Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
787 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.4) | 0.18% | — | Schneider-electric Igss DefinitionAI | 29/7/2026 | 30/7/2026 | CWE-787 Out-of-bounds write vulnerability exists that could cause loss of data or potentially risk arbitrary code execution when a malicious CGF file is imported to IGSS Definition. | |
| Analizada | Media (6.9) | 0.43% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-617 Reachable Assertion vulnerability exists that could allow an authenticated attacker to trigger a denial-of-service condition, impacting system availability when a specially crafted request is sent to a vulnerable network-exposed service. | |
| Analizada | Alta (8.6) | 1.7% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-78 Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability exists that could allow unauthorized execution of commands with elevated privileges, impacting system integrity, confidentiality, and availability when a privileged authenticated user interacts with a vulnerable… | |
| Analizada | Alta (8.7) | 0.46% | — | Schneider-electric Powerlogic P7 Firmware | 25/6/2026 | 1/7/2026 | CWE-476 NULL Pointer Dereference vulnerability exists that could cause a denial-of-service condition, rendering the device’s HMI and configuration functionality unavailable when malformed requests are received over exposed network interfaces. | |
| Analizada | Media (6.7) | 0.16% | — | Schneider-electric Easylogic T150 FirmwareSchneider-electric Saitel DP Firmware | 25/6/2026 | 14/7/2026 | CWE-732 Incorrect Permission Assignment for Critical Resource vulnerability that could cause unauthorized disclosure of password hashes and potential account compromise when an attacker with privileged local access reads improperly protected system files. | |
| Analizada | Alta (8.7) | 0.41% | — | Schneider-electric Easylogic T150 FirmwareSchneider-electric Saitel DP Firmware | 25/6/2026 | 14/7/2026 | CWE-522 Insufficiently Protected Credentials vulnerability that could cause unauthorized access and exposure of sensitive information when unauthenticated attacker accesses credentials stored within firmware or system files. With this credential an attacker could subsequently compromise the device if they have… | |
| Analizada | Alta (7.1) | 0.39% | — | Schneider-electric Struxureware Data Center Expert | 9/6/2026 | 20/7/2026 | CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. | |
| Analizada | Media (6.8) | 0.20% | — | Schneider-electric Ecostruxure Machine Expert Hvac | 14/5/2026 | 17/6/2026 | CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it. | |
| Analizada | Alta (8.2) | 0.49% | — | Schneider-electric Ecostruxure Panel Server Pas400 FirmwareSchneider-electric Ecostruxure Panel Server Pas600 FirmwareSchneider-electric Ecostruxure Panel Server Pas600v2 FirmwareSchneider-electric Ecostruxure Panel Server Pas800 Firmware+1 | 12/5/2026 | 24/6/2026 | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials. | |
| Analizada | Media (5.3) | 0.24% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-400 Uncontrolled Resource Consumption vulnerability exists that could cause excessive troubleshooting zip file creation and denial of service when a Web Admin user floods the system with POST /helpabout requests. | |
| Analizada | Media (6.9) | 0.19% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-116 Improper Encoding or Escaping of Output vulnerability exists that could cause log injection and forged log when an attacker alters the POST /j_security check request payload. | |
| Analizada | Media (5.3) | 0.17% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-1284 Improper Validation of Specified Quantity in Input vulnerability exists that could cause Event and Data Log truncation impacting log integrity when a Web Admin user alters the POST /logsettings request payload. | |
| Analizada | Media (6.9) | 0.27% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-307 Improper Restriction of Excessive Authentication Attempts vulnerability exists that would allow an attacker to gain access to the user account by performing an arbitrary number of authentication attempts with different credentials on a sequence of requests to multiple endpoints. | |
| Analizada | Baja (2.4) | 0.10% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-532 Insertion of Sensitive Information into Log File vulnerability exists that could cause confidential information to be exposed when a Web Admin user executes a malicious file provided by an attacker. | |
| Analizada | Media (5.3) | 0.23% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-93 Improper Neutralization of CRLF Sequences ('CRLF Injection') vulnerability exists that could cause application user credentials to reset when a Web Admin user alters the POST /setPCBEDesc request payload. | |
| Analizada | Media (6.9) | 0.20% | — | Schneider-electric Powerchute Serial Shutdown | 14/4/2026 | 17/6/2026 | CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause critical files overwritten with text data when a Web Admin user alters the POST /REST/upssleep request payload. | |
| Analizada | Alta (7.2) | 0.23% | — | Schneider-electric Ecostruxure Automation Expert | 10/3/2026 | 23/6/2026 | CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent… | |
| Analizada | Alta (7) | 0.32% | — | Schneider-electric Ecostruxure Foxboro DCS Control Software | 10/3/2026 | 24/6/2026 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file. | |
| Analizada | Media (5.1) | 0.22% | — | Schneider-electric Modicon M258 FirmwareSchneider-electric Modicon Lmc058 FirmwareSchneider-electric Modicon M251 FirmwareSchneider-electric Modicon M241 Firmware | 10/3/2026 | 23/6/2026 | CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause condition where authenticated attackers can have a victim’s browser run arbitrary JavaScript when the victim hovers over a maliciously crafted element on a web server containing the… | |
| Analizada | Media (6.9) | 0.46% | — | Schneider-electric Modicon M241 FirmwareSchneider-electric Modicon M251 FirmwareSchneider-electric Modicon M262 Firmware | 10/3/2026 | 23/6/2026 | CWE-404 Improper Resource Shutdown or Release vulnerability exists that could cause partial Denial of Service on Machine Expert protocol when an unauthenticated attacker sends malicious payload to occupy active communication channels. | |
| Analizada | Alta (8.5) | 0.19% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation | 10/3/2026 | 24/6/2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization. | |
| Analizada | Alta (8.4) | 0.35% | — | Schneider-electric Ecostruxure Power Build - Rapsody | 15/1/2026 | 3/9/2026 | CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody. | |
| Analizada | Alta (8.4) | 0.16% | — | Schneider-electric Ecostruxure Power Build - Rapsody | 15/1/2026 | 3/9/2026 | CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody. | |
| Aplazada | Media (5.6) | 0.11% | — | Schneider-electric Spectrum Power 4AI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to alter the local database which contains the application credentials. This allows an attacker to gain administrative application privileges. | |
| Aplazada | Alta (8.7) | 0.39% | — | Schneider-electric Spectrum PowerAI | 11/11/2025 | 26/9/2026 | A vulnerability has been identified in Spectrum Power 4 (All versions < V4.70 SP12 Update 2). The affected application is vulnerable to run arbitrary commands via the user interface. This user interface can be used via the network and allows the execution of commands as administrative application user. |