Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

34 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.89%—Schneider-electric Sage RTU Firmware12/6/202417/6/2026
CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service of the device’s web interface when an attacker sends a specially crafted HTTP request.
ModificadaAlta (8.1)0.39%—Schneider-electric Sage RTU Firmware12/6/202417/6/2026
CWE-120: Buffer Copy without Checking Size of Input (‘Classic Buffer Overflow’) vulnerability exists that could allow a user with access to the device’s web interface to cause a fault on the device when sending a malformed HTTP request.
ModificadaAlta (7.5)0.79%—Schneider-electric Sage RTU Firmware12/6/202417/6/2026
CWE-252: Unchecked Return Value vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request.
ModificadaAlta (8.8)0.37%—Schneider-electric Sage RTU Firmware12/6/202417/6/2026
CWE-276: Incorrect Default Permissions vulnerability exists that could allow an authenticated user with access to the device’s web interface to perform unauthorized file and firmware uploads when crafting custom web requests.
ModificadaAlta (8.1)1.0%—Schneider-electric Sage RTU Firmware12/6/202417/6/2026
CWE-22: Improper Limitation of a Pathname to a Restricted Directory (‘Path Traversal’) vulnerability exists that could allow an authenticated user with access to the device’s web interface to corrupt files and impact device functionality when sending a crafted HTTP request.
ModificadaCrítica (9.8)0.53%—Schneider-electric Sage RTU Firmware12/6/202417/6/2026
CWE-787: Out-of-bounds Write vulnerability exists that could result in an authentication bypass when sending a malformed POST request and particular configuration parameters are set.
ModificadaCrítica (9.8)1.7%—Inea ME RTU Firmware20/11/202317/6/2026
Versions of INEA ME RTU firmware 3.36b and prior are vulnerable to operating system (OS) command injection, which could allow remote code execution.
ModificadaCrítica (9.8)0.86%—Inea ME RTU Firmware20/11/202317/6/2026
Versions of INEA ME RTU firmware 3.36b and prior do not require authentication to the "root" account on the host system of the device. This could allow an attacker to obtain admin-level access to the host system.
ModificadaCrítica (9.8)1.7%—Inea ME RTU Firmware20/4/202317/6/2026
Versions of INEA ME RTU firmware prior to 3.36 are vulnerable to OS command injection, which could allow an attacker to remotely execute arbitrary code.
ModificadaCrítica (9.8)1.8%—Honeywell Controledge PLC FirmwareHoneywell Controledge RTU Firmware31/8/202217/6/2026
Honeywell ControlEdge through R151.1 uses Hard-coded Credentials. According to FSCT-2022-0056, there is a Honeywell ControlEdge hardcoded credentials issue. The affected components are characterized as: SSH. The potential impact is: Remote code execution, manipulate configuration, denial of service. The Honeywell…
ModificadaCrítica (9.8)0.51%—Emerson Dl8000 FirmwareEmerson Roc809 FirmwareEmerson Roc800l FirmwareEmerson Fb3000 RTU Firmware+116/8/202217/6/2026
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and…
ModificadaAlta (8.1)2.0%💥 PoCCaphyon Advanced Installer3CX Call Flow Designer3CX CRM Template GeneratorBoomtv Streamer Portal+666/6/20229/7/2026
Caphyon Ltd Advanced Installer 19.3 and earlier and many products that use the updater from Advanced Installer (Advanced Updater) are affected by a remote code execution vulnerability via the CustomDetection parameter in the update check function. To exploit this vulnerability, a user must start an affected…
ModificadaAlta (7.5)1.0%—Schneider-electric Modicon M340 Bmxp342020 FirmwareSchneider-electric Bmxnoe0100 FirmwareSchneider-electric Bmxnoe0110 FirmwareSchneider-electric Bmxnoc0401 Firmware+1011/2/202217/6/2026
A CWE-787: Out-of-bounds Write vulnerability exists that could cause denial of service when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules: BMXNOE0100 (H),…
