Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

4300 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.1)0.30%—Hestiacp Control Panel10/7/202629/9/2026
HestiaCP before 1.9.5 contains a stored cross-site scripting vulnerability that allows authenticated low-privilege users to inject arbitrary HTML by creating a DNS record with a double-quote followed by a script payload in the value field. The application fails to apply htmlspecialchars() encoding to the DNS record…
AnalizadaAlta (8.7)3.2%—Hestiacp Control Panel10/7/202629/9/2026
HestiaCP before 1.9.5 contains an authenticated OS command injection vulnerability that allows low-privilege authenticated users to execute arbitrary commands as root by injecting a single-quote character into unvalidated DNS record types. Attackers can exploit insufficient input validation in…
AplazadaAlta (8.2)0.34%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Missing Authorization vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Collect Data from Common Resource Locations. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (5.4)0.23%—Armiya Information Technologies Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Reflected XSS. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (6.1)0.25%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of input during web page generation ('cross-site scripting') vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows Stored XSS. This issue affects Access Control System (GKS): before Version 2.
AplazadaMedia (6.1)0.25%—Armiya Information Technologies LTD Access Control System GKSAI7/7/20267/7/2026
Improper neutralization of Script-Related HTML tags in a web page (basic XSS) vulnerability in Armiya Information Technologies Ltd. Co. Access Control System (GKS) allows XSS Targeting HTML Attributes. This issue affects Access Control System (GKS): before Version 2.
AnalizadaAlta (8.6)0.56%—Wso2 API Control PlaneWso2 API ManagerWso2 Traffic ManagerWso2 Universal Gateway6/7/20269/7/2026
The throttling event handling mechanism in multiple WSO2 products accepts user-supplied JSON payloads without sufficient validation of their structure and content. This allows an unauthenticated remote attacker to inject malicious JSON data that can lead to a persistent denial of service condition. Successful…
AnalizadaMedia (6.1)0.25%—Wso2 API Control PlaneWso2 API ManagerWso2 Identity ServerWso2 Identity Server AS KEY Manager+46/7/20266/10/2026
The software accepts user-supplied input via a URL parameter without adequate output encoding before reflecting it back to the user's browser. This condition allows an attacker to inject malicious script content into pages served by the application. By leveraging this weakness, an attacker can cause the user's browser…
AplazadaMedia (5.3)0.40%—Vxcontrol PentagiAI6/7/20266/7/2026
A vulnerability was identified in vxcontrol PentAGI up to 2.1.0. This affects an unknown function of the file backend/pkg/docker/client.go of the component Docker API. The manipulation leads to sandbox issue. The attack may be initiated remotely. The pull request to fix this issue awaits acceptance.
AplazadaAlta (8.8)0.14%—Tubitak Bilgem Pardus-parental-controlAI5/7/20266/7/2026
Incorrect Permission Assignment for Critical Resource, Improper Access Control vulnerability in TUBITAK BILGEM Software Technologies Research Institute Pardus-Parental-Control allows DNS Spoofing. This issue affects Pardus-Parental-Control: from <=0.5.1 before 0.7.0.
