Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

330 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.20%—Schneider-electric Hmibmuhi29d2801 FirmwareSchneider-electric Hmibmusi29d2801 FirmwareSchneider-electric Hmibmuci29d2w01 FirmwareSchneider-electric Hmibmu0i29d2001 Firmware+339/2/202217/6/2026
A CWE-276: Incorrect Default Permissions vulnerability exists that could cause unauthorized access to the base installation directory leading to local privilege escalation. Affected Product: Harmony/Magelis iPC Series (All Versions), Vijeo Designer (All Versions prior to V6.2 SP11 Multiple HotFix 4), Vijeo Designer…
ModificadaMedia (6.1)71%💥 ExploitCodemiq Wordpress Email Template Designer4/2/202217/6/2026
The WP HTML Mail WordPress plugin is vulnerable to unauthorized access which allows unauthenticated attackers to retrieve and modify theme settings due to a missing capability check on the /themesettings REST-API endpoint found in the ~/includes/class-template-designer.php file, in versions up to and including 3.0.9.…
ModificadaAlta (7.8)38%—Myscada Mydesigner19/11/202117/6/2026
mySCADA myDESIGNER Versions 8.20.0 and prior fails to properly validate contents of an imported project file, which may make the product vulnerable to a path traversal payload. This vulnerability may allow an attacker to plant files on the file system in arbitrary locations or overwrite existing files, resulting in…
ModificadaMedia (6.1)0.64%—Advantech Webaccess HMI Designer15/11/202117/6/2026
This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action.
ModificadaAlta (7.8)0.29%—Advantech Webaccess HMI Designer15/11/202117/6/2026
This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer
ModificadaAlta (7.8)11%—Myscada Mydesigner4/10/202117/6/2026
mySCADA myDESIGNER 8.20.0 and below allows Directory Traversal attacks when importing project files. If an attacker can trick a victim into importing a malicious mep file, then they gain the ability to write arbitrary files to OS locations where the user has permission. This would typically lead to code execution.
ModificadaCrítica (9.1)1.3%—Schneider-electric Vijeo DesignerSchneider-electric Ecostruxure Machine Expert2/9/202117/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists in Harmony/HMI Products Configured by Vijeo Designer (all versions prior to V6.2 SP11 ), Vijeo Designer Basic (all versions prior to V1.2), or EcoStruxure Machine Expert (all versions prior to V2.0) that could cause a Denial of…
ModificadaAlta (7.8)1.8%—Fatek Fvdesigner11/8/202117/6/2026
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to a stack-based buffer overflow, which may allow an attacker to execute arbitrary code.
ModificadaAlta (7.8)1.6%—Fatek Fvdesigner11/8/202117/6/2026
FATEK Automation FvDesigner, Versions 1.5.88 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a project file that may permit arbitrary code execution.
ModificadaAlta (7.8)2.0%—Fatek Fvdesigner11/8/202117/6/2026
An uninitialized pointer in FATEK Automation FvDesigner, Versions 1.5.88 and prior may be exploited while the application is processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
ModificadaAlta (8.8)0.87%—Codemiq Wordpress Email Template Designer7/7/202117/6/2026
Cross-site request forgery (CSRF) vulnerability in WordPress Email Template Designer - WP HTML Mail versions prior to 3.0.8 allows remote attackers to hijack the authentication of administrators via unspecified vectors.
ModificadaAlta (7.8)0.95%—Advantech Webaccess/hmi Designer24/6/202117/6/2026
The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
ModificadaAlta (7.8)0.97%—Advantech Webaccess/hmi Designer24/6/202117/6/2026
Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
ModificadaAlta (7.8)1.0%—Advantech Webaccess/hmi Designer24/6/202117/6/2026
Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior).
ModificadaCrítica (9.8)47%💥 ExploitRadykal Fancy Product Designer21/6/202117/6/2026
The Fancy Product Designer WordPress plugin before 4.6.9 allows unauthenticated attackers to upload arbitrary files, resulting in remote code execution.
ModificadaAlta (7.8)0.25%—Schneider-electric Vijeo DesignerSchneider-electric Ecostruxure Machine Expert26/5/202117/6/2026
Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service or unauthorized access to system information when interacting directly with a driver installed by Vijeo Designer or EcoStruxure Machine Expert
ModificadaMedia (6.5)1.1%—Avaya Aura Orchestration Designer23/4/202117/6/2026
An XML External Entities (XXE)vulnerability in the web-based user interface of Avaya Aura Orchestration Designer could allow an authenticated, remote attacker to gain read access to information that is stored on an affected system. The affected versions of Orchestration Designer includes all 7.x versions before 7.2.3.
ModificadaAlta (7.5)1.7%—Vaadin Designer23/4/202117/6/2026
Overly relaxed configuration of frontend resources server in Vaadin Designer versions 4.3.0 through 4.6.3 allows remote attackers to access project sources via crafted HTTP request.
AnalizadaCrítica (9.8)64%⚠ Explotación activa💥 PoCRockwellautomation Factorytalk Services PlatformRockwellautomation Rslogix 5000Rockwellautomation Studio 5000 Logix Designer3/3/202117/6/2026
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact…
ModificadaAlta (7.8)1.1%—Fatek Fvdesigner3/3/202117/6/2026
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds write while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
ModificadaAlta (7.8)1.1%—Fatek Fvdesigner3/3/202117/6/2026
An uninitialized pointer may be exploited in Fatek FvDesigner Version 1.5.76 and prior while the application is processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
ModificadaAlta (7.8)1.2%—Fatek Fvdesigner3/3/202117/6/2026
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to a stack-based buffer overflow while project files are being processed, allowing an attacker to craft a special project file that may permit arbitrary code execution.
ModificadaAlta (7.8)1.1%—Fatek Fvdesigner3/3/202117/6/2026
A use after free issue has been identified in Fatek FvDesigner Version 1.5.76 and prior in the way the application processes project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
ModificadaAlta (7.8)1.1%—Fatek Fvdesigner3/3/202117/6/2026
Fatek FvDesigner Version 1.5.76 and prior is vulnerable to an out-of-bounds read while processing project files, allowing an attacker to craft a special project file that may permit arbitrary code execution.
ModificadaCrítica (9.8)6.9%—Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+3719/2/202117/6/2026
Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all…
Orbitaley — Vulnerabilidades