Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
4300 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.49% | — | Johnsoncontrols VictorAIJohnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI | 23/7/2026 | 6/8/2026 | Deserialization of untrusted data vulnerability in Johnson Control victor on Windows, Johnson Controls CCure 9000, and Johnson Controls Victor Application Server allows capec-586. This issue affects victor: before 8.0; CCure 9000: before 3.2; Victor Application Server: before 4.1. | |
| Pendiente de análisis | Alta (7.2) | 0.39% | — | Johnsoncontrols Ccure 9000AIJohnsoncontrols Victor Application ServerAI | 23/7/2026 | 30/7/2026 | Victor SSRF vulnerability in Johnson Controls CCure 9000 and victor application server allows Server Side Request Forgery. This issue affects CCure 9000 and victor application server: from 2.9 through 3.0. | |
| Aplazada | Media (5.3) | 0.31% | — | Code-atlantic Content ControlAI | 23/7/2026 | 23/7/2026 | Unauthenticated Broken Access Control in Content Control <= 2.6.5 versions. | |
| Aplazada | Media (4.3) | 0.25% | — | Mediavine Control PanelAI | 23/7/2026 | 23/7/2026 | Contributor Broken Access Control in Mediavine Control Panel <= 2.10.10 versions. | |
| Aplazada | Baja (1.9) | 1.1% | — | Syncfusion Ej2-javascript-ui-controlsAI | 22/7/2026 | 23/7/2026 | A security vulnerability has been detected in syncfusion ej2-javascript-ui-controls up to 33.2.3. This affects the function child_process.exec of the file package.json. The manipulation leads to os command injection. An attack has to be approached locally. The exploit has been disclosed publicly and may be used. | |
| Analizada | Media (6.4) | 0.31% | — | Oracle Communications Convergent Charging Controller | 21/7/2026 | 17/8/2026 | Vulnerability in the Oracle Communications Convergent Charging Controller product of Oracle Communications (component: Prov IF). Supported versions that are affected are 15.0.0.0.0 and 15.2.0.0.0. Difficult to exploit vulnerability allows high privileged attacker with network access via HTTP to compromise Oracle… | |
| Analizada | Alta (8.7) | 0.52% | — | Progress Sharefile Storage Zones Controller | 21/7/2026 | 3/9/2026 | In Progress ShareFile Storage Zones Controller versions prior to 5.12.5 and 6.0.2, an authenticated administrative user can exploit a path traversal vulnerability to read arbitrary files from the server filesystem, write files to arbitrary directories, or determine whether specific files exist on the server. | |
| Analizada | Media (6.1) | 0.25% | — | Wso2 API Control PlaneWso2 API ManagerWso2 Identity Server | 20/7/2026 | 19/8/2026 | The affected product accepts user-supplied input within a URL parameter without enforcing expected sanitization or encoding before rendering it within the response. This condition allows for the injection of malicious JavaScript payloads. An attacker can leverage this vulnerability to cause the user's browser to… | |
| Analizada | Alta (7) | 0.10% | — | Remote Control FOR Zoom Contact CenterZoom RoomsZoom Workplace DesktopZoom Workplace Virtual Desktop Infrastructure | 16/7/2026 | 17/8/2026 | A time-of-check to time-of-use (TOCTOU) race condition in the installation and uninstallation process of certain Zoom Clients for Windows could allow an authenticated local user to escalate privileges. | |
| Analizada | Alta (8.8) | 0.53% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+2 | 15/7/2026 | 11/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_slice_module module. When the slice directive and unnamed regex captures are configured or when a background cache update happens, unauthenticated attackers can send requests that may cause uninitialized memory access in the NGINX worker process,… | |
| Analizada | Media (6.3) | 0.45% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF | 15/7/2026 | 10/8/2026 | When NGINX Plus is configured to use the Message Queuing Telemetry Transport (MQTT) filter module (ngx_stream_mqtt_filter_module), unauthenticated attackers can send requests with conditions beyond the attacker's control to cause a heap buffer over-read in the NGINX worker process, leading to a restart. Impact: This… | |
| Analizada | Alta (8.3) | 0.42% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF | 15/7/2026 | 10/8/2026 | NGINX Plus and NGINX Open Source have a vulnerability in the ngx_http_ssi_module module. This vulnerability may exist when the Server-Side Includes (SSI), proxy_pass, and proxy_buffering off directives are configured. With this configuration, an unauthenticated attacker with man-in-the-middle (MITM) ability to control… | |
| Analizada | Alta (8.7) | 0.51% | — | F5 Nginx Ingress Controller | 15/7/2026 | 16/7/2026 | When NGINX Ingress Controller is configured with Custom Resource Definitions (CRDs) or Ingress annotations, an injection vulnerability exists in the configuration generator of NGINX Ingress Controller. Multiple user-controllable fields are written into the generated NGINX configuration without sanitization. An… | |
