Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
–

4288 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
RecibidaMedia (5.6)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
- OS Command Injection vulnerability in Johnson Controls EasyIO FS32 allows - Command Injection. This issue affects EasyIO FS32: before 3.0b63.
RecibidaMedia (5)——Johnsoncontrols Easyio Fs32AI1/10/20261/10/2026
: Use of Hard-coded Credentials vulnerability in Johnson Controls EasyIO FS32 allows : Exploitation of Default or Hard-coded Credentials. This issue affects EasyIO FS32: before 3.0b63.
RecibidaMedia (5.6)——Johnsoncontrols Easy IO FGAI1/10/20261/10/2026
- Improper Privilege Management vulnerability in Johnson Controls Easy IO FG allows (Brute Force). This issue affects Easy IO FG: before 2.0b52.
AplazadaBaja (3.1)——F5 IcontrolAI1/10/20261/10/2026
iControl is affected by a Session Timeout vulnerability, which could allow an attacker to exploit an unattended or abandoned active session, enabling unauthorized access to the application and the ability to perform actions on behalf of the victim.
AplazadaBaja (3.1)——Hcltech IcontrolAI1/10/20261/10/2026
iControl is affected by a Missing Secure Attribute vulnerability, which could allow an attacker to intercept cookies transmitted over unencrypted HTTP connections, enabling the unauthorized extraction of sensitive information such as session identifiers.
AplazadaBaja (3.1)——F5 IcontrolAI1/10/20261/10/2026
iControl is affected by an Improper Error Handling vulnerability, which could allow an unauthenticated attacker to trigger verbose database and system errors, enabling the disclosure of sensitive internal infrastructure details used to plan advanced targeted attacks.
AplazadaMedia (4.3)——F5 IcontrolAI1/10/20261/10/2026
iControl is affected by an insecure Cross-Origin Resource Sharing (CORS) policy vulnerability, which could allow a malicious website to execute cross-origin requests with included credentials, enabling an attacker to access and exfiltrate sensitive data within the context of the victim's active session.
AplazadaAlta (8.8)——Hcltech IcontrolAI1/10/20261/10/2026
iControl is affected by a Broken Access Control vulnerability, which could allow an attacker to exploit missing authentication checks or insecure direct object references (IDOR), enabling privilege escalation and the unauthorized modification or deletion of sensitive application data.
AplazadaMedia (6.8)0.17%—Pardus Parental ControlAI29/9/202630/9/2026
Pardus Parental Control before 0.7.0 contains an incorrect authorization vulnerability in the polkit policy that allows unprivileged local users to disable parental controls as root. Attackers can invoke PPCActivator.py with the --disable argument via pkexec to remove all restrictions including DNS filtering and…
AplazadaMedia (5.6)0.11%—ABB Protection AND Control IED ManagerAI28/9/202628/9/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.
AplazadaAlta (7.1)0.09%—ABB Protection AND Control IED ManagerAI28/9/202628/9/2026
Incorrect Permission Assignment for Critical Resource vulnerability in ABB Protection and control IED manager (PCM600). This issue affects Protection and control IED manager (PCM600): through 2.14.
AnalizadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Predictable exact value from previous values vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23.
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior…
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to unpredictable or erroneous behavior…
ModificadaAlta (8.8)0.38%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Memory overflow vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading Memory overflow vulnerability leading to…
ModificadaAlta (7)0.24%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to a feature policy bypass due to improper HTTP URL based expression…
AnalizadaCrítica (9.3)0.36%—Citrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Inconsistent interpretation of HTTP requests ('HTTP Request/Response smuggling') vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1-37.279 and NDcPP; Gateway: before 14.1-73.37 FIPS and before…
AnalizadaCrítica (9.5)1.3%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202628/9/2026
Vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to Remote Code Execution or Denial of Service
AnalizadaCrítica (9.5)1.1%⚠ Explotación activaCitrix Netscaler Application Delivery ControllerCitrix Netscaler Gateway27/9/202629/9/2026
Improper input validation vulnerability in Citrix NetScaler ADC and Citrix NetScaler Gateway. This issue affects ADC: before 14.1-73.37, before 13.1-64.23, before 14.1-73.37 FIPS, and before 13.1.37.279 FIPS and NDcPP; Gateway: before 14.1-73.37 and before 13.1-64.23 leading to an unauthenticated attacker to execute…
AplazadaAlta (7.5)0.36%—Ciena Navigator Network Control SuiteAI25/9/202628/9/2026
Ciena Navigator Network Control Suite (NCS) contains an information exposure vulnerability in an event-streaming API that does not properly enforce authentication. An unauthenticated attacker with network access to the affected service could access the event stream and potentially obtain sensitive information.
Pendiente de análisisAlta (8.1)0.09%—Dell Rugged Control CenterAI24/9/202629/9/2026
Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Pendiente de análisisMedia (4.4)0.09%—Dell Rugged Control CenterAI24/9/202629/9/2026
Dell Rugged Control Center (RCC), versions prior to 5.2.206, contain an Improper Authorization vulnerability. A low privileged attacker with local access could potentially exploit this vulnerability, leading to Elevation of Privileges.
Pendiente de análisisMedia (6.4)0.17%—Ansible Automation PlatformAIAnsible Automation ControllerAI23/9/202624/9/2026
A server-side request forgery flaw was found in the Ansible Automation Platform automation-controller email notification backend. The email backend passes the user-supplied SMTP host and port from a notification template directly to the SMTP client without validating that the target is not an internal, loopback,…
Pendiente de análisisCrítica (9.9)0.43%—Ansible Automation PlatformAIAnsible Automation-controllerAI23/9/202625/9/2026
A flaw was found in the Ansible Automation Platform automation-controller. When a WorkflowJobTemplate is copied, the deep-copy permission sanitizer validates only the inventory, unified_job_template, and credentials of each cloned node and fails to check the instance_groups (and execution_environment and labels) that…
Pendiente de análisisMedia (5.3)0.34%—Ansible Automation PlatformAIAnsible Automation ControllerAI23/9/202626/9/2026
A flaw was found in the Ansible Automation Platform automation-controller. The unauthenticated Bitbucket Data Center webhook receiver skips HMAC signature verification for diagnostics:ping events after it has already looked up the target template, causing the endpoint to return HTTP 200 for a template that has a…