Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
75 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Crítica (9.6) | 0.35% | — | Home-assistant Home AssistantAIHome-assistant SupervisorAI | 27/3/2026 | 17/6/2026 | Home Assistant is open source home automation software that puts local control and privacy first. Home Assistant apps (formerly add-ons) configured with host network mode expose unauthenticated endpoints bound to the internal Docker bridge interface to the local network. On Linux, this configuration does not restrict… | |
| Aplazada | Media (4.3) | 0.20% | — | SupervisorAI | 24/10/2025 | 17/6/2026 | The Supervisor plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several AJAX functions in all versions up to, and including, 1.3.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to update various plugin settings. | |
| Analizada | Crítica (9.3) | 0.52% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor (firmware version < 2.31F01) has a default admin user "ONEDAY" with a daily generated password. An attacker can predictably generate the password for ONEDAY. The oneday user cannot be deleted or modified by any user. | |
| Analizada | Alta (8.6) | 0.22% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) firmware upgrade packages are unsigned. An attacker can forge malicious firmware upgrade packages. An attacker with admin access to the application services can install a malicious firmware upgrade. | |
| Analizada | Crítica (9.2) | 0.47% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) generates the root linux password on each boot. An attacker can generate the root linux password for a vulnerable device based on known or easy to fetch parameters. | |
| Analizada | Alta (8.7) | 0.34% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) MGW contains an API call that lacks input validation. An attacker can use this command to continuously crash the application services. | |
| Analizada | Media (5.1) | 0.20% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can inject a stored XSS to the floorplan web page. | |
| Analizada | Alta (7.7) | 0.26% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) RCI service contains an API call to read users info, which returns all usernames and password hashes for the application services. | |
| Analizada | Alta (8.8) | 0.36% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) has a floor plan feature that allows for an unauthenticated attacker to upload floor plan files. By uploading a specially crafted floor plan file, an attacker can access any file from the E3 file system. | |
| Analizada | Media (5.3) | 0.31% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 17/6/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) application services (MGW and RCI) uses client side hashing for authentication. An attacker can authenticate by obtaining only the password hash. | |
| Analizada | Media (6.9) | 0.34% | — | Copeland E3 Supervisory Controller Firmware | 2/9/2025 | 30/9/2026 | E3 Site Supervisor Control (firmware version < 2.31F01) contains a hidden API call in the application services that enables SSH and Shellinabox, which exist but are disabled by default. An attacker with admin access to the application services can utilize this API to enable remote access to the underlying OS. | |
| Modificada | Crítica (10) | 72% | — | Home-assistantHome-assistant Supervisor | 8/3/2023 | 17/6/2026 | homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1 or older. Installation types, like Home… | |
| Modificada | Alta (8.8) | 0.40% | — | Cisco MDS 9506 FirmwareCisco MDS 9513 FirmwareCisco MDS 9706 FirmwareCisco MDS 9710 Firmware+140 | 25/8/2022 | 17/6/2026 | A vulnerability in the Cisco Discovery Protocol feature of Cisco FXOS Software and Cisco NX-OS Software could allow an unauthenticated, adjacent attacker to execute arbitrary code with root privileges or cause a denial of service (DoS) condition on an affected device. This vulnerability is due to improper input… | |
| Modificada | Alta (8.6) | 1.1% | — | Cisco Nexus 3016 FirmwareCisco Nexus 3016q FirmwareCisco Nexus 3048 FirmwareCisco Nexus 3064 Firmware+143 | 25/8/2022 | 17/6/2026 | A vulnerability in the OSPF version 3 (OSPFv3) feature of Cisco NX-OS Software could allow an unauthenticated, remote attacker to cause a denial of service (DoS) condition on an affected device. This vulnerability is due to incomplete input validation of specific OSPFv3 packets. An attacker could exploit this… | |
| Analizada | Crítica (10) | 100% | ⚠ Explotación activa | Siemens 6bk1602-0aa12-0tp0 FirmwareSiemens 6bk1602-0aa22-0tp0 FirmwareSiemens 6bk1602-0aa32-0tp0 FirmwareSiemens 6bk1602-0aa42-0tp0 Firmware+139 | 10/12/2021 | 11/8/2026 | Apache Log4j2 2.0-beta9 through 2.15.0 (excluding security releases 2.12.2, 2.12.3, and 2.3.1) JNDI features used in configuration, log messages, and parameters do not protect against attacker controlled LDAP and other JNDI related endpoints. An attacker who can control log messages or log message parameters can… | |
| Modificada | Media (6.5) | 0.81% | — | Omron Cx-supervisor | 19/10/2021 | 17/6/2026 | Out-of-bounds read vulnerability in CX-Supervisor v4.0.0.13 and v4.0.0.16 allows an attacker with administrative privileges to cause information disclosure and/or arbitrary code execution by opening a specially crafted SCS project files. | |
| Modificada | Media (4.3) | 0.68% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 6/5/2020 | 17/6/2026 | A vulnerability in role-based access control of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow a read-only authenticated, remote attacker to disable user accounts on an affected system. The vulnerability is due to incorrect… | |
| Modificada | Alta (8.8) | 1.7% | — | Omron Cx-supervisorTeamviewer | 26/11/2019 | 17/6/2026 | In Omron CX-Supervisor, Versions 3.5 (12) and prior, Omron CX-Supervisor ships with Teamviewer Version 5.0.8703 QS. This version of Teamviewer is vulnerable to an obsolete function vulnerability requiring user interaction to exploit. | |
| Modificada | Alta (8.2) | 2.3% | — | Supervisord Supervisor | 10/9/2019 | 17/6/2026 | In Supervisor through 4.0.2, an unauthenticated user can read log files or restart a service. Note: The maintainer responded that the affected component, inet_http_server, is not enabled by default but if the user enables it and does not set a password, Supervisor logs a warning message. The maintainer indicated the… | |
| Modificada | Crítica (9.8) | 4.5% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to bypass user authentication and gain access as an administrative user. The vulnerability is… | |
| Modificada | Crítica (9.8) | 76% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to acquire a valid session token with administrator privileges, bypassing user… | |
| Modificada | Alta (7.2) | 39% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an authenticated, remote attacker to execute arbitrary commands on the underlying Linux shell as the root user. Exploitation of… | |
| Modificada | Crítica (9.8) | 83% | — | Cisco Integrated Management Controller SupervisorCisco UCS DirectorCisco UCS Director Express FOR BIG Data | 21/8/2019 | 17/6/2026 | A vulnerability in Cisco Integrated Management Controller (IMC) Supervisor, Cisco UCS Director, and Cisco UCS Director Express for Big Data could allow an unauthenticated, remote attacker to log in to the CLI of an affected system by using the SCP User account (scpuser), which has default user credentials. The… | |
| Modificada | Alta (7.5) | 2.0% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the Intelligent Platform Management Interface (IPMI) implementation of Cisco Integrated Management Controller (IMC) could allow an unauthenticated, remote attacker to view sensitive system information. The vulnerability is due to insufficient security restrictions imposed by the affected software. A… | |
| Modificada | Alta (8.8) | 1.4% | — | Cisco Unified Computing SystemCisco Integrated Management Controller Supervisor | 21/8/2019 | 17/6/2026 | A vulnerability in the web server of Cisco Integrated Management Controller (IMC) could allow an authenticated, remote attacker to set sensitive configuration values and gain elevated privileges. The vulnerability is due to improper handling of substring comparison operations that are performed by the affected… |