Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2744▲ 67 respecto a la semana anterior
Críticas / altas1456▲ 350 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)92▼ 421 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.2) | 0.69% | — | Frangoteam FuxaAINodered Node-redAI | 18/8/2026 | 9/9/2026 | FUXA is a web-based Process Visualization (SCADA/HMI/Dashboard) software. In 1.3.2 and earlier, the allowDashboard authorization gate in server/integrations/node-red/index.js calls authJwt.verify for /nodered without inspecting the decoded identity. When nodeRedEnabled is true, secureEnabled is true, and… | |
| Pendiente de análisis | Crítica (10) | 0.95% | — | Siemens Simatic Iot2050 AdvancedAINodered Node-redAI | 11/8/2026 | 28/8/2026 | A vulnerability has been identified in SIMATIC IoT2050 Advanced (6ES7647-0BA00-1YA2) (All versions < V4.3.4.1 running Industrial OS with Node-RED installed). Affected devices do not enforce authentication on the Node-RED HTTP interface, allowing unauthenticated access to programming nodes that are capable of executing… | |
| Rechazada | Sin puntuar | — | — | Nodered Node-redAI | 5/8/2026 | 16/9/2026 | Rejected reason: This CVE ID has been rejected or withdrawn by its CVE Numbering Authority. | |
| Aplazada | Crítica (10) | 12% | — | Nodered Node REDAI | 1/7/2025 | 17/6/2026 | An unauthenticated remote attacker can run arbitrary commands on the affected devices with high privileges because the authentication for the Node_RED server is not configured by default. | |
| Aplazada | Crítica (9.3) | 0.77% | — | Kunbus Revolution PI OSAINodered Node-redAI | 1/5/2025 | 17/6/2026 | KUNBUS Revolution Pi OS Bookworm 01/2025 is vulnerable because authentication is not configured by default for the Node-RED server. This can give an unauthenticated remote attacker full access to the Node-RED server where they can run arbitrary commands on the underlying operating system. | |
| Modificada | Media (6.1) | 0.64% | — | Nodered Node-red-dashboard | 31/10/2022 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in node-red-dashboard. This issue affects some unknown processing of the file components/ui-component/ui-component-ctrl.js of the component ui_text Format Handler. The manipulation leads to cross site scripting. The attack may be initiated remotely.… | |
| Modificada | Media (6.5) | 1.1% | — | Nodered Node-red | 26/2/2021 | 17/6/2026 | Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier has a vulnerability which allows arbitrary path traversal via the Projects API. If the Projects feature is enabled, a user with `projects.read` permission is able to access any file via the Projects API. The… | |
| Modificada | Media (6.5) | 1.4% | — | Nodered Node-red | 26/2/2021 | 17/6/2026 | Node-Red is a low-code programming for event-driven applications built using nodejs. Node-RED 1.2.7 and earlier contains a Prototype Pollution vulnerability in the admin API. A badly formed request can modify the prototype of the default JavaScript Object with the potential to affect the default behaviour of the… | |
| Modificada | Alta (7.5) | 19% | — | Nodered Node-red-dashboard | 26/1/2021 | 17/6/2026 | Node-RED-Dashboard before 2.26.2 allows ui_base/js/..%2f directory traversal to read files. | |
| Modificada | Media (5.4) | 0.64% | — | Nodered Node-red | 28/1/2020 | 17/6/2026 | A stored XSS vulnerability is present within node-red (version: <= 0.20.7) npm package, which is a visual tool for wiring the Internet of Things. This issue will allow the attacker to steal session cookies, deface web applications, etc. | |
| Modificada | Media (5.4) | 0.57% | — | Nodered Node-red-dashboard | 8/10/2019 | 17/6/2026 | It is possible to inject JavaScript within node-red-dashboard versions prior to version 2.17.0 due to the ui_notification node accepting raw HTML by default. |