Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3222▲ 222 respecto a la semana anterior
Críticas / altas1465▲ 132 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)511▼ 31 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.3) | 0.16% | — | AJK Automated Logout | 26/3/2026 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Drupal Automated Logout allows Cross Site Request Forgery.This issue affects Automated Logout: from 0.0.0 before 1.7.0, from 2.0.0 before 2.0.2. | |
| Pendiente de análisis | Alta (7.5) | 0.54% | — | Automatedlogic WebctrlAIBacnetAI | 21/3/2026 | 17/6/2026 | WebCTRL systems that communicate over BACnet inherit the protocol's lack of network layer authentication. WebCTRL does not implement additional validation of BACnet traffic so an attacker with network access could spoof BACnet packets directed at either the WebCTRL server or associated AutomatedLogic controllers.… | |
| Aplazada | Alta (7) | 0.16% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 22/1/2026 | 17/6/2026 | Storing Passwords in a Recoverable Format vulnerability in Automated Logic WebCTRL on Windows, Carrier i-Vu on Windows. Storing Passwords in a Recoverable Format vulnerability (CWE-257) in the Web session management component allows an attacker to access stored passwords in a recoverable format which makes them… | |
| Aplazada | Alta (8.7) | 0.33% | — | Carrier Zone ControllerAIAutomatedlogic Zone ControllerAI | 27/11/2025 | 17/6/2026 | A vulnerability in Automated Logic and Carrier's Zone Controller via BACnet protocol causes the device to crash. The device enters a fault state; after a reset, a second packet can leave it permanently unresponsive until a manual power cycle is performed. | |
| Aplazada | Alta (8.8) | 0.34% | — | Carrier I-vu Gen5 RouterAIAutomatedlogic I-vu Gen5 RouterAI | 27/11/2025 | 17/6/2026 | — | |
| Aplazada | Media (6.9) | 0.31% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 27/11/2025 | 17/6/2026 | The reflective cross-site scripting vulnerability found in ALC WebCTRL and Carrier i-Vu in versions older than 8.0 affects login panels allowing a malicious actor to compromise the client browser . | |
| Aplazada | Crítica (9.2) | 0.33% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 27/11/2025 | 17/6/2026 | The Access Control Bypass vulnerability found in ALC WebCTRL and Carrier i-Vu in versions up to and including 8.5 allows a malicious actor to bypass intended access restrictions and expose sensitive information via the web based building automation server. | |
| Aplazada | Media (5.4) | 0.12% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 19/11/2025 | 17/6/2026 | Reflected XSS using a specific URL in Automated Logic WebCTRL and Carrier i-VU can allow delivery of malicious payload due to a specific GET parameter not being sanitized. | |
| Aplazada | Alta (8.6) | 0.16% | — | Carrier I-vuAIAutomatedlogic WebctrlAI | 19/11/2025 | 17/6/2026 | Open Redirect in URL parameter in Automated Logic WebCTRL and Carrier i-Vu versions 6.0, 6.5, 7.0, 8.0, 8.5, 9.0 may allow attackers to exploit user sessions. | |
| Analizada | Media (4.3) | 0.18% | — | Hcltech Dryice Iautomate | 5/11/2025 | 17/6/2026 | HCL iAutomate v6.5.1 and v6.5.2 is susceptible to a sensitive information disclosure. An HTTP GET method is used to process a request and includes sensitive information in the query string of that request. An attacker could potentially access information or resources they were not intended to see. | |
| Analizada | Baja (2.1) | 0.34% | — | Fabian Automated Voting System | 27/10/2025 | 17/6/2026 | A security flaw has been discovered in code-projects Automated Voting System 1.0. The affected element is an unknown function of the file /admin/user.php. Performing manipulation of the argument Username results in sql injection. The attack is possible to be carried out remotely. The exploit has been released to the… | |
| Analizada | Alta (7.5) | 0.23% | — | Connectwise Automate | 16/10/2025 | 17/6/2026 | The ConnectWise Automate Agent does not fully verify the authenticity of files downloaded from the server, such as updates, dependencies, and integrations. This creates a risk where an on-path attacker could perform a man-in-the-middle attack and substitute malicious files for legitimate ones by impersonating a… | |
