Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

4297 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.6)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
- External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63.
RecibidaAlta (7.2)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63.
RecibidaCrítica (9.3)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
: Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63.
RecibidaMedia (5.6)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
: Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63.
RecibidaAlta (7.3)——Johnsoncontrols Easyio NEOAI1/10/20261/10/2026
- Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25.
RecibidaMedia (6.3)——Johnsoncontrols Easy IO NEOAI1/10/20261/10/2026
- Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63.
RecibidaAlta (7.2)——Johnsoncontrols NEO Series Mvp2AI1/10/20261/10/2026
- On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63.
RecibidaAlta (7.2)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
- On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63.
RecibidaMedia (5.6)——Johnsoncontrols Easyio FGAI1/10/20261/10/2026
- Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52.
RecibidaMedia (5.6)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.
RecibidaMedia (5)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.
RecibidaMedia (5.6)——Johnsoncontrols Easy IO FGAI1/10/20261/10/2026
- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.
AplazadaBaja (3.1)——F5 IcontrolAI1/10/20261/10/2026
iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim.
AplazadaBaja (3.1)——Hcltech IcontrolAI1/10/20261/10/2026
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
AplazadaBaja (3.1)——F5 IcontrolAI1/10/20261/10/2026
iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks.
AplazadaMedia (4.3)——F5 IcontrolAI1/10/20261/10/2026
iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
AplazadaAlta (8.8)——Hcltech IcontrolAI1/10/20261/10/2026
iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.
AplazadaMedia (6.8)0.17%—Pardus Parental ControlAI29/9/202630/9/2026
Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and…
AplazadaMedia (5.6)0.11%—ABB Protection AND Control IED ManagerAI28/9/202628/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.
AplazadaAlta (7.1)0.09%—ABB Protection AND Control IED ManagerAI28/9/202628/9/2026
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.
AnalizadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior…
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior…
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to…
ModificadaAlta (7)0.24%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression…