3DS MAX24/8/202628/8/2026
A maliciously crafted ABC file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Write vulnerability. A malicious actor may leverage this vulnerability to cause a crash, cause data corruption, or execute arbitrary code in the context of the current process.
AnalizadaAlta (7.8)0.21%—Autodesk 3DS MAX24/8/202628/8/2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can force an Out-of-Bounds Read vulnerability. A malicious actor can leverage this vulnerability to cause a crash, read sensitive data, or execute arbitrary code in the context of the current process.
AnalizadaMedia (5.5)0.11%—Autodesk 3DS MAX24/8/202628/8/2026
A maliciously crafted SVG file, when parsed through Autodesk 3ds Max, can trigger an Uncontrolled Recursion vulnerability. A malicious actor may leverage this vulnerability to cause the application to terminate unexpectedly, resulting in a denial-of-service.
AplazadaMedia (4.3)0.40%—AutomatorwpAI22/8/202624/8/2026
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
AplazadaMedia (4.3)0.44%—AutomatorwpAI22/8/202624/8/2026
The AutomatorWP – Automator plugin for no-code automations, webhooks & custom integrations in WordPress plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 5.8.4. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it…
Pendiente de análisisMedia (6.9)0.08%—Johnsoncontrols Simplex Incident ManagerAIJohnsoncontrols Autocall Fire AdministratorAI21/8/20263/9/2026
Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.
AplazadaCrítica (9.8)0.71%—Automation WEB Platform Notifications AND OTP FOR WoocommerceAI21/8/202624/8/2026
The Automation Web Platform – Notifications and OTP for WooCommerce, Advanced Country Code plugin for WordPress is vulnerable to Authentication Bypass in versions up to, and including, 4.8.6. This is due to the handle_email_otp_return() function returning the secret magic login token in the response to a publicly…
AplazadaMedia (5.3)0.35%—Sourcecodester CET Automated Grading System With AI Predictive AnalyticsAI20/8/202624/8/2026
A vulnerability was detected in SourceCodester CET Automated Grading System with AI Predictive Analytics 1.0. This affects the function add_grade of the file /index.php. Performing a manipulation of the argument student_id results in improper authorization. The attack can be initiated remotely.
AplazadaAlta (7.1)0.25%—Nextscripts Social Networks Auto PosterAI19/8/202626/8/2026
The NextScripts: Social Networks Auto-Poster WordPress plugin before 4.4.8 does not escape some of the query-string parameters it reflects back on one of its admin pages, allowing attackers to perform Reflected Cross-Site Scripting attacks against logged-in users such as administrators who are tricked into opening a…