ModificadaAlta (7.5)1.0%—Schneider-electric Modicon M340 Bmxp342020 FirmwareSchneider-electric Bmxnoe0100 FirmwareSchneider-electric Bmxnoe0110 FirmwareSchneider-electric Bmxnoc0401 Firmware+1011/2/202217/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could cause denial of service of the device when an attacker sends a specially crafted HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet Communication Modules:…
ModificadaAlta (7.5)0.96%—Schneider-electric Modicon M340 Bmxp342020 FirmwareSchneider-electric Bmxnoe0100 FirmwareSchneider-electric Bmxnoe0110 FirmwareSchneider-electric Bmxnoc0401 Firmware+1011/2/202217/6/2026
A CWE-200: Information Exposure vulnerability exists that could cause sensitive information of files located in the web root directory to leak when an attacker sends a HTTP request to the web server of the device. Affected Product: Modicon M340 CPUs: BMXP34 (Versions prior to V3.40), Modicon M340 X80 Ethernet…
ModificadaMedia (6.1)4.0%💥 ExploitMitsubishielectric Smartrtu Firmware15/10/202117/6/2026
Mitsubishi Electric Europe B.V. SmartRTU devices allow XSS via the username parameter or PATH_INFO to login.php.
ModificadaAlta (7.5)20%💥 ExploitMitsubishielectric Smartrtu Firmware15/10/202117/6/2026
Mitsubishi Electric Europe B.V. SmartRTU devices allow remote attackers to obtain sensitive information (directory listing and source code) via a direct request to the /web URI.
ModificadaMedia (5.3)0.92%—Schneider-electric Modicon X80 Bmxnor0200h RTU Firmware11/6/202117/6/2026
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists in Modicon X80 BMXNOR0200H RTU SV1.70 IR22 and prior that could cause information leak concerning the current RTU configuration including communication parameters dedicated to telemetry, when a specially crafted HTTP request is…
ModificadaAlta (7.5)0.74%—Honeywell Controledge PLC FirmwareHoneywell Controledge RTU Firmware26/6/202017/6/2026
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes unencrypted passwords on the network.
ModificadaAlta (7.5)0.74%—Honeywell Controledge PLC FirmwareHoneywell Controledge RTU Firmware26/6/202017/6/2026
ControlEdge PLC (R130.2, R140, R150, and R151) and RTU (R101, R110, R140, R150, and R151) exposes a session token on the network.
ModificadaCrítica (9.8)58%💥 ExploitMitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware28/10/201917/6/2026
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote OS Command Injection vulnerability allows an attacker to execute arbitrary commands on the RTU due to the passing of unsafe user supplied data to the RTU's system shell.…
ModificadaCrítica (9.8)2.3%—Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware28/10/201917/6/2026
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Undocumented hard-coded user passwords for root, ineaadmin, mitsadmin, and maint could allow an attacker to gain unauthorised access to the RTU. (Also, the accounts ineaadmin and mitsadmin are…
ModificadaCrítica (9.8)1.9%—Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware28/10/201917/6/2026
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. Stored cleartext passwords could allow an unauthenticated attacker to obtain configured username and password combinations on the RTU due to the weak credentials management on the RTU. An…
ModificadaMedia (5.4)44%—Mitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware28/10/201917/6/2026
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. A number of stored cross-site script (XSS) vulnerabilities allow an attacker to inject malicious code directly into the application. An example input variable vulnerable to stored XSS is…
ModificadaAlta (7.5)42%💥 ExploitMitsubishielectric Smartrtu FirmwareInea Me-rtu Firmware28/10/201917/6/2026
An issue was discovered on Mitsubishi Electric Europe B.V. ME-RTU devices through 2.02 and INEA ME-RTU devices through 3.0. An unauthenticated remote configuration download vulnerability allows an attacker to download the smartRTU's configuration file (which contains data such as usernames, passwords, and other…
Orbitaley — Vulnerabilidades