Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
882 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (2) | 0.11% | — | Vmware EsxiAIIntel Ethernet 800 SeriesAI | 10/2/2026 | 17/6/2026 | Improper initialization for some ESXi kernel mode driver for the Intel(R) Ethernet 800-Series before version 2.2.2.0 (esxi 8.0) & 2.2.3.0 (esxi 9.0) within Ring 1: Device Drivers may allow an information disclosure. Unprivileged software adversary with an authenticated user combined with a low complexity attack… | |
| Aplazada | Baja (1) | 0.16% | — | Silabs Series 2AI | 9/2/2026 | 17/6/2026 | DPA countermeasures in Silicon Labs' Series 2 devices are not reseeded under certain conditions. This may allow an attacker to eventually extract secret keys through a DPA attack. | |
| Aplazada | Crítica (9.3) | 0.55% | — | Kiloview Encoder SeriesAI | 29/1/2026 | 17/6/2026 | A missing authentication for critical function vulnerability in KiloView Encoder Series could allow an unauthenticated attacker to create or delete administrator accounts. This vulnerability can grant the attacker full administrative control over the product. | |
| Analizada | Alta (7.8) | 0.36% | 💥 PoC | Steelseries Nahimic | 16/1/2026 | 17/6/2026 | SteelSeries Nahimic 3 1.10.7 allows Directory traversal. | |
| Aplazada | Alta (8.7) | 1.6% | — | TOA Corporation Trifora 3 SeriesAI | 16/1/2026 | 17/6/2026 | OS Command Injection vulnerability exists in multiple Network Cameras TRIFORA 3 series provided by TOA Corporation, which may allow a logged-in user with the low("monitoring user") or higher privilege to execute an arbitrary OS command. | |
| Aplazada | Crítica (9.3) | 12% | — | Flir Thermal Camera Pt-series FirmwareAI | 8/1/2026 | 17/6/2026 | FLIR Thermal Camera PT-Series firmware version 8.0.0.64 contains multiple unauthenticated remote command injection vulnerabilities in the controllerFlirSystem.php script. Attackers can execute arbitrary system commands as root by exploiting unsanitized POST parameters in the execFlirSystem() function through… | |
| Aplazada | Media (6.5) | 0.17% | — | Justintadlock SeriesAI | 31/12/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Justin Tadlock Series series allows Stored XSS.This issue affects Series: from n/a through <= 2.0.1. | |
| Aplazada | Media (6.9) | 0.39% | — | Guralp Fortimus SeriesAIGuralp Minimus SeriesAIGuralp Certimus SeriesAI | 16/12/2025 | 17/6/2026 | A vulnerability in the web interface of the Güralp Fortimus Series, Minimus Series and Certimus Series allows an unauthenticated attacker with network access to send specially-crafted HTTP requests that can cause the web service process to deliberately restart. Although this mechanism limits the impact of the attack,… | |
| Aplazada | Media (6.3) | 0.46% | — | Mxsecurity SeriesAI | 10/12/2025 | 17/6/2026 | An unauthenticated device registration vulnerability, caused by Improperly Controlled Modification of Dynamically-Determined Object Attributes, has been identified in the MXsecurity Series. An unauthenticated remote attacker can exploit this vulnerability by sending a specially crafted JSON payload to the device's… | |
| Aplazada | Alta (8.7) | 0.37% | — | Automation Systems Engineering 432es-ig3 Series AAIAutomation Systems Engineering Guardlink Ethernet IP InterfaceAI | 9/12/2025 | 17/6/2026 | A security issue exists within 432ES-IG3 Series A, which affects GuardLink® EtherNet/IP Interface, resulting in denial-of-service. A manual power cycle is required to recover the device. | |
| Aplazada | Media (6.6) | 0.56% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Pa-seriesAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Prisma AccessAI | 13/11/2025 | 17/6/2026 | A denial-of-service (DoS) vulnerability in Palo Alto Networks PAN-OS software enables an unauthenticated attacker to reboot a firewall by sending a specially crafted packet through the dataplane. Repeated attempts to initiate a reboot causes the firewall to enter maintenance mode. This issue is applicable to the… | |
