Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
4297 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Recibida | Media (5.6) | — | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 1/10/2026 | - External Control of File Name or Path vulnerability in Johnson Controls EasyIO FS32 allows - traversal attack. This issue affects EasyIO FS32: before 3.0b63. | |
| Recibida | Alta (7.2) | — | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 1/10/2026 | - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows OS Command Injection. This issue affects EasyIO FS32: before 3.0b63. | |
| Recibida | Crítica (9.3) | — | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 1/10/2026 | : Use of Hard-coded Cryptographic Key vulnerability in Johnson Controls EasyIO FS32 allows : Retrieve Embedded Sensitive Data. This issue affects EasyIO FS32: before 3.0b63. | |
| Recibida | Media (5.6) | — | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 1/10/2026 | : Insecure Default Initialization of Resource vulnerability in Johnson Controls EasyIO FS32 allows : Authentication Abuse. This issue affects EasyIO FS32: before 3.0b63. | |
| Recibida | Alta (7.3) | — | — | Johnsoncontrols Easyio NEOAI | 1/10/2026 | 1/10/2026 | - Cleartext Transmission of Sensitive Information vulnerability in Johnson Controls EasyIO NEO allows - Man In the Middle Attack. This issue affects EasyIO NEO: before 3.3b25. | |
| Recibida | Media (6.3) | — | — | Johnsoncontrols Easy IO NEOAI | 1/10/2026 | 1/10/2026 | - Exposure of Sensitive Information vulnerability in Johnson Controls Easy IO Neo allows Collect Data from Common Resource Locations. This issue affects Easy IO Neo: before 3.3b63. | |
| Recibida | Alta (7.2) | — | — | Johnsoncontrols NEO Series Mvp2AI | 1/10/2026 | 1/10/2026 | - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63. | |
| Recibida | Alta (7.2) | — | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 1/10/2026 | - On-Chip Debug Interface vulnerability in Johnson Controls EasyIO FS32 allows Collect Data from Common Resource Locations. This issue affects EasyIO FS32: before 3.3b63. | |
| Recibida | Media (5.6) | — | — | Johnsoncontrols Easyio FGAI | 1/10/2026 | 1/10/2026 | - Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FG allows - Pasword Spraying. This issue affects EasyIO FG: before 2.0b52. | |
| Recibida | Media (5.6) | — | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 1/10/2026 | - OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63. | |
| Recibida | Media (5) | — | — | Johnsoncontrols Easyio Fs32AI | 1/10/2026 | 1/10/2026 | : Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63. | |
| Recibida | Media (5.6) | — | — | Johnsoncontrols Easy IO FGAI | 1/10/2026 | 1/10/2026 | - Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52. | |
| Aplazada | Baja (3.1) | — | — | F5 IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim. | |
| Aplazada | Baja (3.1) | — | — | Hcltech IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers. | |
| Aplazada | Baja (3.1) | — | — | F5 IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks. | |
| Aplazada | Media (4.3) | — | — | F5 IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session. | |
| Aplazada | Alta (8.8) | — | — | Hcltech IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data. | |
| Aplazada | Media (6.8) | 0.17% | — | Pardus Parental ControlAI | 29/9/2026 | 30/9/2026 | Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and… | |
| Aplazada | Media (5.6) | 0.11% | — | ABB Protection AND Control IED ManagerAI | 28/9/2026 | 28/9/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14. | |
| Aplazada | Alta (7.1) | 0.09% | — | ABB Protection AND Control IED ManagerAI | 28/9/2026 | 28/9/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14. | |
| Analizada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23. | |
| Modificada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior… | |
| Modificada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior… | |
| Modificada | Alta (8.8) | 0.38% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to… | |
| Modificada | Alta (7) | 0.24% | — | Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway | 27/9/2026 | 29/9/2026 | Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression… |