Pendiente de análisisCrítica (9.3)0.96%💥 PoCControl WEB PanelAIRoundcubeAI1/7/20262/7/2026
Control Web Panel before 0.9.8.1225 contains a blind SQL injection vulnerability that allows unauthenticated remote attackers to execute arbitrary SQL queries by submitting unsanitized input through the userRes POST parameter at the user endpoint. Attackers can exploit MySQL root privileges obtained via the injection…
Pendiente de análisisMedia (5.6)0.11%—BMC Control-m Enterprise ManagerAI1/7/20261/7/2026
The Control-M/Enterprise Manager uses weak protections for stored hashes of account passwords, potentially allowing offline password recovery attacks if credential data is obtained by an attacker. This vulnerability affects Control-M/Enterprise Manager unsupported versions 9.0.20.x and potentially earlier unsupported…
Pendiente de análisisCrítica (9.5)0.42%—BMC Control-m ServerAI1/7/20261/7/2026
A Control-M/Server communication command does not sufficiently filter or sanitize user-supplied input. Under certain conditions, this issue may allow an unauthenticated attacker to execute unauthorized commands on the affected server, potentially leading to compromise of the server. This vulnerability affects…
Pendiente de análisisAlta (8.9)0.42%—BMC Control-m ServerAIBMC Control-m Enterprise ManagerAI1/7/20261/7/2026
Messaging consumer functionality allows deserialization of user-controlled data without sufficient restriction of allowed object types in the out of support Control-M/Server and Control-M/Enterprise Manager versions 9.0.20.x and potentially earlier. This issue may allow an authenticated attacker to trigger unintended…
Pendiente de análisisAlta (7.3)0.14%—HP FAN Control APPAI30/6/20262/7/2026
—
AnalizadaAlta (8.8)0.63%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20261/7/2026
Multiple Memory overflow vulnerabilities in NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if NetScaler ADC is configured as an LB of type Oracle OR NetScaler ADC is configured as a DNS Proxy OR NetScaler ADC is configured as a DNS recursive resolver deployment
AnalizadaAlta (8.8)1.0%⚠ Explotación activa💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/202627/8/2026
Memory overflow vulnerability NetScaler ADC and NetScaler Gateway leading to unpredictable or erroneous behavior and Denial of Service if the appliance is configured as a Gateway (SSL VPN, ICA Proxy, CVPN, RDP Proxy) or AAA virtual server
AnalizadaAlta (8.8)0.50%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20261/7/2026
Insufficient input validation in NetScaler ADC and NetScaler Gateway leading to memory overread if NetScaler ADC or NetScaler Gateway is configured as a SAML IDP
AnalizadaAlta (8.7)0.56%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Denial of service via malformed HTTP/2 requests in NetScaler ADC and NetScaler Gateway if HTTP/2 is enabled in HTTP Profile and associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
AnalizadaMedia (6.9)0.56%💥 PoCCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Insufficient input validation leading to memory overread in NetScaler ADC and NetScaler Gateway if the TCP TimeStamp is enabled in TCP Profile and is associated with the virtual server (of type LB, CS, VPN) or the service configured on NetScaler
AnalizadaAlta (7.1)0.58%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway30/6/20262/7/2026
Arbitrary File Read (Unauthenticated) in NetScaler ADC and NetScaler Gateway if the access to NSIP, Cluster Management IP or SNIP with management access is enabled
AplazadaMedia (5.1)0.44%—Intermark IT Webcontrol CMSAI30/6/202630/6/2026
Cross-Site Scripting (XSS) vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to execute JavaScript code or inject a dynamic iframe into the victim’s browser by sending a malicious URL via the 'urlDestino' parameter in '/portal.do'. This vulnerability can be exploited to steal…
AplazadaMedia (5.1)0.44%—Intermark IT Webcontrol CMSAI30/6/202630/6/2026
HTML injection vulnerability in Intermark IT's WebControl CMS v3.5. This vulnerability allows an attacker to send an email containing malicious HTML code to a victim via the contact form. To exploit this vulnerability, the attacker must send a request using the 'nombreApellidos', 'dirección ', and 'comentarios '…
AnalizadaAlta (7.7)0.38%—Peplink Intcontrol 226/6/20262/7/2026
Peplink InControl 2 through 2.14.2 before 2026-06-03 allows use of a semicolon to bypass access-control rules for certain /rest/o/{orgId} endpoints.
Pendiente de análisisMedia (4.1)0.12%—ABB Control Builder AAIABB 800xa FOR Advant MasterAI23/6/20266/10/2026
Uncontrolled Search Path Element vulnerability in ABB Control Builder A, ABB 800xA for Advant Master. This issue affects Control Builder A: through 1.4/4; 800xA for Advant Master: through 6.0.3-1, through 6.1.1-1, 6.1.1-3, 6.2.0-1.