Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
882 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.25% | — | Rockwellautomation 1756-en2tr Series A FirmwareRockwellautomation 1756-en2tr Series B FirmwareRockwellautomation 1756-en2tr Series C FirmwareRockwellautomation 1756-en4tr Firmware+1 | 9/9/2025 | 17/6/2026 | A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability. | |
| Aplazada | Media (6.3) | 0.27% | — | Johnsoncontrols Apogee PXC Series BacnetAIJohnsoncontrols Apogee PXC Series P2 EthernetAIJohnsoncontrols Talon TC Series BacnetAI | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices connected to the network allow unrestricted access to sensitive files, such as databases. This could allow an attacker to download… | |
| Aplazada | Crítica (9.1) | 0.69% | — | SAP NetweaverAIIBM I-seriesAI | 9/9/2025 | 17/6/2026 | Due to a missing authentication check in the SAP NetWeaver application on IBM i-series, the application allows high privileged unauthorized users to read, modify, or delete sensitive information, as well as access administrative or privileged functionalities. This results in a high impact on the confidentiality,… | |
| Aplazada | Alta (7.3) | 0.46% | — | Mitsubishi Electric Corporation Melsec Iq-f Series CPU ModuleAI | 1/9/2025 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series CPU module allows a remote unauthenticated attacker to read or write the device values of the product and stop the operation of the programs, since MODBUS/TCP in the products does not have authentication… | |
| Aplazada | Media (5) | 0.35% | — | Cisco Nexus 3000 Series SwitchesAICisco Nexus 9000 Series SwitchesAICisco Nx-osAI | 27/8/2025 | 17/6/2026 | A vulnerability in the Protocol Independent Multicast Version 6 (PIM6) feature of Cisco Nexus 3000 Series Switches and Cisco Nexus 9000 Series Switches in standalone NX-OS mode could allow an authenticated, low-privileged, remote attacker to trigger a crash of the PIM6 process, resulting in a denial of service (DoS)… | |
| Aplazada | Media (6.8) | 0.27% | — | Danfoss Ak-sm8xxa SeriesAI | 22/8/2025 | 17/6/2026 | Post-authenticated external control of system web interface configuration setting vulnerability in Danfoss AK-SM8xxA Series prior to 4.3.1, which could allow for a denial of service attack induced by improper handling of exceptional conditions | |
| Aplazada | Alta (8.7) | 0.96% | — | Danfoss Ak-sm8xxa SeriesAI | 22/8/2025 | 17/6/2026 | Improper neutralization of alarm-to-mail configuration fields used in an OS shell Command ('Command Injection') in Danfoss AK-SM8xxA Series prior to version 4.3.1, leading to a potential post-authenticated remote code execution on an attacked system. | |
| Analizada | Media (6.5) | 1.2% | — | Microsoft Ecesv6-series Azure VM FirmwareMicrosoft Dcesv6-series Azure VM FirmwareMicrosoft Nccadsh100v5-series Azure VM FirmwareMicrosoft Ecedsv5-series Azure VM Firmware+7 | 12/8/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Azure Virtual Machines allows an authorized attacker to disclose information over a network. | |
| Analizada | Media (5.5) | 0.45% | — | Microsoft Ecesv6-series Azure VM FirmwareMicrosoft Dcesv6-series Azure VM FirmwareMicrosoft Nccadsh100v5-series Azure VM FirmwareMicrosoft Ecedsv5-series Azure VM Firmware+7 | 12/8/2025 | 17/6/2026 | Improper access control in Azure Virtual Machines allows an authorized attacker to perform spoofing locally. | |
| Aplazada | Media (4.8) | 0.14% | — | Intel 700 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable denial of service. | |
| Aplazada | Media (4.8) | 0.14% | — | Intel 700 Series Ethernet Kernel-mode DriverAI | 12/8/2025 | 17/6/2026 | Uncontrolled resource consumption in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable denial of service. | |
| Aplazada | Alta (8.8) | 0.13% | — | Intel 700 Series EthernetAI | 12/8/2025 | 17/6/2026 | Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (4.1) | 0.14% | — | Intel Graphics Driver ARC B-seriesAI | 12/8/2025 | 17/6/2026 | Protection mechanism failure in the Intel(R) Graphics Driver for the Intel(R) Arc(TM) B-Series graphics before version 32.0.101.6737 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Baja (2) | 0.14% | — | Intel I350 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Improper initialization in the Linux kernel-mode driver for some Intel(R) I350 Series Ethernet before version 5.19.2 may allow an authenticated user to potentially enable Information disclosure via data exposure. | |
| Aplazada | Alta (8.8) | 0.14% | — | Intel 700 Series Ethernet Kernel DriverAI | 12/8/2025 | 17/6/2026 | Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.8) | 0.14% | — | Intel 800 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Crítica (9.3) | 0.14% | — | Intel 800 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Improper input validation in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Baja (2) | 0.12% | — | Intel 800 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Integer overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.8) | 0.13% | — | Intel 800 Series EthernetAI | 12/8/2025 | 17/6/2026 | Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.4) | 0.14% | — | Intel 800 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Integer overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Alta (8.8) | 0.13% | — | Intel 800 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Insufficient control flow management in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (8.8) | 0.13% | — | Intel 800 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Integer overflow or wraparound in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.9) | 0.13% | — | Intel 700 Series EthernetAILinux KernelAI | 12/8/2025 | 17/6/2026 | Improper input validation in the Linux kernel-mode driver for some Intel(R) 700 Series Ethernet before version 2.28.5 may allow an authenticated user to potentially enable escalation of privilege. | |
| Aplazada | Alta (8.6) | 0.14% | — | Intel 800 Series Ethernet Kernel-mode DriverAI | 12/8/2025 | 17/6/2026 | Improper check for unusual or exceptional conditions in the Linux kernel-mode driver for some Intel(R) 800 Series Ethernet before version 1.17.2 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Media (6.5) | 53% | 💥 Exploit | Mitel 6800 Series SIP PhonesAIMitel 6900 Series SIP PhonesAIMitel 6900w Series SIP PhonesAIMitel 6970 Conference UnitAI | 7/8/2025 | 17/6/2026 | A vulnerability in the Mitel 6800 Series, 6900 Series, and 6900w Series SIP Phones through 6.4 SP4 (R6.4.0.4006), and the 6970 Conference Unit through 6.4 SP4 (R6.4.0.4006) or version V1 R0.1.0, could allow an unauthenticated attacker to conduct a command injection attack due to insufficient parameter sanitization. A… |