Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
574 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.4) | 0.30% | — | Azeotech Daqfactory | 11/12/2025 | 17/6/2026 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of uninitialized pointer vulnerability can be exploited by an attacker which can lead to arbitrary code execution. | |
| Modificada | Alta (7.3) | 0.22% | — | Azeotech Daqfactory | 11/12/2025 | 17/6/2026 | In AzeoTech DAQFactory release 20.7 (Build 2555), an access of resource using incompatible type vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process. | |
| Modificada | Alta (7.3) | 0.24% | — | Azeotech Daqfactory | 11/12/2025 | 17/6/2026 | In AzeoTech DAQFactory release 20.7 (Build 2555), a use after free vulnerability can be exploited to cause memory corruption while parsing specially crafted .ctl files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (8.4) | 0.35% | — | Azeotech Daqfactory | 11/12/2025 | 30/9/2026 | In AzeoTech DAQFactory release 20.7 (Build 2555), an Out-of-bounds Read vulnerability can be exploited by an attacker to cause the program to read data past the end of an allocated buffer. This could allow an attacker to disclose information or cause a system crash. | |
| Analizada | Media (4.3) | 0.28% | — | Nextcloud Two-factor Webauthn | 5/12/2025 | 17/6/2026 | Nextcloud Twofactor WebAuthn is the WebAuthn Two-Factor Provider for Nextcloud. Prior to 1.4.2 and 2.4.1, a missing ownership check allowed an attack to take-away a 2FA webauthn device when correctly guessing a 80-128 character long random string of letters, numbers and symbols. The victim would then be prompted to… | |
| Aplazada | Media (6.5) | 0.24% | — | Wpfactory Wishlist FOR WoocommerceAI | 25/11/2025 | 17/6/2026 | The Wishlist for WooCommerce plugin for WordPress is vulnerable to Insecure Direct Object Reference in all versions up to, and including, 1.1.3 via several functions in class-th-wishlist-frontend.php due to missing validation on a user controlled key. This makes it possible for unauthenticated attackers to modify… | |
| Aplazada | Media (5.1) | 0.44% | — | Myfactory FMSAI | 24/11/2025 | 17/6/2026 | FMS developed by Otsuka Information Technology has a Reflected Cross-site Scripting vulnerability, allowing unauthenticated remote attackers to execute arbitrary JavaScript codes in user's browser through phishing attacks. | |
| Modificada | Media (6.5) | 0.30% | — | Keyfactor Signserver | 13/11/2025 | 17/6/2026 | A class name enumeration was found in Keyfactor SignServer versions prior to 7.3.2. Setting any chosen class name to any of the properties requiring a class path and the provided class is not expected to return different errors if the class exists in deployment or not. This returns information about the classes loaded… | |
| Modificada | Media (5.3) | 0.25% | — | Keyfactor Signserver | 13/11/2025 | 17/6/2026 | An arbitrary file write was found in Keyfactor SignServer versions prior to 7.3.2. The properties ARCHIVETODISK_FILENAME-PATTERN, ARCHIVETODISK_PATH_BASE, ARCHIVETODISK_PATH_PATTERN can be set to any path, even ones that will point to files that already exist. This vulnerability gives a user with admin access the… | |
| Modificada | Media (5.3) | 0.27% | — | Keyfactor Signserver | 13/11/2025 | 17/6/2026 | A local file enumeration was found in Keyfactor SignServer versions prior to 7.3.2 .The property VISIBLE_SIGNATURE_CUSTOM_IMAGE_PATH, which exists in the PDFSigner and the PAdESSigner, can be set to any path without any restrictions by an admin user. In the case that the provided path points to an existing file,… | |
| Aplazada | Media (6.5) | 0.20% | — | Dfactory Events-makerAI | 27/10/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in dFactory Events Maker by dFactory events-maker allows Stored XSS.This issue affects Events Maker by dFactory: from n/a through <= 1.6.14. | |
