Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

1028 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.57%—Schneider-electric OPC UA Module FOR M580 FirmwareSchneider-electric X80 Advanced RTU Module Firmware13/7/202217/6/2026
A CWE-73: External Control of File Name or Path vulnerability exists that could cause loading of unauthorized firmware images when user-controlled data is written to the file path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100)…
ModificadaAlta (7.5)0.69%—Schneider-electric OPC UA Module FOR M580 FirmwareSchneider-electric X80 Advanced RTU Module Firmware13/7/202217/6/2026
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause denial of service when parsing the URL. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
ModificadaAlta (7.5)0.29%—Schneider-electric OPC UA Module FOR M580 FirmwareSchneider-electric X80 Advanced RTU Module Firmware13/7/202217/6/2026
A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists that could cause loading of unauthorized firmware images due to improper verification of the firmware signature. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module…
ModificadaAlta (7.5)0.72%—Schneider-electric OPC UA Module FOR M580 FirmwareSchneider-electric X80 Advanced RTU Module Firmware13/7/202217/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists that could cause unauthorized firmware image loading when unsigned images are added to the firmware image path. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA…
ModificadaAlta (7.5)0.89%—Schneider-electric OPC UA Module FOR M580 FirmwareSchneider-electric X80 Advanced RTU Module Firmware13/7/202217/6/2026
A CWE-476: NULL Pointer Dereference vulnerability exists that could cause a denial of service of the webserver when parsing JSON content type. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V2.01 and later), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
ModificadaAlta (7.5)0.78%—Schneider-electric OPC UA Module FOR M580 FirmwareSchneider-electric X80 Advanced RTU Module Firmware13/7/202217/6/2026
A CWE-835: Loop with Unreachable Exit Condition ('Infinite Loop') vulnerability exists that could cause a denial of service of the webserver due to improper handling of the cookies. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10…
ModificadaAlta (7.5)0.78%—Schneider-electric OPC UA Module FOR M580 FirmwareSchneider-electric X80 Advanced RTU Module Firmware13/7/202217/6/2026
A CWE-787: Out-of-bounds Write vulnerability exists that could cause a denial of service of the webserver due to improper parsing of the HTTP Headers. Affected Products: X80 advanced RTU Communication Module (BMENOR2200H) (V1.0), OPC UA Modicon Communication Module (BMENUA0100) (V1.10 and prior)
ModificadaAlta (7.5)1.3%—Siemens En100 Ethernet Module Dnp3 IP FirmwareSiemens En100 Ethernet Module IEC 104 FirmwareSiemens En100 Ethernet Module IEC 61850 FirmwareSiemens En100 Ethernet Module Modbus TCP Firmware+112/7/202217/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.40), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaCrítica (9.8)1.5%—Newsletter Module Project Newsletter Module5/7/202217/6/2026
Newsletter Module v3.x was discovered to contain a SQL injection vulnerability via the zemez_newsletter_email parameter at /index.php.
ModificadaAlta (7.5)1.2%—Siemens En100 Ethernet Module Dnp3 FirmwareSiemens En100 Ethernet Module IEC 104 FirmwareSiemens En100 Ethernet Module IEC 61850 FirmwareSiemens En100 Ethernet Module Modbus TCP Firmware+114/6/202217/6/2026
A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All…
ModificadaCrítica (9.8)0.85%—Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+2519/5/202217/6/2026
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,…
ModificadaMedia (6.7)1.1%—Cisco Cgr1000 Compute ModuleCisco Ic3000 Industrial Compute GatewayCisco Ir510 Operating SystemCisco IOS+115/4/202217/6/2026
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or…
ModificadaAlta (7.5)1.1%—Cisco Cgr1000 Compute ModuleCisco Ic3000 Industrial Compute GatewayCisco IOS15/4/202217/6/2026
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or…
ModificadaMedia (4.8)0.64%—Cisco Cgr1000 Compute ModuleCisco Ic3000 Industrial Compute GatewayCisco Ir510 Operating SystemCisco IOS+115/4/202217/6/2026
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or…
ModificadaMedia (5.3)1.3%—Cisco Cgr1000 Compute ModuleCisco Ic3000 Industrial Compute GatewayCisco IOSCisco IOS XE15/4/202217/6/2026
Multiple vulnerabilities in the Cisco IOx application hosting environment on multiple Cisco platforms could allow an attacker to inject arbitrary commands into the underlying host operating system, execute arbitrary code on the underlying host operating system, install applications without being authenticated, or…
ModificadaBaja (3.3)0.21%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
Hard-coded credentials in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enable attackers with command line access to access the device’s Wi-Fi module.
ModificadaAlta (7.1)0.47%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.
ModificadaAlta (7.5)0.62%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to recover user credentials of the administrative interface.
ModificadaAlta (7.5)1.9%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows unauthenticated remote attackers to access sensitive information and escalate privileges.
ModificadaMedia (6.3)0.21%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration.
ModificadaMedia (6.1)0.85%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to inject arbitrary web script or HTML into various locations.
ModificadaAlta (7.2)1.2%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root.
ModificadaMedia (6.1)0.66%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites.
ModificadaAlta (8.1)1.3%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.
ModificadaAlta (8.8)1.5%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.
Orbitaley — Vulnerabilidades