| Analizada | Alta (7.5) | 0.21% | — | Connectwise Automate | 16/10/2025 | 17/6/2026 | In the ConnectWise Automate Agent, communications could be configured to use HTTP instead of HTTPS. In such cases, an on-path threat actor with a man-in-the-middle network position could intercept, modify, or replay agent-server traffic. Additionally, the encryption method used to obfuscate some communications over… | |
| Analizada | Baja (2) | 0.43% | — | Fabian Automated Voting System | 13/10/2025 | 17/6/2026 | A vulnerability was determined in code-projects Automated Voting System 1.0. Affected by this issue is some unknown functionality of the file /admin/update_user.php. This manipulation of the argument Password causes sql injection. The attack is possible to be carried out remotely. The exploit has been publicly… | |
| Analizada | Baja (2.1) | 0.42% | — | Fabian Automated Voting System | 13/10/2025 | 17/6/2026 | A vulnerability was found in code-projects Automated Voting System 1.0. Affected by this vulnerability is an unknown functionality of the file /admin/add_candidate_modal.php.. The manipulation of the argument firstname results in sql injection. The attack can be executed remotely. The exploit has been made public and… | |
| Analizada | Alta (8.8) | 24% | — | Chef Automate | 29/9/2025 | 17/6/2026 | In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in the compliance service via improperly neutralized inputs used in an SQL command using a well-known token. | |
| Analizada | Alta (8.8) | 0.37% | — | Chef Automate | 29/9/2025 | 17/6/2026 | In Progress Chef Automate, versions earlier than 4.13.295, on Linux x86 platform, an authenticated attacker can gain access to Chef Automate restricted functionality in multiple services via improperly neutralized inputs used in an SQL command. | |
| Aplazada | Media (5.9) | 0.22% | — | Gravitate Automated TesterAI | 22/9/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Gravitate Gravitate Automated Tester gravitate-automated-tester allows Stored XSS.This issue affects Gravitate Automated Tester: from n/a through <= 1.4.5. | |
| Analizada | Media (6.5) | 0.29% | — | Hcltech Dryice Iautomate | 24/7/2025 | 17/6/2026 | HCL iAutomate is affected by a sensitive data exposure vulnerability. This issue may allow unauthorized access to sensitive information within the system. | |
| Analizada | Media (6.5) | 0.26% | — | Hcltech Dryice Iautomate | 24/7/2025 | 17/6/2026 | HCL iAutomate includes hardcoded credentials which may result in potential exposure of confidential data if intercepted or accessed by unauthorized parties. | |
| Analizada | Alta (7.1) | 0.33% | — | Hcltech Dryice Iautomate | 24/7/2025 | 17/6/2026 | HCL iAutomate is affected by an insufficient session expiration. This allows tokens to remain valid indefinitely unless manually revoked, increasing the risk of unauthorized access. | |
| Analizada | Media (5.5) | 0.70% | — | Fabian Automated Voting System | 20/6/2025 | 17/6/2026 | A vulnerability classified as problematic has been found in code-projects Automated Voting System 1.0. Affected is an unknown function of the file /vote.php of the component Backend. The manipulation leads to direct request. It is possible to launch the attack remotely. The exploit has been disclosed to the public and… | |
| Analizada | Crítica (9.8) | 1.2% | — | Microsoft Power Automate FOR Desktop | 5/6/2025 | 17/6/2026 | Exposure of sensitive information to an unauthorized actor in Power Automate allows an unauthorized attacker to elevate privileges over a network. | |
| Aplazada | Alta (8.7) | 0.37% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | 266 vulnerability in Crestron Automate VX allows Privilege Escalation.This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. | |
| Aplazada | Crítica (10) | 0.28% | — | Crestron Automate VXAI | 6/5/2025 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in Crestron Automate VX allows Sniffing Network Traffic. The device allows Web UI and API access over non-secure network ports which exposes sensitive information such as user passwords. This issue affects Automate VX: from 5.6.8161.21536 through 6.4.0.49. |