Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2624▼ 224 respecto a la semana anterior
Críticas / altas1373▲ 143 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
882 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | — | — | Publishpress SeriesAI | 2/10/2026 | 2/10/2026 | Authorization Bypass Through User-Controlled Key vulnerability in PublishPress PublishPress Series organize-series allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects PublishPress Series: from n/a through 3.1.3. | |
| Aplazada | Alta (7.2) | 0.24% | — | Johnsoncontrols NEO Series Mvp2AI | 1/10/2026 | 2/10/2026 | - On-Chip Debug Interface vulnerability in Johnson Controls Neo Series MVP2 allows Collect Data from Common Resource Locations. This issue affects Neo Series MVP2: before 3.3b63. | |
| Aplazada | Media (5.4) | 0.14% | — | Publishpress SeriesAI | 17/9/2026 | 17/9/2026 | Unauthenticated Cross Site Request Forgery (CSRF) in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Alta (7.6) | 0.38% | — | Publishpress SeriesAI | 17/9/2026 | 19/9/2026 | Administrator SQL Injection in PublishPress Series <= 3.1.3 versions. | |
| Aplazada | Media (6.5) | 0.22% | — | Publishpress SeriesAI | 17/9/2026 | 19/9/2026 | Contributor Cross Site Scripting (XSS) in PublishPress Series <= 3.1.3 versions. | |
| Analizada | Alta (7.5) | 0.19% | — | Qualcomm Q-7790 FirmwareQualcomm Qam8255p FirmwareQualcomm Qam8295p FirmwareQualcomm Qamsrv1h Firmware+372 | 17/9/2026 | 22/9/2026 | Transient DOS when processing authentication frames with invalid FILS information element header lengths. | |
| Pendiente de análisis | Alta (8.6) | 0.55% | — | Cisco Secure Firewall Adaptive Security ApplianceAICisco Secure Firewall Threat DefenseAICisco Secure Firewall 3100 SeriesAICisco Secure Firewall 4200 SeriesAI | 16/9/2026 | 18/9/2026 | A vulnerability in Datagram TLS (DTLS) message handling of Cisco Secure Firewall Adaptive Security Appliance (ASA) Software and Cisco Secure Firewall Threat Defense (FTD) Software for Cisco Secure Firewall 3100 Series and 4200 Series devices could allow an unauthenticated, remote attacker to cause a denial of service… | |
| Aplazada | Media (4.1) | 0.18% | — | Conprosys Nano SeriesAI | 14/9/2026 | 16/9/2026 | Plaintext storage of a password issue exists in CONPROSYS nano Series . If this vulnerability is exploited, an attacker with physical access to the product may obtain credentials. | |
| Aplazada | Media (5.3) | 0.46% | — | Conprosys Nano SeriesAI | 14/9/2026 | 16/9/2026 | Out-of-bounds write vulnerability exists in CONPROSYS nano Series. Receiving a specially crafted request created and sent by a remote attacker may cause a denial-of-service (DoS) condition. | |
| Aplazada | Media (5.1) | 0.24% | — | Conprosys Nano SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in CONPROSYS nano Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (8.7) | 0.61% | — | Conprosys TM SeriesAI | 14/9/2026 | 16/9/2026 | Unrestricted upload of file with dangerous type issue exists in CONPROSYS TM Series. If a specially crafted file is uploaded by a remote authenticated attacker, an arbitrary command may be executed on the product. | |
| Aplazada | Alta (8.7) | 1.9% | — | Conprosys TM SeriesAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS TM Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.3) | 0.45% | — | Conprosys PAC SeriesAI | 14/9/2026 | 16/9/2026 | An exposure of information through directory listing issue exists in CONPROSYS PAC Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | |
| Aplazada | Alta (8.7) | 1.9% | — | Conprosys PAC SeriesAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.1) | 0.26% | — | Conprosys PAC SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in CONPROSYS PAC Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (5.3) | 0.45% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | An exposure of information through directory listing issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. Accessing a specific URL on this product may allow a remote unauthenticated attacker to obtain the directory list without authentication. | |
| Aplazada | Alta (8.7) | 1.9% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Aplazada | Media (5.1) | 0.26% | — | Conprosys M2M Gateway SeriesAIConprosys M2M Controller SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in CONPROSYS M2M Gateway Series and CONPROSYS M2M Controller Series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (4.8) | 0.24% | — | Contec Ec1000 SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in Contec EC1000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Media (4.8) | 0.24% | — | Contec Fx5000 SeriesAIContec Fx4000 SeriesAIContec Fx3000 SeriesAI | 14/9/2026 | 16/9/2026 | Cross-site scripting vulnerability exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary script may be executed on a logged-in user's web browser. | |
| Aplazada | Alta (8.7) | 1.9% | — | Contec Fx5000 SeriesAIContec Fx4000 SeriesAIContec Fx3000 SeriesAI | 14/9/2026 | 16/9/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in Contec FX5000 series, FX4000 series, and FX3000 series. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Pendiente de análisis | Alta (7.2) | 0.37% | — | Paloaltonetworks Pan-osAIPaloaltonetworks Vm-seriesAIPaloaltonetworks Pa-seriesAIPaloaltonetworks PanoramaAI | 10/9/2026 | 11/9/2026 | A buffer overflow vulnerability in the XML processing functionality of Palo Alto Networks PAN-OS® software enables an unauthenticated attacker with network access to the management web or dataplane interface to cause a denial of service (DoS) condition on VM-Series firewalls or execute arbitrary code with root… | |
| Pendiente de análisis | Alta (7.5) | 0.37% | — | Cisco Desk Phone 9800 SeriesAICisco IP Phone 7800 SeriesAICisco IP Phone 8800 SeriesAICisco Video Phone 8875AI+1 | 2/9/2026 | 2/9/2026 | A vulnerability in Cisco Desk Phone 9800 Series, Cisco IP Phone 7800 and 8800 Series, and Cisco Video Phone 8875 that are running Cisco Session Initiation Protocol (SIP) Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is… | |
| Pendiente de análisis | Media (5.4) | 0.27% | — | Cisco Industrial Ethernet 1000 Series SwitchesAI | 19/8/2026 | 20/8/2026 | A vulnerability in the web-based management interface of Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an authenticated, remote attacker to conduct a stored cross-site scripting (XSS) attack against a user of the interface. This vulnerability is due to insufficient validation of user-supplied input… | |
| Pendiente de análisis | Media (5.3) | 0.51% | — | Cisco Industrial Ethernet 1000 Series SwitchesAI | 19/8/2026 | 20/8/2026 | A vulnerability in the handling of management plane packets by Cisco Industrial Ethernet (IE) 1000 Series Switches could allow an unauthenticated, remote attacker to cause the device manager, SSH, or API to become inaccessible.This vulnerability is due to insufficient protection against management plane flooding… |