Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

2356 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.81%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetProjects' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.81%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.81%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.81%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'DeleteProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.81%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.81%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.81%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateGateways' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateSmtpSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateTcmSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateUsers' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportDatabase' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectConnections' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to…
AnalizadaAlta (8.7)0.86%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write…
AnalizadaAlta (8.7)0.89%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'RestoreFromBackup' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaCrítica (9.3)1.0%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'Authenticate' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaCrítica (9.3)1.0%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'VerifyUser' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the…
AnalizadaCrítica (9.3)1.0%—Siemens Telecontrol Server Basic16/4/202517/6/2026
A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the…
AplazadaMedia (5.4)0.14%—Siemens License ServerAI8/4/202517/6/2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application does not properly restrict permissions of the users. This could allow a lowly-privileged attacker to escalate their privileges.
AplazadaMedia (5.4)0.16%—Siemens License ServerAI8/4/202517/6/2026
A vulnerability has been identified in Siemens License Server (SLS) (All versions < V4.3). The affected application searches for executable files in the application folder without proper validation. This could allow an attacker to execute arbitrary code with administrative privileges by placing a malicious executable…
AplazadaCrítica (9.3)0.74%—Siemens Industrial Edge Device KITAISiemens Industrial Edge OWN DeviceAISiemens Industrial Edge Virtual DeviceAISiemens Scalance Lpe9413AI+68/4/202517/6/2026
A vulnerability has been identified in Industrial Edge Device Kit - arm64 V1.17 (All versions), Industrial Edge Device Kit - arm64 V1.18 (All versions), Industrial Edge Device Kit - arm64 V1.19 (All versions), Industrial Edge Device Kit - arm64 V1.20 (All versions < V1.20.2-1), Industrial Edge Device Kit - arm64 V1.21…
AnalizadaMedia (6.9)0.38%—Siemens 7KT Pac1260 Data Manager Firmware8/4/202517/6/2026
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices allows to change the login password without knowing the current password. In combination with a prepared CSRF attack (CVE-2024-41795) an unauthenticated attacker could be able to set the…
AnalizadaMedia (6.9)0.21%—Siemens 7KT Pac1260 Data Manager Firmware8/4/202517/6/2026
A vulnerability has been identified in SENTRON 7KT PAC1260 Data Manager (All versions). The web interface of affected devices is vulnerable to Cross-Site Request Forgery (CSRF) attacks. This could allow an unauthenticated attacker to change arbitrary device settings by tricking a legitimate device administrator to…