Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2860▼ 336 respecto a la semana anterior
Críticas / altas1383▼ 43 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 214 respecto a la semana anterior
–

152 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.39%—Schneider-electric Struxureware Data Center Expert9/6/202620/7/2026
CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints.
AnalizadaMedia (6.8)0.20%—Schneider-electric Ecostruxure Machine Expert Hvac14/5/202617/6/2026
CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it.
AnalizadaAlta (8.2)0.49%—Schneider-electric Ecostruxure Panel Server Pas400 FirmwareSchneider-electric Ecostruxure Panel Server Pas600 FirmwareSchneider-electric Ecostruxure Panel Server Pas600v2 FirmwareSchneider-electric Ecostruxure Panel Server Pas800 Firmware+112/5/202624/6/2026
CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials.
AnalizadaAlta (7.2)0.23%—Schneider-electric Ecostruxure Automation Expert10/3/202623/6/2026
CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent…
AnalizadaAlta (7)0.32%—Schneider-electric Ecostruxure Foxboro DCS Control Software10/3/202624/6/2026
CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file.
AnalizadaAlta (8.5)0.19%—Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation10/3/202624/6/2026
CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization.
AnalizadaAlta (8.4)0.35%—Schneider-electric Ecostruxure Power Build - Rapsody15/1/20263/9/2026
CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody.
AnalizadaAlta (8.4)0.16%—Schneider-electric Ecostruxure Power Build - Rapsody15/1/20263/9/2026
CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody.
AplazadaAlta (8.1)0.53%—Ancorathemes StruxAI18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Strux strux allows PHP Local File Inclusion.This issue affects Strux: from n/a through <= 1.9.
AnalizadaCrítica (10)0.65%—Schneider-electric Ecostruxure IT Gateway13/11/202417/6/2026
CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices.
AnalizadaAlta (7.8)0.21%—Schneider-electric Vijeo DesignerSchneider-electric Vijeo Designer Embedded IN Ecostruxure Machine Expert11/9/202417/6/2026
CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries.
ModificadaAlta (7.8)0.24%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services11/7/202417/6/2026
CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModificadaMedia (5.5)0.15%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services11/7/202417/6/2026
CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModificadaAlta (7.1)0.15%—Schneider-electric Ecostruxure Foxboro DCS Control Core Services11/7/202417/6/2026
CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver.
ModificadaAlta (7.8)0.24%—Schneider-electric Ecostruxure IT Gateway12/6/202417/6/2026
CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user.
AnalizadaAlta (7.7)0.23%—Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert14/2/202417/6/2026
CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert.
AnalizadaAlta (8.1)0.32%—Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp341000h FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp342010 Firmware+4214/2/202417/6/2026
CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack.
AnalizadaAlta (7.1)0.15%—Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert14/2/202417/6/2026
CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation.
ModificadaMedia (6.1)0.41%—Schneider-electric Ecostruxure Power Monitoring Expert15/11/202317/6/2026
A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload.
ModificadaMedia (6.1)0.45%—Schneider-electric Ecostruxure Power Monitoring Expert15/11/202317/6/2026
A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed.
ModificadaCrítica (9.8)0.92%—Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports4/10/202317/6/2026
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
ModificadaMedia (5.5)0.21%—Ecostruxure OPC UA Server Expert12/7/202317/6/2026
A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server.
ModificadaAlta (7.2)0.86%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored.
ModificadaAlta (7.2)0.86%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages.
ModificadaAlta (8.8)0.60%—Schneider-electric Struxureware Data Center Expert12/7/202317/6/2026
A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration…
Orbitaley — Vulnerabilidades