Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2625▼ 312 respecto a la semana anterior
Críticas / altas1347▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)61▼ 466 respecto a la semana anterior
–

47 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.2)0.77%—Lb-link X-proAI15/8/202620/8/2026
A security flaw has been discovered in LB-LINK X-PRO 1.0.22-20231206. This affects an unknown function of the file /etc/config/easycwmp. The manipulation results in hard-coded credentials. It is possible to launch the attack remotely. Attacks of this nature are highly complex. The exploitability is reported as…
AplazadaAlta (8.2)2.9%—Lb-link X-proAI15/8/202620/8/2026
A vulnerability was identified in LB-LINK X-PRO 1.0.22-20231206. The impacted element is an unknown function of the file /etc/shadow. The manipulation leads to hard-coded credentials. It is possible to initiate the attack remotely. A high degree of complexity is needed for the attack. The exploitability is regarded as…
AplazadaBaja (2.1)0.47%—Nextlevelbuilder Ui-ux-pro-max-skillAI1/5/202617/6/2026
A vulnerability has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this issue is the function data.get of the file .claude/skills/design-system/scripts/generate-slide.py of the component Slide Generator. Such manipulation leads to cross site scripting. The attack may be performed from…
AplazadaBaja (2.1)0.41%—Nextlevelbuilder Ui-ux-pro-max-skillAI1/5/202617/6/2026
A flaw has been found in nextlevelbuilder ui-ux-pro-max-skill up to 2.5.0. Affected by this vulnerability is the function _format_plugins of the file .claude/skills/ui-styling/scripts/tailwind_config_gen.py of the component Tailwind Config Generator. This manipulation causes code injection. The attack is possible to…
AplazadaAlta (7.8)0.18%—Omron Cx-programmerAI17/2/202517/6/2026
Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability.
AnalizadaMedia (6.5)0.32%—Zyxel Nwa50ax FirmwareZyxel Nwa50ax-pro FirmwareZyxel Nwa55axe FirmwareZyxel Nwa90ax Firmware+1623/7/202417/6/2026
The improper privilege management vulnerability in the Zyxel WBE660S firmware version 6.70(ACGG.3) and earlier versions could allow an authenticated user to escalate privileges and download the configuration files on a vulnerable device.
AplazadaAlta (7.8)0.24%—Omron Cx-oneAIOmron Cx-programmerAI1/5/202417/6/2026
Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed.
AnalizadaAlta (7.2)1.3%—Zyxel Atp100 FirmwareZyxel Atp100w FirmwareZyxel Atp200 FirmwareZyxel Atp500 Firmware+3820/2/202417/6/2026
A post-authentication command injection vulnerability in the file upload binary in Zyxel ATP series firmware versions from 4.32 through 5.37 Patch 1, USG FLEX series firmware versions from 4.50 through 5.37 Patch 1, USG FLEX 50(W) series firmware versions from 4.16 through 5.37 Patch 1, USG20(W)-VPN series firmware…
ModificadaMedia (5.5)0.21%—Zyxel ZLDZyxel Nwa110ax FirmwareZyxel Nwa1123acv3 FirmwareZyxel Nwa210ax Firmware+1628/11/202317/6/2026
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series…
ModificadaMedia (5.5)0.22%—Zyxel ZLDZyxel Nwa110ax FirmwareZyxel Nwa1123acv3 FirmwareZyxel Nwa210ax Firmware+1628/11/202317/6/2026
An improper privilege management vulnerability in the debug CLI command of the Zyxel ATP series firmware versions 4.32 through 5.37, USG FLEX series firmware versions 4.50 through 5.37, USG FLEX 50(W) series firmware versions 4.16 through 5.37, USG20(W)-VPN series firmware versions 4.16 through 5.37, VPN series…
ModificadaAlta (7.8)0.24%—Omron Cx-programmer3/8/202317/6/2026
Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314.
ModificadaAlta (7.8)0.24%—Omron Cx-programmer3/8/202317/6/2026
Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314.
ModificadaAlta (7.8)0.24%—Omron Cx-programmer3/8/202317/6/2026
Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317.
ModificadaAlta (7.8)0.22%—Omron Cx-programmer3/8/202317/6/2026
Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
ModificadaAlta (7.8)0.24%—Omron Cx-programmer3/8/202317/6/2026
Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
ModificadaAlta (7.8)0.22%—Omron Cx-programmer3/8/202317/6/2026
Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur.
ModificadaMedia (6.5)0.77%—Zyxel Atp200 FirmwareZyxel Atp100 FirmwareZyxel Atp700 FirmwareZyxel Atp500 Firmware+4724/4/202317/6/2026
A post-authentication information exposure vulnerability in the CGI program of Zyxel ATP series firmware versions 4.32 through 5.35, USG FLEX series firmware versions 4.50 through 5.35, USG FLEX 50(W) firmware versions 4.16 through 5.35, USG20(W)-VPN firmware versions 4.16 through 5.35, VPN series firmware versions…
ModificadaAlta (7.8)0.28%—Omron Cx-programmer7/12/202217/6/2026
Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
ModificadaAlta (7.8)0.25%—Omron Cx-programmer7/12/202217/6/2026
Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
ModificadaAlta (7.8)0.26%—Omron Cx-programmer7/12/202217/6/2026
Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file.
ModificadaCrítica (9.8)0.71%—Omron Cx-programmer6/10/202217/6/2026
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
ModificadaCrítica (9.8)0.71%—Omron Cx-programmer6/10/202217/6/2026
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
ModificadaCrítica (9.8)0.71%—Omron Cx-programmer6/10/202217/6/2026
OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)0.25%—Omron Cx-programmer12/9/202217/6/2026
Opening a specially crafted file could cause the affected product to fail to release its memory reference potentially resulting in arbitrary code execution.
ModificadaAlta (7.5)0.65%—Omron Sysmac CS1 FirmwareOmron Sysmac Cj2m FirmwareOmron Sysmac Cj2h FirmwareOmron Sysmac Cp1e Firmware+426/7/202217/6/2026
Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using…