Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
2356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.54% | — | Siemens Polarion ALM | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in Polarion V2310 (All versions), Polarion V2404 (All versions < V2404.4). The application insufficiently validates user input for database read queries. This could allow an authenticated remote attacker to conduct an SQL injection attack that bypasses authorization controls and… | |
| Aplazada | Alta (8.7) | 0.55% | — | Siemens Desigo CCAI | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in Desigo CC (All versions if access from Installed Clients to Desigo CC server is allowed from networks outside of a highly protected zone), Desigo CC (All versions if access from Installed Clients to Desigo CC server is only allowed within highly protected zones). The affected… | |
| Analizada | Media (6.3) | 0.44% | — | Siemens Telecontrol Server Basic | 17/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected product does not properly validate a length field in a serialized message which it uses to determine the amount of memory to be allocated for deserialization. This could allow an unauthenticated remote attacker to… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetOverview' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'MigrateDatabase' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.74% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetTraces' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.45% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.45% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ExportCertificate' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateBackup' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetLogs' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateLog' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.65% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockTraceLevelSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.65% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockTraceLevelSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.65% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateTraceLevelSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.65% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and… | |
| Analizada | Alta (8.7) | 0.65% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and… | |
| Analizada | Alta (8.7) | 0.65% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateWebServerGatewaySettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.65% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.65% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.70% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockTcmSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… |