Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2783▼ 434 respecto a la semana anterior
Críticas / altas1335▼ 118 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

923 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (4.3)0.34%—GomatrixserverlibAI16/1/202517/6/2026
Gomatrixserverlib is a Go library for matrix federation. Gomatrixserverlib is vulnerable to server-side request forgery, serving content from a private network it can access, under certain conditions. The commit `c4f1e01` fixes this issue. Users are advised to upgrade. Users unable to upgrade should use a local…
AnalizadaCrítica (9.8)99%⚠ Explotación activa💥 ExploitAviatrix Controller8/1/202517/6/2026
An issue was discovered in Aviatrix Controller before 7.1.4191 and 7.2.x before 7.2.4996. Due to the improper neutralization of special elements used in an OS command, an unauthenticated attacker is able to execute arbitrary code. Shell metacharacters can be sent to /v1/api in cloud_type for…
AplazadaMedia (4.3)0.48%—Matrix-rust-sdk Matrix-sdk-cryptoAI7/1/202517/6/2026
matrix-rust-sdk is an implementation of a Matrix client-server library in Rust. Versions of the matrix-sdk-crypto Rust crate before 0.8.0 lack a dedicated mechanism to notify that a user's cryptographic identity has changed from a verified to an unverified one, which could cause client applications relying on the SDK…
AplazadaMedia (5.3)0.42%—TrixAI3/1/202517/6/2026
Trix is a what-you-see-is-what-you-get rich text editor for everyday writing. Versions prior to 2.1.12 are vulnerable to cross-site scripting when pasting malicious code in the link field. An attacker could trick the user to copy&paste a malicious `javascript:` URL as a link that would execute arbitrary JavaScript…
AnalizadaMedia (6.7)0.17%—Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+110/12/202417/6/2026
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and…
AnalizadaCrítica (9.8)0.76%—Dell Data LakehouseDell InsightiqDell Powerflex Appliance Intelligent CatalogDell Powerflex Manager+110/12/202417/6/2026
Dell PowerFlex appliance versions prior to IC 46.381.00 and IC 46.376.00, Dell PowerFlex rack versions prior to RCM 3.8.1.0 (for RCM 3.8.x train) and prior to RCM 3.7.6.0 (for RCM 3.7.x train), Dell PowerFlex custom node using PowerFlex Manager versions prior to 4.6.1.0, Dell InsightIQ versions prior to 5.1.1, and…
AplazadaMedia (5.1)0.46%—TrixAI9/12/202417/6/2026
The Trix rich text editor, prior to versions 2.1.9 and 1.3.3, is vulnerable to cross-site scripting (XSS) + mutation XSS attacks when pasting malicious code. An attacker could trick a user to copy and paste malicious code that would execute arbitrary JavaScript code within the context of the user's session,…
AnalizadaAlta (8.7)0.50%—ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+155/12/202417/6/2026
Server-Side Request Forgery vulnerabilities were found providing a potential for access to unauthorized resources and unintended information disclosure. Affected products:
AnalizadaCrítica (9.3)1.1%💥 ExploitABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+155/12/202417/6/2026
Cross Site Scripting vulnerabilities where found providing a potential for malicious scripts to be injected into a client browser. Affected products:
AnalizadaAlta (8.7)0.40%—ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+155/12/202417/6/2026
Web browser interface may manipulate application username/password in clear text or Base64 encoding providing a higher probability of unintended credentails exposure. Affected products:
AplazadaCrítica (9.3)0.42%—ABB AspectAIABB Nexus SeriesAIABB Matrix SeriesAI5/12/202417/6/2026
Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials. Affected products:
AnalizadaAlta (8.8)0.39%—ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+155/12/202417/6/2026
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products:
AnalizadaCrítica (9.3)0.45%—ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+155/12/202417/6/2026
Default Credentail vulnerabilities in ASPECT on Linux allows access to the product using publicly available default credentials. Affected products:
AnalizadaCrítica (9.3)1.8%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Data Validation / Data Sanitization vulnerabilities in Linux allows unvalidated and unsanitized data to be injected in an Aspect device. Affected products:
AnalizadaCrítica (9.3)0.54%—ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Absolute File Traversal vulnerabilities allows access and modification of un-intended resources. Affected products:
AnalizadaAlta (8.7)0.59%—ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Dangerous File Upload vulnerabilities allow upload of malicious scripts. Affected products:
AnalizadaAlta (8.7)1.5%💥 ExploitABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Credentials Disclosure vulnerabilities allow access to on board project back-up bundles. Affected products:
AnalizadaCrítica (9.3)0.43%—ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Username Enumeration vulnerabilities allow access to application level username add, delete, modify and list functions. Affected products:
AnalizadaAlta (8.8)13%—ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Service Control vulnerabilities allow access to service restart requests and vm configuration settings. Affected products:
AnalizadaAlta (8.8)0.33%—ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Information Disclosure vulnerabilities allow access to application configuration information. Affected products:
AnalizadaAlta (8.8)0.33%—ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Configuration Download vulnerabilities allow access to dependency configuration information. Affected products:
AnalizadaAlta (8.8)0.32%—ABB Aspect-ent-12 FirmwareABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+155/12/202417/6/2026
Local File Inclusion vulnerabilities allow access to sensitive system information. Affected products:
AnalizadaAlta (8.8)0.26%—ABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+155/12/202417/6/2026
MD5 Checksum Bypass vulnerabilities where found exploiting a weakness in the way an application dependency calculates or validates MD5 checksum hashes. Affected products:
AnalizadaAlta (7.1)0.64%💥 ExploitABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+155/12/202417/6/2026
Cross Site Request Forgery vulnerabilities where found providing a potiential for exposing sensitive information or changing system settings. Affected products:
AnalizadaCrítica (9.3)1.8%💥 ExploitABB Aspect-ent-2 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 FirmwareABB Nexus-2128 Firmware+155/12/202417/6/2026
Weak Password Reset Rules vulnerabilities where found providing a potiential for the storage of weak passwords that could facilitate unauthorized admin/application access. Affected products: