Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.15% | — | Rockwellautomation Factorytalk Services PlatformAI | 14/7/2026 | 14/7/2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to "none" and… | |
| Analizada | Alta (7) | 0.27% | — | Rockwellautomation Arena | 14/7/2026 | 15/7/2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Analizada | Alta (7) | 0.27% | — | Rockwellautomation Arena | 14/7/2026 | 15/7/2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Analizada | Alta (7) | 0.27% | — | Rockwellautomation Arena | 14/7/2026 | 15/7/2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Analizada | Alta (7) | 0.27% | — | Rockwellautomation Arena | 14/7/2026 | 15/7/2026 | A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in… | |
| Pendiente de análisis | Crítica (10) | 0.41% | — | Rockwellautomation 1715-aentrAI | 14/7/2026 | 14/7/2026 | A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If exploited, a threat actor could read or delete… | |
| Aplazada | Media (5.3) | 0.56% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 14/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to authorization bypass in all versions up to, and including, 1.4.12. This is due to the plugin not properly verifying that a user is authorized to perform an action. This makes it possible for unauthenticated attackers to publish draft… | |
| Aplazada | Media (5.3) | 0.52% | — | Aiwu AI Chatbot Workflow AutomationAI | 11/7/2026 | 15/7/2026 | The AI Chatbot & Workflow Automation by AIWU plugin for WordPress is vulnerable to Missing Authorization in all versions up to, and including, 1.4.12. This is due to missing capability checks and nonce verification on AJAX actions registered under both wp_ajax_ and wp_ajax_nopriv_ hooks, as the base controller's… | |
| Aplazada | Crítica (9.8) | 0.48% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows SQL Injection. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (8.8) | 0.45% | — | Adam Retail Automation LTD Mobilmen 20TAI | 10/7/2026 | 10/7/2026 | Authorization bypass through User-Controlled key vulnerability in Adam Retail Automation Ltd. MobilMen 20T allows Privilege Escalation. This issue affects MobilMen 20T: from v3 through 10072026. NOTE: The vendor was contacted early about this disclosure but did not respond in any way. | |
| Aplazada | Alta (8.4) | 0.16% | — | BR Industrial Automation AprolAI | 6/7/2026 | 6/7/2026 | Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. | |
| Aplazada | Crítica (9.1) | 0.22% | — | B AND R Industrial Automation Gmbh AprolAI | 6/7/2026 | 6/7/2026 | Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. | |
| Analizada | Crítica (9.1) | 0.41% | — | IBM Business Automation Manager | 30/6/2026 | 2/7/2026 | IBM Business Automation Manager Open Editions 9.0.0 through 9.4.2 is vulnerable to an XML external entity injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. | |
| Analizada | Media (6.5) | 0.33% | — | IBM Devops AutomationIBM Devops Loop | 30/6/2026 | 6/10/2026 | IBM DevOps Automation 1.0.1 and IBM DevOps Loop 1.0.2 does not invalidate session IDs after expiration which could allow an authenticated user to impersonate another user on the system. | |
| Aplazada | Alta (7.5) | 0.66% | — | Mz-automation Lib60870AI | 29/6/2026 | 4/8/2026 | A heap buffer overflow in the HighPriorityASDUQueue_hasUnconfirmedIMessages function of lib60870 v2.3.3 to v2.3.6 allows attackers to cause a Denial of Service (DoS) via a crafted payload. | |
| Aplazada | Alta (8.4) | 0.18% | — | Hornerautomation CscapeAI | 25/6/2026 | 25/6/2026 | Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code. | |
| Pendiente de análisis | Media (6.3) | 0.45% | — | Rockwellautomation CompactlogixAI | 16/6/2026 | 17/6/2026 | A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct… | |
| Pendiente de análisis | Alta (8.8) | 0.43% | — | Rockwellautomation 1794-aentrAI | 16/6/2026 | 17/6/2026 | An improper authentication security issue exists within the 1794-AENTR adapter's embedded web server. The vulnerability allows an unauthenticated attacker to change the device's web interface password by sending a crafted HTTP GET request to a specific endpoint, without any prior authentication being required. If… | |
| Pendiente de análisis | Crítica (9.2) | 0.29% | — | Rockwellautomation Factorytalk Historian Site EditionAI | 16/6/2026 | 7/10/2026 | An authentication bypass security issue exists within FactoryTalk Historian Site Edition. By continually sending requests to the login endpoint, an attacker may obtain a valid authentication token. | |
| Aplazada | Alta (7.1) | 0.40% | — | Funnelkit AutomationsAI | 15/6/2026 | 17/6/2026 | Subscriber Broken Authentication in FunnelKit Automations <= 3.7.3 versions. | |
| Modificada | Alta (7.7) | 1.0% | — | AxiosRedhat Advanced Cluster Management FOR KubernetesRedhat Advanced Cluster SecurityRedhat Ansible Automation Platform+8 | 11/6/2026 | 11/9/2026 | Axios is a promise based HTTP client for the browser and Node.js. From 0.19.0 to before 0.31.1 and 1.15.2, Axios contains prototype-pollution gadgets in request config processing. If another vulnerability in the same JavaScript process has already polluted Object.prototype.transformResponse, affected Axios versions… | |
| Modificada | Alta (7.5) | 0.99% | — | Js-cookie Javascript CookieRedhat 3scale API ManagementRedhat Ansible Automation PlatformRedhat Openshift AI+2 | 10/6/2026 | 9/9/2026 | JavaScript Cookie is a JavaScript API for handling cookies, client-side. Prior to version 3.0.7, js-cookie's internal assign() helper copies properties with for...in + plain assignment. When the source object is produced by JSON.parse, the JSON object's "__proto__" member is an own enumerable property, so the for…in… | |
| Aplazada | Crítica (9.8) | 0.50% | — | Akmer Informatics Automation Industry AND Trade TeknopassAI | 4/6/2026 | 22/7/2026 | Authorization bypass through User-Controlled SQL primary key vulnerability in Akmer Informatics Automation Industry and Trade Ltd. Co. TeknoPass allows SQL Injection. This issue affects TeknoPass: from 20210501 through 20260429. | |
| Analizada | Media (4.3) | 0.22% | — | IBM Business Automation Workflow | 27/5/2026 | 17/6/2026 | IBM Business Automation Workflow containers and traditional may leak information about its database structure in error messages. | |
| Analizada | Media (6.5) | 7.1% | ⚠ Explotación activa💥 Exploit | Encode StarletteRedhat AI Inference ServerRedhat Ansible Automation PlatformRedhat Migration Toolkit FOR Applications+4 | 26/5/2026 | 1/10/2026 | Starlette is a lightweight ASGI framework/toolkit. Prior to version 1.0.1, the HTTP `Host` request header was not validated before being used to reconstruct `request.url`. Because the routing algorithm relies on the raw HTTP path while `request.url` is rebuilt from the `Host` header, a malformed header could make… |