Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
889 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.7) | 0.19% | — | Intel Ethernet Connection I219 Series DriversAI | 12/2/2025 | 17/6/2026 | Improper access control in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Media (5.7) | 0.19% | — | Intel Ethernet Connection I219 SeriesAI | 12/2/2025 | 17/6/2026 | Stack-based buffer overflow in some drivers for Intel(R) Ethernet Connection I219 Series before version 12.19.1.39 may allow an authenticated user to potentially enable denial of service via local access. | |
| Aplazada | Baja (2) | 0.23% | — | Intel 800 Series Ethernet DriverAI | 12/2/2025 | 17/6/2026 | Incorrect execution-assigned permissions in the Linux kernel mode driver for the Intel(R) 800 Series Ethernet Driver before version 1.15.4 may allow an authenticated user to potentially enable information disclosure via local access. | |
| Aplazada | Alta (7.1) | 0.37% | — | Intel 800 Series Ethernet DriverAI | 12/2/2025 | 17/6/2026 | Out-of-bounds write in the Intel(R) 800 Series Ethernet Driver for Intel(R) Ethernet Adapter Complete Driver Pack before versions 29.1 may allow an unauthenticated user to potentially enable denial of service via adjacent access. | |
| Aplazada | Media (6) | 0.44% | — | Schneider-electric Apogee PXC Series BacnetAISchneider-electric Apogee PXC Series P2 EthernetAISchneider-electric Talon TC Series BacnetAI | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain an out-of-bounds read in the memory dump function. This could allow an attacker with Medium (MED) or higher privileges to… | |
| Aplazada | Alta (8.7) | 0.20% | — | Schneider-electric Apogee PXC SeriesAISchneider-electric Talon TC SeriesAI | 11/2/2025 | 17/6/2026 | A vulnerability has been identified in APOGEE PXC Series (BACnet) (All versions), APOGEE PXC Series (P2 Ethernet) (All versions), TALON TC Series (BACnet) (All versions). Affected devices contain a weak encryption mechanism based on a hard-coded key. This could allow an attacker to guess or decrypt the password from… | |
| Aplazada | Media (6.1) | 0.40% | — | Cisco Expressway SeriesAI | 5/2/2025 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Expressway Series could allow an unauthenticated, remote attacker to conduct a cross-site scripting (XSS) attack against a user of the interface. This vulnerability exists because the web-based management interface does not properly validate user-supplied… | |
| Analizada | Alta (7.5) | 0.63% | — | IBM Txseries FOR Multiplatforms | 19/1/2025 | 17/6/2026 | IBM TXSeries for Multiplatforms 10.1 could allow a remote attacker to cause a denial of service using persistent connections due to improper allocation of resources. | |
| Analizada | Alta (7.5) | 0.75% | — | IBM Txseries FOR Multiplatforms | 19/1/2025 | 17/6/2026 | IBM TXSeries for Multiplatforms 10.1 is vulnerable to a denial of service, caused by improper enforcement of the timeout on individual read operations. By conducting a slowloris-type attacks, a remote attacker could exploit this vulnerability to cause a denial of service. | |
| Aplazada | Media (6.6) | 0.66% | — | Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAI | 14/1/2025 | 17/6/2026 | Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products. | |
| Aplazada | Alta (7) | 0.20% | — | RedistimeseriesAI | 8/1/2025 | 17/6/2026 | RedisTimeSeries is a time-series database (TSDB) module for Redis, by Redis. Executing one of these commands TS.QUERYINDEX, TS.MGET, TS.MRAGE, TS.MREVRANGE by an authenticated user, using specially crafted command arguments may cause an integer overflow, a subsequent heap overflow, and potentially lead to remote code… | |
| Aplazada | Crítica (9.3) | 0.42% | — | ABB AspectAIABB Nexus SeriesAIABB Matrix SeriesAI | 5/12/2024 | 17/6/2026 | Default Credentail vulnerabilities allows access to an Aspect device using publicly available default credentials since the system does not require the installer to change default credentials. Affected products: | |
| Aplazada | Alta (7.5) | 0.68% | — | Mitsubishi Electric Corporation Melsec Iq-f Series Fx5-enetAIMitsubishi Electric Corporation Melsec Iq-f Series Fx5-enet IPAI | 19/11/2024 | 17/6/2026 | Improper Validation of Specified Type of Input vulnerability in Mitsubishi Electric Corporation MELSEC iQ-F Series FX5-ENET versions 1.100 to 1.200 and FX5-ENET/IP versions 1.100 to 1.104 allows a remote attacker to cause a Denial of Service condition in Ethernet communication of the products by sending specially… | |
