Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.8) | 0.55% | — | Eaton Tripp Lite PadmAI | 30/7/2026 | 31/7/2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite series PADM firmware could allow an authenticated user to elevate privileges resulting in unrestricted access to the device. | |
| Pendiente de análisis | Alta (8.3) | 0.58% | — | Eaton Tripp Lite Series PadmAI | 30/7/2026 | 31/7/2026 | Improper input validation in one of the session management interface of Eaton's Tripp Lite Series PADM firmware could allow an authenticated administrator to execute arbitrary commands within a restricted environment. | |
| Pendiente de análisis | Alta (8.6) | 0.66% | — | Eaton Tripp Lite PadmAI | 30/7/2026 | 31/7/2026 | Improper input validation in the authentication component of Eaton's Tripp Lite series PADM firmware could allow an unauthenticated remote attacker to bypass authentication and gain a privileged user access to the device. | |
| Analizada | Crítica (9.9) | 0.32% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | Eaton Intelligent Power Protector (IPP) is affected by insecure library loading in its executable, which could lead to arbitrary code execution by an attacker with access to the software package. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download… | |
| Analizada | Alta (7.1) | 0.23% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | A security misconfiguration was identified in Eaton Intelligent Power Protector (IPP), where an HTTP response header was set with an insecure attribute, potentially exposing users to web‑based attacks. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton… | |
| Analizada | Alta (7.4) | 0.17% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | Eaton Intelligent Power Protector (IPP) uses an insecure cookie configuration, which could allow a network‑based attacker to intercept the cookie and exploit it through a man‑in‑the‑middle attack. This security issue has been fixed in the latest version of Eaton IPP software which is available on the Eaton download… | |
| Analizada | Alta (7.5) | 0.32% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | Eaton Intelligent Power Protector (IPP) software allows repeated authentication attempts against the web interface login page due to insufficient rate‑limiting controls. This security issue has been fixed in the latest version of Eaton IPP which is available on the Eaton download centre. | |
| Analizada | Alta (7.2) | 0.34% | — | Eaton Intelligent Power Protector | 16/4/2026 | 17/6/2026 | Due to improper input validation in one of the Eaton Intelligent Power Protector (IPP) XML, it is possible for an attacker with admin privileges and access to the local system to inject malicious code resulting in arbitrary command execution. This security issue has been fixed in the latest version of Eaton IPP… | |
| Analizada | Media (6.1) | 0.08% | — | Eaton Easysoft | 10/3/2026 | 17/6/2026 | The encryption mechanism used in Eaton's EasySoft project file was insecure and susceptible to brute force attacks, an attacker with access to this file and the local host machine could potentially read the sensitive information stored and tamper with the project file. This security issue has been fixed in the latest… | |
| Aplazada | Media (5.7) | 0.16% | — | Eaton Network M3AI | 9/2/2026 | 17/6/2026 | The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton Network M3 which is available on the Eaton download center. | |
| Analizada | Alta (8.6) | 0.26% | — | Eaton UPS Companion | 26/12/2025 | 17/6/2026 | Improper authentication of library files in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | |
| Analizada | Alta (7.8) | 0.15% | — | Eaton UPS Companion | 26/12/2025 | 6/10/2026 | Due to insecure library loading in the Eaton UPS Companion software executable, an attacker with access to the software package could perform arbitrary code execution . This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | |
| Analizada | Media (6.7) | 0.19% | — | Eaton UPS Companion | 26/12/2025 | 6/10/2026 | Improper quotation in search paths in the Eaton UPS Companion software installer could lead to arbitrary code execution of an attacker with the access to the file system. This security issue has been fixed in the latest version of EUC which is available on the Eaton download center. | |
