Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
–

4300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.3)0.36%—Armiya Information Technologies LTD Access Control SystemAI10/9/202610/9/2026
URL redirection to untrusted site ('open redirect') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows Fake the Source of Data. This issue affects Access Control System: before Versiyon 2.
AplazadaCrítica (9.8)0.47%—Armiya Information Technologies LTD Access Control SystemAI10/9/202610/9/2026
Improper neutralization of special elements used in an SQL command ('SQL injection') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System allows SQL Injection. This issue affects Access Control System: before Versiyon 2.
AplazadaMedia (5.3)0.46%—Flux Source ControllerAIKubernetesAIFlux Kustomize ControllerAIFlux Helm ControllerAI8/9/202630/9/2026
The source-controller is a Kubernetes operator, specialised in artifacts acquisition from external sources such as Git, OCI, Helm repositories and S3-compatible buckets. In versions 0.0.17 through 1.8.4, an actor with the ability to influence the contents of a bucket referenced by a `Bucket` resource can cause…
AplazadaMedia (6.9)0.67%—Tp-link Omada ControllerAI8/9/202621/9/2026
An information disclosure vulnerability has been identified in Omada Controller. An API endpoint intended for Controller initialization remains accessible after completion and may disclose account-related information to unauthenticated remote users. Successful exploitation may allow an attacker to remote query the…
AplazadaAlta (8.9)0.32%—Siveillance Control PRO V3.0AISiveillance Control PRO V4.0AISiveillance Control V3.0AISiveillance Control V4.0AI8/9/20268/9/2026
A vulnerability has been identified in Siveillance Control Pro V3.0 (All versions < V3.0.12.2173), Siveillance Control Pro V4.0 (All versions < V4.0.9.2178), Siveillance Control V3.0 (All versions < V3.0.22.2177), Siveillance Control V4.0 (All versions < V4.0.11.2177). A vulnerability in the OIS web module allows an…
AplazadaAlta (7.7)0.20%—Asus Control Center Express AgentAI8/9/202628/9/2026
Missing authentication for a critical function in ASUS Control Center Express Agent allows an unauthenticated nearby user to control the host via a direct connection to the agent when the host has an active login session. Refer to the ' Security Update for ASUS Control Center Express Agent ' section on the ASUS…
Pendiente de análisisAlta (7.5)0.25%—IBM Verify Identity Access Advanced Access ControlAI4/9/20268/9/2026
IBM Verify Identity Access Advanced Access Control may be vulnerable to an information disclosure attack.
AplazadaAlta (8.5)0.15%—Jalinfotec Pallet ControlAI4/9/20268/9/2026
PALLET CONTROL products contain an incorrect default permission vulnerability, which may allow a local attacker to execute arbitrary code with SYSTEM privileges on the affected product.
AplazadaCrítica (10)0.34%—Asus Control CenterAI4/9/202617/9/2026
Missing Authentication for Critical Function, Server-Side Request Forgery (SSRF), and Use of Hard-coded Credentials in ASUS Control Center allow an unauthorized user to obtain the encryption key via an HTTP request, causing a local service to enable SSH on port 2222. The attacker can then log in with the hardcode…
AnalizadaAlta (8.4)0.22%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+43/9/20269/9/2026
The administrative operations within the Carbon Console do not adequately validate specific user-supplied input. This oversight allows a malicious actor with administrative privileges to inject and execute arbitrary code remotely. Successful exploitation enables a threat actor with administrative privileges and Carbon…
AnalizadaAlta (7.5)0.36%—Wso2 API Control PlaneWso2 API Manager3/9/202615/9/2026
The API Publisher component previously used a non-cryptographic pseudorandom number generator (PRNG) to create shared secrets for Webhook HMAC validation. This PRNG lacks sufficient entropy for security-sensitive operations, allowing a sophisticated attacker to predict future secrets. This enables malicious actors to…
Pendiente de análisisAlta (8.7)0.50%—Nginx Ingress ControllerAI2/9/20263/9/2026
When NGINX Ingress Controller is configured with Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An authenticated attacker with permission to…
AnalizadaBaja (2.3)0.23%—F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+172/9/202615/9/2026
A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages Impact: An attacker may trick authenticated BIG-IP users into accessing malicious links and reflect a spoofed error message in the victim's BIG-IP Configuration utility web browser session.…
AplazadaCrítica (9.3)3.2%—Proxmox Virtual EnvironmentAIProxmox Libpve-access-controlAI1/9/20268/9/2026
Proxmox Virtual Environment (VE) 7.0 through 8.0 contains an authentication bypass vulnerability in libpve-access-control before 8.0.4 that allows unauthenticated attackers to authenticate as any existing enabled user without a configured second factor by supplying an arbitrary tfa-challenge value in the API login…
Pendiente de análisisAlta (7)0.12%—ControlflashAI1/9/20261/9/2026
A security issue exists within ControlFLASH™, where the installer grants write permissions to the "Everyone" group on a product installation directory. This could allow arbitrary code execution, resulting in an attacker being given the ability to run any commands or code of the attacker's choice on a target machine at…
Pendiente de análisisMedia (5.2)0.19%—Johnsoncontrols T2000AI27/8/20263/9/2026
Debug and Test Interface With Improper Access Control vulnerability in Johnson Controls T2000 allows Accessing Functionality Not Properly Constrained by ACLs. This issue affects T2000: before 31.6.