| Aplazada | Alta (8.4) | 0.13% | — | Intel ARC B-series GpusAI | 11/11/2025 | 17/6/2026 | Incorrect default permissions in some firmware for the Intel(R) Arc(TM) B-series GPUs within Ring 1: Device Drivers may allow an escalation of privilege. System software adversary with a privileged user combined with a low complexity attack may enable escalation of privilege. This result may potentially occur via… | |
| Aplazada | Media (5.3) | 0.45% | — | Mitsubishi Electric Corporation Melsec Iq-f Series CPU ModuleAI | 6/11/2025 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in TCP Communication Function on Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote attacker to disconnect the connection by sending specially crafted TCP packets to cause a denial-of-service (DoS) condition on the products.… | |
| Aplazada | Crítica (9.8) | 0.56% | — | Geutebruck G-cam E-seriesAIGeutebruck Efd-2130AI | 3/11/2025 | 17/6/2026 | An unauthenticated SQL Injection was discovered within the Geutebruck G-Cam E-Series Cameras through the `Group` parameter in the `/uapi-cgi/viewer/Param.cgi` script. This has been confirmed on the EFD-2130 camera running firmware version 1.12.0.19. | |
| Aplazada | Media (6.9) | 0.32% | — | Century Systems Futurenet MAAICentury Systems Ip-k SeriesAI | 31/10/2025 | 17/6/2026 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. put the firmware version and the garbage collection information on the internal web page. With some crafted HTTP request, they can be accessed without authentication. | |
| Aplazada | Alta (8.6) | 1.2% | — | Century Systems Futurenet MAAICentury Systems Ip-k SeriesAI | 31/10/2025 | 17/6/2026 | FutureNet MA and IP-K series provided by Century Systems Co., Ltd. contain an OS command Injection vulnerability. A user who logs in to the Web UI of the product may execute an arbitrary OS command. | |
| Aplazada | Media (6.8) | 0.23% | — | Honeywell S35 Series CamerasAI | 27/10/2025 | 17/6/2026 | Honeywell S35 Series Cameras contains an authorization bypass Vulnerability through User controller key. An attacker could potentially exploit this vulnerability, leading to Privilege Escalation to admin privileged functionalities . Honeywell also recommends updating to the most recent version of this product, service… | |
| Aplazada | Crítica (9.3) | 0.55% | — | Novakon P SeriesAI | 23/9/2025 | 17/6/2026 | — | |
| Aplazada | Crítica (9.4) | 0.22% | — | Novakon P SeriesAI | 23/9/2025 | 17/6/2026 | — | |
| Aplazada | Alta (7.3) | 0.36% | — | Novakon P SeriesAI | 23/9/2025 | 30/9/2026 | — | |
| Aplazada | Alta (8.6) | 0.22% | — | Novakon P SeriesAI | 23/9/2025 | 25/9/2026 | No password for the root user is set in Novakon P series. This allows phyiscal attackers to enter the console easily. This issue affects P series: P – V2001.A.C518o2 until P-2.0.05 Build 2026.02.06 (commit d0f97fd9). | |
| Aplazada | Crítica (10) | 1.1% | — | Novakon P SeriesAI | 23/9/2025 | 25/9/2026 | — | |
| Aplazada | Media (6.8) | 1.0% | — | Mitsubishi Electric Corporation Melsec-q Series Q03udvcpuAIMitsubishi Electric Corporation Melsec-q Series Q04udvcpuAIMitsubishi Electric Corporation Melsec-q Series Q06udvcpuAIMitsubishi Electric Corporation Melsec-q Series Q13udvcpuAI+5 | 19/9/2025 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric Corporation MELSEC-Q Series Q03UDVCPU, Q04UDVCPU, Q06UDVCPU, Q13UDVCPU, Q26UDVCPU, Q04UDPVCPU, Q06UDPVCPU, Q13UDPVCPU, and Q26UDPVCPU with the first 5 digits of serial No. "24082" to "27081" allows a remote attacker to cause an… | |
| Aplazada | Crítica (9.8) | 0.88% | — | Sophos AP6 Series Wireless Access PointAI | 9/9/2025 | 17/6/2026 | An authentication bypass vulnerability allows remote attackers to gain administrative privileges on Sophos AP6 Series Wireless Access Points older than firmware version 1.7.2563 (MR7). | |
| Analizada | Alta (7.1) | 0.68% | — | Rockwellautomation 1756-en2tr Series A FirmwareRockwellautomation 1756-en2tr Series B FirmwareRockwellautomation 1756-en2tr Series C FirmwareRockwellautomation 1756-en4tr Firmware+1 | 9/9/2025 | 17/6/2026 | A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash. |