Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.2)0.69%—Frangoteam FuxaAINodered Node-redAI18/8/20269/9/2026
FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true, secureEnabled is true, and…
Pendiente de análisisCrítica (10)0.95%—Siemens Simatic Iot2050 AdvancedAINodered Node-redAI11/8/202628/8/2026
A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing…
RechazadaSin puntuar——Nodered Node-redAI5/8/202616/9/2026
Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority.
AplazadaCrítica (10)12%—Nodered Node REDAI1/7/202517/6/2026
An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default.
AplazadaCrítica (9.3)0.77%—Kunbus Revolution PI OSAINodered Node-redAI1/5/202517/6/2026
KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system.
ModificadaMedia (6.1)0.64%—Nodered Node-red-dashboard31/10/202217/6/2026
A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.…
ModificadaMedia (6.5)1.1%—Nodered Node-red26/2/202117/6/2026
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Projects API. If the Projects feature is enabled, a user with `projects.read` permission is able to access any file via the Projects API. The…
ModificadaMedia (6.5)1.4%—Nodered Node-red26/2/202117/6/2026
Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to affect the default behaviour of the…
ModificadaAlta (7.5)19%—Nodered Node-red-dashboard26/1/202117/6/2026
Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files.
ModificadaMedia (5.4)0.64%—Nodered Node-red28/1/202017/6/2026
A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc.
ModificadaMedia (5.4)0.57%—Nodered Node-red-dashboard8/10/201917/6/2026
It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default.