| Aplazada | Media (5.3) | 0.81% | — | Cisco ASR 5000 Series SoftwareAICisco StarosAI | 18/11/2024 | 17/6/2026 | A vulnerability in the ipsecmgr process of Cisco ASR 5000 Series Software (StarOS) could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition. This vulnerability is due to insufficient validation of incoming Internet Key Exchange Version 2 (IKEv2) packets. An attacker could… | |
| Aplazada | Media (6) | 0.18% | — | Cisco Network Convergence System 4000 SeriesAICisco IOS XRAI | 15/11/2024 | 17/6/2026 | A vulnerability in the TL1 function of Cisco Network Convergence System (NCS) 4000 Series could allow an authenticated, local attacker to cause a memory leak in the TL1 process. This vulnerability is due to TL1 not freeing memory under some conditions. An attacker could exploit this vulnerability by connecting to… | |
| Aplazada | Media (5.3) | 0.86% | — | Cisco ATA 190 Series Adaptive Telephone AdapterAI | 15/11/2024 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol functionality of Cisco ATA 190 Series Adaptive Telephone Adapter firmware could allow an unauthenticated, remote attacker to cause a DoS condition on an affected device. This vulnerability is due to an out-of-bounds read when processing Cisco Discovery… | |
| Analizada | Media (5.3) | 0.31% | — | IBM Txseries FOR Multiplatforms | 1/11/2024 | 17/6/2026 | IBM TXSeries for Multiplatforms 10.1 could allow an attacker to determine valid usernames due to an observable timing discrepancy which could be used in further attacks against the system. | |
| Analizada | Media (5.9) | 0.34% | — | IBM Txseries FOR Multiplatforms | 1/11/2024 | 17/6/2026 | IBM TXSeries for Multiplatforms 10.1 could allow an attacker to obtain sensitive information from the query string of an HTTP GET method to process a request which could be obtained using man in the middle techniques. | |
| Aplazada | Media (5.9) | 0.56% | — | Mitsubishielectric CNC SeriesAI | 17/10/2024 | 17/6/2026 | Improper Validation of Specified Quantity in Input vulnerability in Mitsubishi Electric CNC Series allows a remote unauthenticated attacker to cause Denial of Service (DoS) condition on the product by sending specially crafted packets to TCP port 683, causing an emergency stop. | |
| Analizada | Media (4.3) | 1.3% | — | Apache Commons IONetapp Active IQ Unified ManagerNetapp BluexpNetapp E-series Santricity Unified Manager+4 | 3/10/2024 | 17/6/2026 | Uncontrolled Resource Consumption vulnerability in Apache Commons IO. The org.apache.commons.io.input.XmlStreamReader class may excessively consume CPU resources when processing maliciously crafted input. This issue affects Apache Commons IO: from 2.0 before 2.14.0. Users are recommended to upgrade to version 2.14.0… | |
| Aplazada | Crítica (9.8) | 53% | 💥 PoC | Linear Emerge E3-seriesAI | 2/10/2024 | 17/6/2026 | The Linear eMerge e3-Series through version 1.00-07 is vulnerable to an OS command injection vulnerability. A remote and unauthenticated attacker can execute arbitrary OS commands via the login_id parameter when invoking the forgot_password functionality over HTTP. | |
| Aplazada | Crítica (9.3) | 0.59% | — | Omntec Proteus Tank Monitoring Oel8000iii SeriesAI | 27/9/2024 | 17/6/2026 | OMNTEC Proteus Tank Monitoring OEL8000III Series could allow an attacker to perform administrative actions without proper authentication. | |
| Analizada | Alta (8.8) | 0.58% | — | Cisco IOS XRCisco Network Services OrchestratorCisco Small Business RV Series Router Firmware | 11/9/2024 | 17/6/2026 | This vulnerability is due to improper authorization checks on the API. An attacker with privileges sufficient to access the affected application or device could exploit this vulnerability by sending malicious requests to the JSON-RPC API. A successful exploit could allow the attacker to make unauthorized modifications… | |
| Analizada | Crítica (9.3) | 0.16% | — | Intel Ethernet 800 Series Controllers Driver | 14/8/2024 | 17/6/2026 | Improper access control in Linux kernel mode driver for some Intel(R) Ethernet Network Controllers and Adapters before version 28.3 may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Aplazada | Alta (7) | 0.39% | — | Intel Ethernet Network Controllers E810 SeriesAI | 14/8/2024 | 17/6/2026 | Protection mechanism failure in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 4.4 may allow an unauthenticated user to potentially enable denial of service via network access. |