Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

2405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.8)0.15%—Rockwellautomation Factorytalk Services PlatformAI14/7/202614/7/2026
A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and…
AnalizadaAlta (7)0.27%—Rockwellautomation Arena14/7/202615/7/2026
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in…
AnalizadaAlta (7)0.27%—Rockwellautomation Arena14/7/202615/7/2026
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in…
AnalizadaAlta (7)0.27%—Rockwellautomation Arena14/7/202615/7/2026
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in…
AnalizadaAlta (7)0.27%—Rockwellautomation Arena14/7/202615/7/2026
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in…
Pendiente de análisisCrítica (10)0.41%—Rockwellautomation 1715-aentrAI14/7/202614/7/2026
A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete…
AplazadaMedia (5.3)0.56%—Aiwu AI Chatbot Workflow AutomationAI11/7/202614/7/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft…
AplazadaMedia (5.3)0.52%—Aiwu AI Chatbot Workflow AutomationAI11/7/202615/7/2026
The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's…
AplazadaCrítica (9.8)0.48%—Adam Retail Automation LTD Mobilmen 20TAI10/7/202610/7/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaAlta (8.8)0.45%—Adam Retail Automation LTD Mobilmen 20TAI10/7/202610/7/2026
Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way.
AplazadaAlta (8.4)0.16%—BR Industrial Automation AprolAI6/7/20266/7/2026
Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
AplazadaCrítica (9.1)0.22%—B AND R Industrial Automation Gmbh AprolAI6/7/20266/7/2026
Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5.
AnalizadaCrítica (9.1)0.41%—IBM Business Automation Manager30/6/20262/7/2026
IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources.
AnalizadaMedia (6.5)0.33%—IBM Devops AutomationIBM Devops Loop30/6/20266/10/2026
IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system.
AplazadaAlta (7.5)0.66%—Mz-automation Lib60870AI29/6/20264/8/2026
A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload.
AplazadaAlta (8.4)0.18%—Hornerautomation CscapeAI25/6/202625/6/2026
Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code.
Pendiente de análisisMedia (6.3)0.45%—Rockwellautomation CompactlogixAI16/6/202617/6/2026
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct…
Pendiente de análisisAlta (8.8)0.43%—Rockwellautomation 1794-aentrAI16/6/202617/6/2026
An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If…
Pendiente de análisisCrítica (9.2)0.29%—Rockwellautomation Factorytalk Historian Site EditionAI16/6/20267/10/2026
An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token.
AplazadaAlta (7.1)0.40%—Funnelkit AutomationsAI15/6/202617/6/2026
Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions.
ModificadaAlta (7.7)1.0%—AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+811/6/202611/9/2026
Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions…
ModificadaAlta (7.5)0.99%—Js-cookie Javascript CookieRedhat 3scale API ManagementRedhat Ansible Automation PlatformRedhat Openshift AI+210/6/20269/9/2026
JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in…
AplazadaCrítica (9.8)0.50%—Akmer Informatics Automation Industry AND Trade TeknopassAI4/6/202622/7/2026
Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429.
AnalizadaMedia (4.3)0.22%—IBM Business Automation Workflow27/5/202617/6/2026
IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages.
AnalizadaMedia (6.5)7.1%⚠ Explotación activa💥 ExploitEncode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+426/5/20261/10/2026
Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make…