| Analizada | Alta (8.8) | 0.32% | — | Eaton Xcomfort Ethernet Communication Interface | 23/12/2025 | 17/6/2026 | Improper input validation at one of the endpoints of Eaton xComfort ECI's web interface, could lead into an attacker with network access to the device executing privileged user commands. As cybersecurity standards continue to evolve and to meet our requirements today, Eaton has decided to discontinue the product. Upon… | |
| Aplazada | Alta (7.3) | 0.15% | — | Eaton GalileoAI | 27/11/2025 | 17/6/2026 | Improper input sanitization in the file archives upload functionality of Eaton Galileo software allows traversing paths which could lead into an attacker with local access to execute unauthorized code or commands. This security issue has been fixed in the latest version of Galileo which is available on the Eaton… | |
| Aplazada | Alta (7.1) | 0.22% | — | Eaton BlssAI | 3/11/2025 | 17/6/2026 | The privileged user could log in without sufficient credentials after enabling an application protocol. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004). | |
| Aplazada | Alta (8.3) | 0.36% | — | Eaton BlssAI | 3/11/2025 | 17/6/2026 | Arbitrary code execution is possible due to improper validation of the file upload functionality in Eaton BLSS. This security issue has been fixed in the latest script patch latest version of of Eaton BLSS (7.3.0.SCP004). | |
| Aplazada | Alta (8.6) | 0.18% | — | Eaton IPPAI | 14/10/2025 | 17/6/2026 | Improper authentication of library files in the Eaton IPP software installer could lead to arbitrary code execution of an attacker with the access to the software package. This security issue has been fixed in the latest version of IPP which is available on the Eaton download center. | |
| Aplazada | Media (4.7) | 0.29% | — | Eaton NMC G2AI | 5/9/2025 | 17/6/2026 | An attacker with authenticated and privileged access could modify the contents of a non-sensitive file by traversing the path in the limited shell of the CLI. This security issue has been fixed in the latest version of NMC G2 which is available on the Eaton download center. | |
| Aplazada | Media (5.7) | 0.20% | — | Eaton G4 PDUAI | 6/8/2025 | 17/6/2026 | The server identity check mechanism for firmware upgrade performed via command shell is insecurely implemented potentially allowing an attacker to perform a Man-in-the-middle attack. This security issue has been fixed in the latest firmware version of Eaton G4 PDU which is available on the Eaton download center. | |
| Aplazada | Alta (7.5) | 0.41% | — | Eaton Aspect EnterpriseAIEaton Nexus SeriesAIEaton Matrix SeriesAI | 22/5/2025 | 17/6/2026 | Relative Path Traversal vulnerabilities in ASPECT allow access to file resources if session administrator credentials become compromised. This issue affects ASPECT-Enterprise: through 3.08.03; NEXUS Series: through 3.08.03; MATRIX Series: through 3.08.03. | |
| Aplazada | Crítica (9.1) | 0.43% | — | Eaton X303AI | 13/1/2025 | 17/6/2026 | In Eaton X303 3.5.16 - X303 3.5.17 Build 712, an attacker with network access to a XC-303 PLC can login as root over SSH. The root password is hardcoded in the firmware. NOTE: This vulnerability appears in versions that are no longer supported by Eaton. | |
| Aplazada | Media (5.2) | 8.3% | — | Eaton Intelligent Power ManagerAI | 25/11/2024 | 17/6/2026 | Eaton Intelligent Power Manager (IPM) prior to 1.70 is vulnerable to stored Cross site scripting. The vulnerability exists due to insufficient validation of input from certain resources by the IPM software. The attacker would need access to the local Subnet and an administrator interaction to compromise the system | |
| Modificada | Media (6.5) | 0.27% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides multiple customizable input fields for the users to configure parameters in the tool like alarms, reports, etc. Some of these input fields were not checking the length and bounds of the entered value. The exploit of this security flaw by a bad actor may result in excessive memory… | |
| Modificada | Alta (8.1) | 0.12% | — | Eaton Foreseer Electrical Power Monitoring System | 13/9/2024 | 17/6/2026 | The Eaton Foreseer software provides the feasibility for the user to configure external servers for multiple purposes such as network management, user management, etc. The software uses encryption to store these configurations securely on the host machine. However, the keys used for this encryption were insecurely… |