AplazadaCrítica (9.8)0.56%—Infinitumform GEO ControllerAI27/8/202628/8/2026
Unauthenticated PHP Object Injection in Geo Controller <= 8.9.8 versions.
Pendiente de análisisMedia (6.1)0.40%—Johnsoncontrols MetasysAI24/8/20263/9/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls Metasys 14 and Johnson Controls Metasys 15 allows Cross Site Scripting. This issue affects Metasys 14: before 14.1.5; Metasys 15: before 15.0.1.
Pendiente de análisisMedia (6.9)0.08%—Johnsoncontrols Simplex Incident ManagerAIJohnsoncontrols Autocall Fire AdministratorAI21/8/20263/9/2026
Cleartext Storage of Sensitive Information in Memory vulnerability in Johnson Controls Simplex Incident Manager / Autocall Fire Administrator may allow an attcker to Retrieve Embedded Sensitive Data. This issue affects Simplex Incident Manager / Autocall Fire Administrator: before 2.01.05.
Pendiente de análisisAlta (7.7)0.63%—Redhat Multicluster EngineAIRedhat Clusterclaims ControllerAI21/8/202629/9/2026
A flaw was found in the clusterclaims-controller component of multicluster engine (MCE). A tenant with standard permissions to create and delete ClusterClaim resources can exploit this by manipulating the `spec.namespace` field. This allows the tenant to specify and delete any ManagedCluster, including the hub's…
Pendiente de análisisMedia (6.2)0.54%—Volsync Addon-controllerAIRedhat Openshift Lifecycle ManagerAI19/8/20268/9/2026
A flaw was found in volsync-addon-controller. This vulnerability allows an attacker to inject malicious YAML (Yet Another Markup Language) code into the OpenShift Lifecycle Manager (OLM) Subscription resource. This is due to improper escaping of annotation values when they are rendered into YAML. Successful…
AnalizadaCrítica (9.3)23%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway19/8/202610/9/2026
Vulnerability in NetScaler ADC and NetScaler Gateway. This issue affects ADC: from 14.1 through 73.32 and from 13.1 through 63.21; Gateway: from 14.1 through 73.32 and from 13.1 through 63.21.
AnalizadaAlta (8.1)0.36%—Oracle Project Planning AND Control18/8/202628/8/2026
Vulnerability in the Oracle Project Planning and Control product of Oracle E-Business Suite (component: Change Management). Supported versions that are affected are 12.2.3-12.2.15. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Project Planning and…
Pendiente de análisisAlta (8.8)0.81%—Redhat Advanced Cluster Management FOR KubernetesAIRedhat Governance Policy Addon ControllerAI18/8/202627/8/2026
A flaw was found in the governance-policy-addon-controller component of Red Hat Advanced Cluster Management for Kubernetes. A user with permissions to annotate the namespaced ManagedClusterAddOn resource can override the governance-policy container image. This allows an attacker to run a controlled image with…
Pendiente de análisisCrítica (9.9)0.49%—Open Cluster Management Managedcluster Import ControllerAI17/8/202629/9/2026
A flaw was found in the managedcluster-import-controller. The Certificate Signing Request (CSR) auto-approval logic improperly validates incoming CSRs, specifically by not inspecting the signer name or decoding the PEM-encoded x509 CSR. This vulnerability allows a privileged service account on a spoke cluster to…