Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

435 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.3%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-284: Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow a user the ability to perform actions via the web interface at a higher privilege level.
ModificadaMedia (5.4)0.63%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow an attacker to perform actions on behalf of the authorized user when accessing an…
ModificadaAlta (7.2)2.1%—Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Power ManagerSchneider-electric Powerscada Expert With Advanced Reporting AND Dashboards+11/12/202017/6/2026
A CWE-284:Improper Access Control vulnerability exists in EcoStruxureª and SmartStruxureª Power Monitoring and SCADA Software (see security notification for version information) that could allow for arbitrary code execution on the server when an authorized user access an affected webpage.
ModificadaAlta (7.8)2.5%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)2.5%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-125 Out-of-bounds Read vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)2.5%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)2.5%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)2.5%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)2.4%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-787 Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)1.7%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)1.7%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-787: Out-of-bounds Write vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247, that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)2.5%—Schneider-electric Interactive Graphical Scada System19/11/202017/6/2026
A CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in IGSS Definition (Def.exe) version 14.0.0.20247 and prior that could cause Remote Code Execution when malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)1.9%—Laquisscada Scada14/10/202017/6/2026
An attacker who convinces a valid user to open a specially crafted project file to exploit could execute code under the privileges of the application due to an out-of-bounds read vulnerability on the LAquis SCADA (Versions prior to 4.3.1.870).
ModificadaAlta (7.8)1.4%—Schneider-electric Scadapack X70 Security Administrator16/9/202017/6/2026
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack x70 Security Administrator (V1.2.0 and prior) which could allow arbitrary code execution when an attacker builds a custom .SDB file containing a malicious serialized buffer.
ModificadaAlta (7.8)0.82%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-284 Improper Access Control vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place executables in a specific folder and run code whenever RemoteConnect is executed by the user.
ModificadaAlta (8.8)1.2%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-285 Improper Authorization vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows improper access to executable code folders.
ModificadaMedia (5.5)0.88%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Transversal') vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which allows an attacker to place content in any unprotected folder on the target system using a crafted .RCZ file.
ModificadaAlta (7.8)1.4%—Schneider-electric Scadapack 7X Remote Connect16/9/202017/6/2026
A CWE-502 Deserialization of Untrusted Data vulnerability exists in SCADAPack 7x Remote Connect (V3.6.3.574 and prior) which could allow arbitrary code execution when an attacker builds a custom .PRJ file containing a malicious serialized buffer.
ModificadaAlta (7.8)0.46%—Rapidscada Rapid Scada14/8/202017/6/2026
Rapid Software LLC Rapid SCADA 5.8.0 is affected by a local privilege escalation vulnerability in the ScadaAgentSvc.exe executable file. An attacker can obtain admin privileges by placing a malicious .exe file in the application and renaming it ScadaAgentSvc.exe, which would result in executing the binary as NT…
ModificadaAlta (7.8)0.81%—Lcds Laquis Scada4/5/202017/6/2026
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users
ModificadaMedia (5.5)0.83%—Lcds Laquis Scada4/5/202017/6/2026
LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users.
ModificadaCrítica (9.8)71%💥 ExploitHitachienergy Microscada PRO Sys60029/4/202017/6/2026
ABB MicroSCADA Pro SYS600 version 9.3 suffers from an instance of CWE-306: Missing Authentication for Critical Function.
ModificadaAlta (7.5)2.6%—Trianglemicroworks Scada Data Gateway15/4/202017/6/2026
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers cause a denial-of-service condition due to a lack of proper validation of the length of user-supplied data, prior to copying it to a fixed-length stack-based buffer. Authentication is not required to…
ModificadaAlta (7.5)2.5%—Trianglemicroworks Scada Data Gateway15/4/202017/6/2026
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to disclose sensitive information due to the lack of proper validation of user-supplied data, which can result in a read past the end of an allocated structure. Authentication is not required to exploit…
ModificadaCrítica (9.8)5.2%—Trianglemicroworks Scada Data Gateway15/4/202017/6/2026
Triangle MicroWorks SCADA Data Gateway 3.02.0697 through 4.0.122, 2.41.0213 through 4.0.122 allows remote attackers to execute arbitrary code due to the lack of proper validation of user-supplied data, which can result in a type confusion condition. Authentication is not required to exploit this vulnerability. Only…