Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2839▼ 348 respecto a la semana anterior
Críticas / altas1378▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

2350 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.5)1.5%—Johnsoncontrols Metasys Application AND Data ServerAIJohnsoncontrols Metasys Extended Application AND Data ServerAIJohnsoncontrols Lcs8500AIJohnsoncontrols Nae8500AI+230/1/202617/6/2026
Johnson Controls Metasys component listed below have Improper Neutralization of Special Elements used in a Command (Command Injection) Vulnerability . Successful exploitation of this vulnerability could allow remote SQL execution This issue affects
AnalizadaAlta (8.8)0.75%—Craftycontrol Crafty Controller30/1/202617/6/2026
An input neutralization vulnerability in the File Operations API Endpoint component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
AnalizadaAlta (8.8)0.66%—Craftycontrol Crafty Controller30/1/202617/6/2026
An input neutralization vulnerability in the Backup Configuration component of Crafty Controller allows a remote, authenticated attacker to perform file tampering and remote code execution via path traversal.
AplazadaAlta (8.5)0.18%—Program Access ControllerAI28/1/202617/6/2026
Program Access Controller 1.2.0.0 contains an unquoted service path vulnerability in PACService.exe that allows local attackers to execute code with elevated privileges. Attackers can exploit the unquoted path during system startup or reboot to inject and run malicious executables with LocalSystem permissions.
AnalizadaMedia (5.1)0.28%—Tp-link Omada Controller26/1/202617/6/2026
Blind Server-Side Request Forgery (SSRF) in Omada Controllers through webhook functionality, enabling crafted requests to internal services, which may lead to enumeration of information.
AnalizadaBaja (2.1)0.32%—Tp-link Omada Controller26/1/202617/6/2026
Password Confirmation Bypass vulnerability in Omada Controllers, allowing an attacker with a valid session token to bypass secondary verification, and change the user’s password without proper confirmation, leading to weakened account security.
AnalizadaAlta (8.3)0.45%—Tp-link Omada Controller26/1/202617/6/2026
An IDOR vulnerability exists in Omada Controllers that allows an attacker with Administrator permissions to manipulate requests and potentially hijack the Owner account.
AnalizadaMedia (6)0.22%—Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+5222/1/20266/10/2026
An authentication weakness was identified in Omada Controllers, Gateways and Access Points, controller-device adoption due to improper handling of random values. Exploitation requires advanced network positioning and allows an attacker to intercept adoption traffic and forge valid authentication through offline…
AnalizadaMedia (5.7)0.20%—Tp-link Omada ControllerTp-link Oc200 FirmwareTp-link Oc220 FirmwareTp-link Oc300 Firmware+122/1/202617/6/2026
A Cross-Site Scripting (XSS) vulnerability was identified in a parameter in Omada Controllers due to improper input sanitization. Exploitation requires advanced conditions, such as network positioning or emulating a trusted entity, and user interaction by an authenticated administrator. If successful, an attacker…
AplazadaMedia (5.4)0.28%—Merkulove ScrollerAI22/1/202617/6/2026
Missing Authorization vulnerability in merkulove Scroller scroller allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Scroller: from n/a through <= 2.0.2.
AplazadaCrítica (10)0.39%—Ruckus Vriot IOT ControllerAI9/1/202617/6/2026
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) contain hardcoded credentials for an operating system user account within an initialization script. The SSH service is network-accessible without IP-based restrictions. Although the configuration disables SCP and pseudo-TTY allocation, an attacker…
AplazadaCrítica (10)0.86%—Ruckus Vriot IOT ControllerAI9/1/202617/6/2026
The Ruckus vRIoT IoT Controller firmware versions prior to 3.0.0.0 (GA) expose a command execution service on TCP port 2004 running with root privileges. Authentication to this service relies on a hardcoded Time-based One-Time Password (TOTP) secret and an embedded static token. An attacker who extracts these…
AnalizadaCrítica (10)2.1%—Gongrzhe Terminal-controller-mcp7/1/202617/6/2026
A command injection vulnerability in the execute_command function of terminal-controller-mcp 0.1.7 allows attackers to execute arbitrary commands via a crafted input.
AplazadaMedia (5.3)0.27%—Silabs Z-wave Protocol ControllerAI5/1/202617/6/2026
An integer underflow vulnerability in the Silicon Labs Z-Wave Protocol Controller can lead to out of bounds memory reads.
AplazadaMedia (6.5)0.16%—Intinitum Form GEO ControllerAI5/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in INTINITUM FORM Geo Controller allows DOM-Based XSS.This issue affects Geo Controller: from n/a through 8.5.2.
ModificadaCrítica (9.3)0.70%—Tinycontrol LAN Controller Firmware30/12/202524/9/2026
Tinycontrol LAN Controller 1.58a contains an authentication bypass vulnerability that allows unauthenticated attackers to change admin passwords through a crafted API request. Attackers can exploit the /stm.cgi endpoint with a specially crafted authentication parameter to disable access controls and modify…
AnalizadaAlta (8.7)0.43%—F5 Nginx Ingress Controller17/12/202517/6/2026
A vulnerability exists in NGINX Ingress Controller's nginx.org/rewrite-target annotation validation. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated.
AnalizadaCrítica (9.9)6.6%💥 PoCCraftycontrol Crafty Controller17/12/202517/6/2026
An input neutralization vulnerability in the Webhook Template component of Crafty Controller allows a remote, authenticated attacker to perform remote code execution via Server Side Template Injection.
AnalizadaAlta (7.1)0.29%—Craftycontrol Crafty Controller17/12/202525/9/2026
An input neutralization vulnerability in the Server MOTD component of Crafty Controller allows a remote, unauthenticated attacker to perform stored XSS via server MOTD modification.
AplazadaMedia (5.8)0.39%—Kubernetes Kube-controller-managerAIPurestorage PortworxAI14/12/202517/6/2026
A half-blind Server Side Request Forgery (SSRF) vulnerability exists in kube-controller-manager when using the in-tree Portworx StorageClass. This vulnerability allows authorized users to leak arbitrary information from unprotected endpoints in the control plane’s host network (including link-local or loopback…
AplazadaCrítica (9.9)0.63%—Tinycontrol LAN Controller V3 LK3AI9/12/202517/6/2026
Tinycontrol LAN Controller v3 LK3 version 1.58a contains an unauthenticated vulnerability that allows remote attackers to download configuration backup files containing sensitive credentials. Attackers can retrieve the lk3_settings.bin file and extract base64-encoded user and admin passwords without authentication.
AplazadaMedia (5.3)0.29%—Infinitumform GEO ControllerAI9/12/202517/6/2026
Insertion of Sensitive Information Into Sent Data vulnerability in INFINITUM FORM Geo Controller cf-geoplugin allows Retrieve Embedded Sensitive Data.This issue affects Geo Controller: from n/a through <= 8.9.4.
AnalizadaBaja (2.7)0.22%—IBM Cognos ControllerIBM Controller8/12/202517/6/2026
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow a privileged user to bypass validation, passing user input into the application as trusted data, due to client-side enforcement of server-side security.
AnalizadaMedia (6.5)0.27%—IBM Controller8/12/202517/6/2026
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 stores unencrypted sensitive information in environmental variables files which can be obtained by an authenticated user.
AnalizadaMedia (6.5)0.29%—IBM Cognos ControllerIBM Controller8/12/202517/6/2026
IBM Controller 11.1.0 through 11.1.1 and IBM Cognos Controller 11.0.0 through 11.0.1 FP6 could allow an authenticated user to cause a denial of service due to improper validation of a specified quantity size input.
Orbitaley — Vulnerabilidades