Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

4300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.27%—Hcltech Icontrol3/8/20265/8/2026
HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization.
AplazadaBaja (2.9)0.42%—Vxcontrol PentagiAI3/8/202612/8/2026
A weakness has been identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown part of the file backend/pkg/templates/prompts/pentester.tmpl of the component Tool Management Protocol Handler. Executing a manipulation can lead to sandbox issue. It is possible to launch the attack remotely. The attack requires…
AnalizadaMedia (4.8)0.23%—Johnsoncontrols FMS Employee31/7/202610/8/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Johnson Controls FM Systems Employee allows Cross-Site Scripting (XSS). This issue affects FM Systems Employee: before 2025.3.1.
AnalizadaMedia (4.8)0.23%—Johnsoncontrols FMS Employee31/7/202610/8/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Johnson Controls FM Systems Employee allows Stored XSS. This issue affects FM Systems Employee: before 2025.3.1.
AnalizadaMedia (4.8)0.10%—Johnsoncontrols Xaap31/7/202610/8/2026
Cleartext storage of sensitive information vulnerability in Johnson Controls XAAP Application on Android allows an attacker on a jailbroken or otherwise compromised device to Retrieve Sensitive Data. This issue affects XAAP Application: before 1.53.
AnalizadaMedia (4.8)0.50%—Johnsoncontrols FMS Employee31/7/202610/8/2026
Unrestricted upload of file with dangerous type vulnerability in Johnson Controls FM Systems Employee allows Using Malicious Files. This issue affects FM Systems Employee: before 2025.3.1.
AnalizadaMedia (5.3)0.29%—Hcltech Icontrol31/7/20265/8/2026
HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated.
AnalizadaMedia (5.3)0.30%—Hcltech Icontrol31/7/20265/8/2026
HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions.
AnalizadaBaja (3.3)0.14%—Hcltech Icontrol31/7/20265/8/2026
HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
AnalizadaMedia (5.3)0.33%—Hcltech Icontrol31/7/20266/8/2026
HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status
AnalizadaBaja (3.3)0.14%—Hcltech Icontrol31/7/20266/8/2026
HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening.
AplazadaMedia (4.3)0.31%—HCL IcontrolAI31/7/202629/9/2026
HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type.
AplazadaAlta (7.6)0.21%—Watchfire Controller SoftwareAI30/7/20268/9/2026
The affected Watchfire Controller Software contains self-signed hard-coded RSA private keys and corresponding X.509 certificates used for authenticating and encrypting HTTPS/TLS connections to the controller's built-in web management interface. These keys are embedded in plaintext within the application patch binaries…
Pendiente de análisisAlta (8.8)0.80%—Samba Active Directory Domain ControllerAI30/7/202630/7/2026
A security flaw combining LDAP filter injection and improper authorization checks was found in Samba Active Directory Domain Controller (AD DC). When processing LDAP Compare requests, Samba fails to properly validate user-supplied attribute names and executes the resulting internal database search in a trusted…
AplazadaAlta (7.1)0.19%—Mitsubishielectric Melsec MX Controller Mx-rAIMitsubishielectric Melsec MX Controller Mx-fAIMitsubishielectric Cc-link IE TSN Interface BoardAIMitsubishielectric Motion ModuleAI+2530/7/202618/9/2026
Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability in Mitsubishi Electric MELSEC MX Controller MX-R model, MELSEC MX Controller MX-F model, Master/local module, CC-Link IE TSN interface board, Motion module, MELSEC iQ-L Series Motion Module, Motion Control Board,…
AplazadaMedia (6.1)0.27%—WP Real IP Based Access ControlAI30/7/202630/7/2026
The WP Real IP-based Access Control WordPress plugin through 1.3.1 does not perform any capability or nonce checks before storing one of its option values, and does not escape that value on output on its settings page, allowing unauthenticated users to store arbitrary JavaScript that executes in the context of any…
Pendiente de análisisAlta (7.1)0.23%—Kong Kubernetes Ingress ControllerAIKong OperatorAIKong GatewayAI29/7/202630/7/2026
Kong Operator's embedded Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. The embedded KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without…
Pendiente de análisisAlta (7.1)0.23%—Kong Kubernetes Ingress ControllerAI29/7/202630/7/2026
Kong Kubernetes Ingress Controller (KIC) allows a user with namespace-scoped Secret creation privileges to cause a cluster-wide ingress configuration denial of service. KIC collects CA-certificate Secrets across all watched namespaces using a label selector alone, without ingress-class or namespace restrictions. The…
AplazadaAlta (7.1)0.28%—Codesys Profinet ControllerAICodesys ControlAI29/7/202630/7/2026
An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in…
AplazadaMedia (4.8)0.43%—Ericsson Packet Core ControllerAI27/7/202629/9/2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a directory traversal vulnerability in Configuration Management that could allow an attacker to change directory permissions, denying access to legitimate users.
AplazadaMedia (5.1)0.16%—Ericsson Packet Core ControllerAI27/7/202629/9/2026
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain a hardcoded credential vulnerability in the alarm system. An attacker with access to the cluster with knowledge of the hardcoded credential can read alarm and alert information.
AplazadaMedia (4.8)0.23%—Ericsson Packet Core ControllerAI27/7/202629/9/2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain an Exposure of Sensitive System Information vulnerability in Configuration Management allowing an attacker to enumerate other users on the system.
AplazadaMedia (6.8)0.23%—Ericsson Packet Core ControllerAI27/7/202629/9/2026
Ericsson Packet Core Controller (PCC) versions prior to 1.39 contain a vulnerability in Configuration Management, allowing an attacker to execute specifically crafted commands to reveal system secret through error messages.
AplazadaAlta (8.5)0.28%—Ericsson Packet Core ControllerAI27/7/202629/9/2026
Ericsson Packet Core Controller (PCC) versions prior to 1.38 contain an Improper Neutralization of Special Elements vulnerability allowing an attacker to execute arbitrary code as root.
Pendiente de análisisAlta (7.1)0.33%—Johnsoncontrols Victor WEBAI23/7/202630/7/2026
Cwe-269 vulnerability in Johnson Controls victor Web on Windows allows capec-233. This issue affects victor Web: before 7.1.
Orbitaley — Vulnerabilidades