Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.2% | — | Schneider-electric Interactive Graphical Scada System | 11/6/2021 | 17/6/2026 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 1.2% | — | Schneider-electric Interactive Graphical Scada System | 11/6/2021 | 17/6/2026 | A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition. | |
| Modificada | Alta (7.8) | 1.2% | — | Schneider-electric Interactive Graphical Scada System | 11/6/2021 | 17/6/2026 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition. | |
| Modificada | Alta (7.8) | 0.85% | — | Schneider-electric Interactive Graphical Scada System | 11/6/2021 | 17/6/2026 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 1.2% | — | Schneider-electric Interactive Graphical Scada System | 11/6/2021 | 17/6/2026 | A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file is imported to IGSS Definition. | |
| Analizada | Media (5.4) | 48% | ⚠ Explotación activa | Scadabr | 11/6/2021 | 17/6/2026 | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows stored XSS via system_settings.shtm. | |
| Analizada | Alta (8.8) | 39% | ⚠ Explotación activa💥 PoC | Scadabr | 11/6/2021 | 17/6/2026 | OpenPLC ScadaBR through 0.9.1 on Linux and through 1.12.4 on Windows allows remote authenticated users to upload and execute arbitrary JSP files via view_edit.shtm. | |
| Modificada | Media (6.7) | 0.17% | — | Schneider-electric ClearscadaSchneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 26/5/2021 | 17/6/2026 | Use of Password Hash with Insufficient Computational Effort vulnerability exists in ClearSCADA (all versions), EcoStruxure Geo SCADA Expert 2019 (all versions), and EcoStruxure Geo SCADA Expert 2020 (V83.7742.1 and prior), which could cause the revealing of account credentials when server database files are available.… | |
| Modificada | Alta (8.8) | 1.2% | — | Advantech Webaccess/scada | 26/4/2021 | 17/6/2026 | Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system. | |
| Modificada | Media (6.1) | 0.71% | — | Advantech Webaccess/scada | 18/3/2021 | 17/6/2026 | WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser actions. | |
| Modificada | Alta (7.8) | 0.93% | — | Schneider-electric Interactive Graphical Scada System | 11/3/2021 | 17/6/2026 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to… | |
| Modificada | Alta (7.8) | 0.88% | — | Schneider-electric Interactive Graphical Scada System | 11/3/2021 | 17/6/2026 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to… | |
| Modificada | Alta (7.8) | 2.2% | — | Schneider-electric Interactive Graphical Scada System | 11/3/2021 | 17/6/2026 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could cause remote code execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition. | |
| Modificada | Alta (7.8) | 2.2% | — | Schneider-electric Interactive Graphical Scada System | 11/3/2021 | 17/6/2026 | A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in loss of data or remote code execution when malicious CGF (Configuration Group File) file is imported to… | |
| Modificada | Alta (7.8) | 0.55% | — | Advantech Webaccess/scada | 3/3/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. | |
| Modificada | Alta (8.8) | 1.6% | — | Advantech Webaccess/scada | 23/2/2021 | 17/6/2026 | The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator. | |
| Modificada | Alta (8.8) | 0.50% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. | |
| Modificada | Alta (8.8) | 0.50% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. | |
| Modificada | Alta (8.8) | 0.50% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT… | |
| Modificada | Alta (8.8) | 0.49% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. | |
| Modificada | Alta (7.7) | 3.5% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 1.6% | — | SDG Pnpscada | 16/2/2021 | 9/7/2026 | PNPSCADA 2.200816204020 allows SQL injection via parameter 'interf' in /browse.jsp. Exploiting this issue could allow an attacker to compromise the application, access or modify data, or exploit latent vulnerabilities in the underlying database. | |
| Modificada | Media (6.1) | 0.71% | — | Sdgc Pnpscada | 10/2/2021 | 17/6/2026 | PNPSCADA 2.200816204020 allows cross-site scripting (XSS), which can execute arbitrary JavaScript in the victim's browser. | |
| Modificada | Alta (7.5) | 1.3% | — | Freyrscada Iec-60879-5-104 Server Simulator | 11/1/2021 | 17/6/2026 | A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.8) | 0.31% | — | Schneider-electric Ecostruxure GEO Scada Expert 2019Schneider-electric Ecostruxure GEO Scada Expert 2020 | 11/12/2020 | 17/6/2026 | A CWE-522: Insufficiently Protected Credentials vulnerability exists in EcoStruxure Geo SCADA Expert 2019 (Original release and Monthly Updates to September 2020, from 81.7268.1 to 81.7578.1) and EcoStruxure Geo SCADA Expert 2020 (Original release and Monthly Updates to September 2020, from 83.7551.1 to 83.7578.1),… |