Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2797▼ 203 respecto a la semana anterior
Críticas / altas1352▲ 28 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 266 respecto a la semana anterior
27 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Baja (3.1) | 0.14% | — | F5 IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim. | |
| Aplazada | Baja (3.1) | 0.10% | — | Hcltech IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers. | |
| Aplazada | Baja (3.1) | 0.16% | — | F5 IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks. | |
| Aplazada | Media (4.3) | 0.22% | — | F5 IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session. | |
| Aplazada | Alta (8.8) | 0.30% | — | Hcltech IcontrolAI | 1/10/2026 | 1/10/2026 | iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data. | |
| Pendiente de análisis | Media (5.9) | 0.13% | — | Kunbus PicontrolAI | 14/8/2026 | 28/8/2026 | Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the event notification functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to corrupt kernel heap and event-list state and… | |
| Pendiente de análisis | Alta (7.3) | 0.13% | — | Kunbus PicontrolAI | 14/8/2026 | 28/8/2026 | Nozomi Networks Labs identified a CWE-362: Concurrent Execution using Shared Resource with Improper Synchronization ('Race Condition') vulnerability in the configuration and process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker to trigger use-after-free… | |
| Pendiente de análisis | Alta (7.3) | 0.14% | — | Kunbus PicontrolAI | 14/8/2026 | 28/8/2026 | Nozomi Networks Labs identified a CWE-787: Out-of-bounds Write vulnerability in the process-image management functionality of KUNBUS piControl in version 2.6.2 that allows a local authenticated attacker with device configuration access to write attacker-controlled data outside the bounds of the process-image buffer… | |
| Analizada | Media (6.5) | 0.15% | — | Hcltech Icontrol | 3/8/2026 | 5/8/2026 | HCL iControl is affected by Weak SSL/TLS Version Supported vulnerability. It was observed that the application was using weak TLS versions such as TLS 1.0 and 1.1. These outdated protocols lack modern security features, making them vulnerable to known attacks and exposing sensitive information during data transmission. | |
| Analizada | Media (5.3) | 0.27% | — | Hcltech Icontrol | 3/8/2026 | 5/8/2026 | HCL iControl is affected by Missing Access Control vulnerability. The application failed to enforce proper granular access controls, allowing users to access or view administrator-level functionalities without appropriate authorization. | |
| Analizada | Media (5.3) | 0.29% | — | Hcltech Icontrol | 31/7/2026 | 5/8/2026 | HCL iControl was affected by Improper Error Handling vulnerabilities. It involves Out of memory, null pointer exceptions, system call failure, database unavailable, network timeout, and hundreds of other common conditions can cause errors to be generated. | |
| Analizada | Media (5.3) | 0.30% | — | Hcltech Icontrol | 31/7/2026 | 5/8/2026 | HCL iControl was affected by Auto complete Enabled vulnerabilities. It involves expose sensitive information such as: Valid usernames, Email addresses used for login, Account identifiers If the system is accessed from shared environments, attackers may enumerate valid usernames through browser suggestions. | |
| Analizada | Baja (3.3) | 0.14% | — | Hcltech Icontrol | 31/7/2026 | 5/8/2026 | HCL iControl was affected by Sensitive Data Exposure vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | |
| Analizada | Media (5.3) | 0.33% | — | Hcltech Icontrol | 31/7/2026 | 6/8/2026 | HCL iControl was affected by Information Exposure Through Verbose Client-Side API Error Messages vulnerabilities. It involves application displays raw server/API error messages to users instead of generic error messages and exposes internal endpoint names, request parameters, error codes, and authentication status | |
| Analizada | Baja (3.3) | 0.14% | — | Hcltech Icontrol | 31/7/2026 | 6/8/2026 | HCL iControl v4.3.0 was affected by Security Misconfiguration vulnerabilities. It involves the public exposure of internal configuration files due to improper web server or application hardening. | |
| Aplazada | Media (4.3) | 0.31% | — | HCL IcontrolAI | 31/7/2026 | 29/9/2026 | HCL iControl was affected by Improper Input Validation vulnerability. It is vulnerable to unexpected system behavior and potential security bypasses. This was caused by an implementation flaw in an architectural security tactic that fails to properly validate whether the received input matches the expected type. | |
| Analizada | Media (5.3) | 0.20% | — | Hcltech Icontrol | 17/6/2026 | 30/9/2026 | HCL iControl was affected by Inadequate Session Timeout vulnerability. The vulnerability involves a security risk where a web application fails to automatically terminate user sessions after a period of inactivity | |
| Aplazada | Crítica (9.8) | 0.48% | — | IcontrolwpAI | 15/6/2026 | 17/6/2026 | Unauthenticated Privilege Escalation in iControlWP <= 5.5.3 versions. | |
| Analizada | Alta (8.8) | 0.20% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Export CSV - CSV Injection vulnerability. It is vulnerable to a reflected cross-site scripting vulnerability. This was caused by an insufficient sanitation of input parameters. . | |
| Analizada | Media (4.3) | 0.16% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl v4.0.0 was affected by Unhandled Exception - Stack Trace Disclosure vulnerability. The error occurs due to an undefined property being accessed in the application's JavaScript code. Specifically, the code attempts to read the property dashboard key from an object that is undefined. This issue likely stems… | |
| Analizada | Media (5.3) | 0.16% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Missing Security Headers vulnerability. which lead to cross-site scripting (XSS) attacks by enabling the built-in XSS filtering mechanisms of modern web browsers. | |
| Analizada | Media (4.3) | 0.10% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Missing Cookie Attributes vulnerability. It was observed that the application is missing several critical cookie attributes, including Secure and SameSite. And also path is set to root. | |
| Analizada | Media (4.3) | 0.17% | — | Hcltech Icontrol | 4/6/2026 | 22/7/2026 | HCL iControl was affected by Weak Input Validation vulnerability. This weakness is caused during implementation of an architectural security tactic. Received input that is expected to be of a certain type, but it does not validate or incorrectly validates that the input is actually of the expected type. | |
| Analizada | Media (6.3) | 0.28% | — | Vivaldigroup Icontrol+ ServerVivaldigroup Vivaldi Domotica Icontrol Firmware | 29/7/2025 | 17/6/2026 | A cross-site scripting vulnerability in Vivaldi United Group iCONTROL+ Server including Firmware version 4.7.8.0.eden Logic version 5.32 and below. This issue allows attackers to inject JavaScript payloads within the error or edit-menu-item parameters which are then executed in the victim's browser session. | |
| Modificada | Crítica (9.8) | 0.88% | — | Icontrolwp | 30/1/2025 | 17/6/2026 | The iControlWP – Multiple WordPress Site Manager plugin for WordPress is vulnerable to PHP Object Injection in all versions up to, and including, 4.4.5 via deserialization of untrusted input from the reqpars parameter. This makes it possible for unauthenticated attackers to inject a PHP Object. No known POP chain is… |