Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
19 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (6.4) | 0.17% | — | Ansible Automation PlatformAIAnsible Automation ControllerAI | 23/9/2026 | 24/9/2026 | A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the SMTP client without validating that the target is not an internal, loopback,… | |
| Pendiente de análisis | Crítica (9.9) | 0.43% | — | Ansible Automation PlatformAIAnsible Automation-controllerAI | 23/9/2026 | 25/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that… | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Ansible Automation PlatformAIAnsible Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a… | |
| Pendiente de análisis | Media (6.6) | 0.18% | — | Redhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Alta (7.1) | 0.29% | — | Redhat Automation-controllerAIAnsible-coreAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Media (6.5) | 0.31% | — | Ansible Automation ControllerAI | 23/9/2026 | 25/9/2026 | — | |
| Pendiente de análisis | Media (5.3) | 0.34% | — | Redhat Ansible Automation ControllerAI | 23/9/2026 | 24/9/2026 | — | |
| Pendiente de análisis | Alta (7.6) | 0.31% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in Ansible Automation Platform's automation-controller. The custom Credential Type environment-variable injector validates variable names against a deny-list (an ANSIBLE_* prefix check plus a fixed ENV_BLOCKLIST) that omits process-hijacking loader variables such as BASH_ENV, ENV, LD_PRELOAD,… | |
| Pendiente de análisis | Crítica (9.9) | 0.62% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The Project scm_url field is not validated against values that begin with a dash and is stored and passed verbatim to the git SCM module. Because the module runs git ls-remote with the URL as a positional argument and without a "--"… | |
| Pendiente de análisis | Alta (7.7) | 0.38% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 26/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. Survey questions of type password are write-only and stored encrypted, displayed only as a placeholder on read. When a schedule or workflow job template node is revalidated against a tightened survey specification, the controller… | |
| Pendiente de análisis | Crítica (9.9) | 0.80% | — | Redhat Ansible Automation PlatformAIRedhat Automation ControllerAI | 23/9/2026 | 24/9/2026 | A flaw was found in Red Hat Ansible Automation Platform's automation- controller. The provisioning-callback secret (host_config_key) is exposed to users holding only the read-level view_jobtemplate permission -- both in the job template API representation and in the activity stream -- and the provisioning callback… | |
| Aplazada | Alta (7) | 0.25% | — | Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAIOmron Sysmac StudioAI | 14/7/2025 | 17/6/2026 | Least Privilege Violation (CWE-272) Vulnerability exists in the communication function between the NJ/NX-series Machine Automation Controllers and the Sysmac Studio Software. An attacker may use this vulnerability to perform unauthorized access and to execute unauthorized code remotely to the controller products. | |
| Aplazada | Media (6.6) | 0.66% | — | Omron NJ Series Machine Automation ControllerAIOmron NX Series Machine Automation ControllerAI | 14/1/2025 | 17/6/2026 | Path Traversal Vulnerabilities (CWE-22) exist in NJ/NX-series Machine Automation Controllers. An attacker may use these vulnerabilities to perform unauthorized access and to execute unauthorized code remotely to the controller products. | |
| Aplazada | Media (6.6) | 0.43% | — | Ansible Automation ControllerAI | 12/9/2024 | 17/6/2026 | An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account. | |
| Aplazada | Alta (7.2) | 0.88% | — | Omron Machine Automation Controller NJ SeriesAIOmron Machine Automation Controller NX SeriesAI | 12/3/2024 | 17/6/2026 | Path traversal vulnerability exists in Machine Automation Controller NJ Series and Machine Automation Controller NX Series. An arbitrary file in the affected product may be accessed or arbitrary code may be executed by processing a specially crafted request sent from a remote attacker with an administrative privilege.… | |
| Modificada | Media (5.4) | 0.81% | — | Redhat Ansible Automation ControllerRedhat Ansible Automation PlatformRedhat Ansible DeveloperRedhat Ansible Inside | 4/10/2023 | 17/6/2026 | An HTML injection flaw was found in Controller in the user interface settings. This flaw allows an attacker to capture credentials by creating a custom login page by injecting HTML, resulting in a complete compromise. | |
| Modificada | Media (5.5) | 0.14% | — | Selinc Sel-5033 Acselerator Real-time Automation Controller | 31/8/2023 | 17/6/2026 | Insecure Inherited Permissions vulnerability in Schweitzer Engineering Laboratories SEL-5033 AcSELerator RTAC Software on Windows allows Leveraging/Manipulating Configuration File Search Paths. See Instruction Manual Appendix A [Cybersecurity] tag dated 20230522 for more details. This issue affects SEL-5033… | |
| Modificada | Media (4.3) | 0.68% | — | Fluxcd Flux2Fluxcd Helm-controllerFluxcd Image-automation-controllerFluxcd Image-reflector-controller+3 | 22/10/2022 | 17/6/2026 | Flux is an open and extensible continuous delivery solution for Kubernetes. Versions prior to 0.35.0 are subject to a Denial of Service. Users that have permissions to change Flux’s objects, either through a Flux source or directly within a cluster, can provide invalid data to fields `.spec.interval` or… | |
| Modificada | Crítica (9.8) | 3.4% | — | Siemens Apogee MBC (ppc) (P2 Ethernet) FirmwareSiemens Apogee MEC (ppc) (P2 Ethernet) FirmwareSiemens Apogee PXC Bacnet Automation Controller FirmwareSiemens Apogee PXC Compact (P2 Ethernet) Firmware+4 | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3),… |