Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
2299 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (5.6) | 0.10% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Exposed ioctl with insufficient access control in the firmware for some Intel(R) Ethernet Connection E825-C. before version NVM ver. 3.84 within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a high complexity attack may enable denial of service.… | |
| Analizada | Media (6.7) | 0.12% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Out-of-bounds write in the firmware for some Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially occur… | |
| Analizada | Media (6.7) | 0.12% | — | Intel Ethernet Controller | 10/2/2026 | 17/6/2026 | Uncaught exception in the firmware for some 100GbE Intel(R) Ethernet Controller E810 before version cvl fw 1.7.8.x within Ring 0: Bare Metal OS may allow a denial of service. System software adversary with a privileged user combined with a low complexity attack may enable denial of service. This result may potentially… | |
| Aplazada | Alta (8.5) | 0.18% | — | Alps Pointing-device ControllerAI | 5/2/2026 | 17/6/2026 | Alps Pointing-device Controller 8.1202.1711.04 contains an unquoted service path vulnerability in the ApHidMonitorService that allows local attackers to execute code with elevated privileges. Attackers can place a malicious executable in the service path and gain system-level access when the service restarts or the… | |
| Analizada | Baja (2.3) | 0.18% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 4/2/2026 | 17/6/2026 | A vulnerability exists in an undisclosed BIG-IP Configuration utility page that may allow an attacker to spoof error messages. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Alta (8.2) | 0.39% | — | F5 Nginx Gateway FabricF5 Nginx Ingress ControllerF5 Nginx Instance ManagerF5 Nginx Open Source+1 | 4/2/2026 | 17/6/2026 | A vulnerability exists in NGINX OSS and NGINX Plus when configured to proxy to upstream Transport Layer Security (TLS) servers. An attacker with a man-in-the-middle (MITM) position on the upstream server side—along with conditions beyond the attacker's control—may be able to inject plain text data into the response… | |
| Aplazada | Crítica (9.5) | 1.5% | — | Johnsoncontrols Metasys Application AND Data ServerAIJohnsoncontrols Metasys Extended Application AND Data ServerAIJohnsoncontrols Lcs8500AIJohnsoncontrols Nae8500AI+2 | 30/1/2026 | 17/6/2026 | Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects | |
| Analizada | Alta (8.8) | 0.75% | — | Craftycontrol Crafty Controller | 30/1/2026 | 17/6/2026 | An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. | |
| Analizada | Alta (8.8) | 0.66% | — | Craftycontrol Crafty Controller | 30/1/2026 | 17/6/2026 | An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal. | |
| Aplazada | Alta (8.5) | 0.18% | — | Program Access ControllerAI | 28/1/2026 | 17/6/2026 | Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions. | |
| Analizada | Media (5.1) | 0.28% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information. | |
| Analizada | Baja (2.1) | 0.32% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security. | |
| Analizada | Alta (8.3) | 0.45% | — | Tp-link Omada Controller | 26/1/2026 | 17/6/2026 | An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account. | |
| Analizada | Media (6) | 0.22% | — | Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+52 | 23/1/2026 | 17/6/2026 | An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline… | |
| Analizada | Media (5.7) | 0.20% | — | Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+1 | 22/1/2026 | 17/6/2026 | A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker… | |
| Aplazada | Crítica (10) | 0.39% | — | Ruckus Vriot IOT ControllerAI | 9/1/2026 | 17/6/2026 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker… | |
| Aplazada | Crítica (10) | 0.86% | — | Ruckus Vriot IOT ControllerAI | 9/1/2026 | 17/6/2026 | The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these… | |
| Analizada | Crítica (10) | 2.1% | — | Gongrzhe Terminal-controller-mcp | 7/1/2026 | 17/6/2026 | A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input. | |
| Aplazada | Media (5.3) | 0.27% | — | Silabs Z-wave Protocol ControllerAI | 5/1/2026 | 17/6/2026 | An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads. | |
| Aplazada | Media (6.5) | 0.16% | — | Intinitum Form GEO ControllerAI | 5/1/2026 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in INTINITUM FORM Geo Controller allows DOM-Based XSS.This issue affects Geo Controller: from n/a through 8.5.2. | |
| Modificada | Crítica (9.3) | 0.70% | — | Tinycontrol LAN Controller Firmware | 30/12/2025 | 24/9/2026 | Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify… | |
| Analizada | Alta (8.7) | 0.43% | — | F5 Nginx Ingress Controller | 17/12/2025 | 17/6/2026 | A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. | |
| Analizada | Crítica (9.9) | 6.6% | — | Craftycontrol Crafty Controller | 17/12/2025 | 17/6/2026 | An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection. | |
| Analizada | Alta (7.1) | 0.29% | — | Craftycontrol Crafty Controller | 17/12/2025 | 25/9/2026 | An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification. | |
| Aplazada | Media (5.8) | 0.39% | — | Kubernetes Kube-controller-managerAIPurestorage PortworxAI | 14/12/2025 | 17/6/2026 | A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback… |