| Analizada | Alta (7.1) | 0.50% | — | F5 Nginx Ingress Controller | 15/7/2026 | 16/7/2026 | When NGINX Ingress Controller processes Ingress or TransportServer resources, an authenticated, remote attacker with permission to create or modify Ingress or TransportServer resources can cause the NGINX Ingress Controller process to terminate. Impact: The NGINX Ingress Controller control plane process terminates and… | |
| Analizada | Crítica (9.2) | 0.89% | 💥 PoC | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx PlusF5 WAF | 15/7/2026 | 10/8/2026 | A vulnerability exists in NGINX Plus and NGINX Open Source when a map directive uses regex matching and a string expression references the map's regex capture variables before referencing the map output variable. Alternatively, the same result could be achieved by using a non-cacheable variable in a string expression… | |
| Aplazada | Media (5.6) | 0.14% | — | Asus System Control Interface V3AIAsus System Control InterfaceAIAsus Business ManagerAI | 15/7/2026 | 17/9/2026 | Out-of-bounds Read in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to read memory regions beyond the intended firmware boundary by supplying a crafted IOCTL request that bypasses the validation. Refer to the ' Security Update for ASUS System… | |
| Aplazada | Alta (8.4) | 0.17% | — | Asus System Control Interface V3AIAsus System Control InterfaceAIAsus Business ManagerAI | 15/7/2026 | 17/9/2026 | Untrusted Pointer Dereference in ASUS System Control Interface v3, ASUS System Control Interface, and ASUS Business Manager allows a local administrator to perform arbitrary physical memory read and write operations via crafted IOCTL requests to the driver, bypassing OS-enforced memory protections. Refer to the '… | |
| Aplazada | Alta (8.2) | 0.16% | 💥 PoC | Asus System Control InterfaceAIAsus Business ManagerAI | 15/7/2026 | 17/9/2026 | Allocation of Resources Without Limits and Throttling and Sensitive Information in Resource Not Removed Before Reuse in the ASUS System Control Interface driver and ASUS Business Manager allow a local administrator to disclose sensitive information via crafted IOCTL requests, which, in severe cases, may lead to a… | |
| Pendiente de análisis | Crítica (9.8) | 0.66% | — | Ciena Navigator Network Control SuiteAICiena Manage Control PlanAICiena Blue PlanetAI | 14/7/2026 | 15/7/2026 | An authentication bypass vulnerability exists in certain releases of Ciena Navigator Network Control Suite (NCS), Manage Control Plan (MCP), and Blue Planet products. The issue is caused by improper handling of HTTP request paths and headers, which allows an unauthenticated attacker to manipulate requests in a manner… | |
| Pendiente de análisis | Crítica (9.8) | 0.48% | — | Ciena Navigator Network Control SuiteAICiena Manage Control PlanAI | 14/7/2026 | 15/7/2026 | In Ciena's Navigator Network Control Suite (NCS) and Manage Control Plan (MCP), there are hidden system accounts used for internal software operations. Some of these accounts have default passwords that may be predictable. While these accounts have very limited permissions on their own, an attacker could combine an… | |
| Pendiente de análisis | Media (5.8) | 0.65% | — | Amazon AWS Load Balancer ControllerAI | 14/7/2026 | 15/7/2026 | Incorrect behavior order in the Gateway API listener-rule generation in Amazon AWS Load Balancer Controller before 3.4.2 might allow an authenticated remote user to intercept, spoof, or deny another namespace's gRPC traffic on a shared Gateway via a crafted HTTPRoute resource. To mitigate this issue, users should… | |
| Pendiente de análisis | Alta (8.2) | 0.22% | — | Allen Bradley Compactlogix 5380AIAllen Bradley Controllogix 5580AIAllen Bradley EN4 Communication ModuleAI | 14/7/2026 | 14/7/2026 | A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a… | |
| Pendiente de análisis | Crítica (9.2) | 0.43% | — | 5380 ControllerAI5480 ControllerAI5580 ControllerAI | 14/7/2026 | 29/9/2026 | A denial-of-service issue exists in 5380/5480/5580 controllers. This vulnerability could potentially allow a malicious user to write invalid file data to the controller, causing the device to enter a major non-recoverable fault (MNRF). | |
| Pendiente de análisis | Crítica (9.2) | 0.43% | — | Siemens Simatic S7-1500 Software Controller 5370AISiemens Simatic S7-1500 Software Controller 5570AI | 14/7/2026 | 29/9/2026 | A denial-of-service issue exists in 5370/5570 controllers. This vulnerability could potentially allow a remote user to load an invalid project, causing the device to enter a major non-recoverable fault (MNRF). | |
| Aplazada | Alta (8.5) | 0.16% | — | Gigabyte Control CenterAIGigabyte Mbstorage DramAI | 13/7/2026 | 14/7/2026 | The MBStorage DRAM lighting control module within Gigabyte Control Center (GCC) developed by GIGABYTE Technology has an Improper Access Control vulnerability. Authenticated local attackers can send specific IOCTL commands through the driver MyPortIO_x64.sys bundled with the module, thereby arbitrarily reading and… |