| Aplazada | Alta (8.8) | 0.35% | — | Keyy TWO Factor AuthenticationAI | 15/10/2025 | 17/6/2026 | The Keyy Two Factor Authentication (like Clef) plugin for WordPress is vulnerable to privilege escalation via account takeover in all versions up to, and including, 1.2.3. This is due to the plugin not properly validating a user's identity associated with a token generated. This makes it possible for authenticated… | |
| Analizada | Alta (8.5) | 0.18% | — | Rockwellautomation Factorytalk Linx | 14/10/2025 | 17/6/2026 | A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching… | |
| Analizada | Alta (8.5) | 0.18% | — | Rockwellautomation Factorytalk Linx | 14/10/2025 | 17/6/2026 | A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full… | |
| Aplazada | Alta (8.7) | 0.46% | — | Rockwellautomation Factorytalk ViewpointAI | 14/10/2025 | 17/6/2026 | A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service. | |
| Analizada | Alta (8.7) | 0.61% | — | Rockwellautomation Factorytalk View | 14/10/2025 | 17/6/2026 | A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted. | |
| Analizada | Alta (7) | 0.39% | — | Rockwellautomation Factorytalk View | 14/10/2025 | 17/6/2026 | An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more. | |
| Analizada | Alta (8.1) | 0.38% | — | Hiyouga Llama-factory | 7/10/2025 | 17/6/2026 | LLaMA-Factory is a tuning library for large language models. Prior to version 0.9.4, a Server-Side Request Forgery (SSRF) vulnerability in the chat API allows any authenticated user to force the server to make arbitrary HTTP requests to internal and external networks. This can lead to the exposure of sensitive… | |
| Aplazada | Media (5.3) | 0.31% | — | Webfactoryltd WP ResetAI | 7/10/2025 | 17/6/2026 | The WP Reset plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.05 via the WF_Licensing::log() method when debugging is enabled (default). This makes it possible for unauthenticated attackers to extract sensitive license key and site data. | |
| Aplazada | Baja (2) | 1.9% | — | Keyfactor Rg-ew5100beAI | 27/9/2025 | 17/6/2026 | A vulnerability was detected in Keyfactor RG-EW5100BE EW_3.0B11P280_EW5100BE-PRO_12183019. The affected element is an unknown function of the file /cgi-bin/luci/api/cmd of the component HTTP POST Request Handler. The manipulation of the argument url results in command injection. The attack can be launched remotely.… | |
| Aplazada | Media (5.9) | 0.22% | — | Proof Factor LLC Proof Factor Social Proof NotificationsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proof Factor LLC Proof Factor – Social Proof Notifications proof-factor-social-proof-notifications allows Stored XSS.This issue affects Proof Factor – Social Proof Notifications: from n/a through <= 1.0.5. | |
| Aplazada | Media (6.5) | 0.27% | — | Wpfactory AdvertsAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Adverts adverts-click-tracker allows DOM-Based XSS.This issue affects Adverts: from n/a through <= 1.4. | |
| Aplazada | Media (4.3) | 0.25% | — | Wpfactory Helpdesk Support Ticket System FOR WoocommerceAI | 22/9/2025 | 1/10/2026 | Missing Authorization vulnerability in WPFactory Helpdesk Support Ticket System for WooCommerce support-ticket-system-for-woocommerce allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Helpdesk Support Ticket System for WooCommerce: from n/a through <= 2.1.1. | |
| Aplazada | Media (6.5) | 0.17% | — | Wpfactory Product-tabs-for-woocommerceAI | 9/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in WPFactory Additional Custom Product Tabs for WooCommerce product-tabs-for-woocommerce allows Stored XSS.This issue affects Additional Custom Product Tabs for WooCommerce: from n/a through <= 1.7.3. | |
| Analizada | Alta (7.3) | 0.55% | — | Rockwellautomation Factorytalk Optix | 9/9/2025 | 17/6/2026 | A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution. |