Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (10) | 4.2% | — | Rockwellautomation Factorytalk Services Platform | 18/3/2021 | 17/6/2026 | In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly. | |
| Modificada | Alta (7.2) | 1.2% | — | Webfactoryltd 301 Redirects | 18/3/2021 | 17/6/2026 | Unvaludated input in the 301 Redirects - Easy Redirect Manager WordPress plugin, versions before 2.51, did not sanitise its "Redirect From" column when importing a CSV file, allowing high privilege users to perform SQL injections. | |
| Analizada | Crítica (9.8) | 64% | ⚠ Explotación activa💥 PoC | Rockwellautomation Factorytalk Services PlatformRockwellautomation Rslogix 5000Rockwellautomation Studio 5000 Logix Designer | 3/3/2021 | 17/6/2026 | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact… | |
| Modificada | Alta (7.5) | 34% | — | Rockwellautomation Factorytalk Diagnostics | 29/12/2020 | 17/6/2026 | An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer… | |
| Modificada | Media (5.5) | 4.8% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected. | |
| Modificada | Alta (7.5) | 39% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx… | |
| Modificada | Alta (7.5) | 25% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected. | |
| Modificada | Alta (7.5) | 3.9% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address… | |
| Modificada | Alta (7.5) | 1.9% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a denial-of-service condition on the device. | |
| Modificada | Crítica (9.8) | 6.8% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution. | |
| Modificada | Crítica (9.8) | 69% | 💥 Exploit | Jfrog Artifactory | 12/10/2020 | 17/6/2026 | Jfrog Artifactory uses default passwords (such as "password") for administrative accounts and does not require users to change them. This may allow unauthorized network-based attackers to completely compromise of Jfrog Artifactory. This issue affects Jfrog Artifactory versions prior to 6.17.0. | |
| Modificada | Alta (7.8) | 0.60% | — | Rockwellautomation Factorytalk View | 20/7/2020 | 17/6/2026 | In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. Rockwell Automation recommends applying patch 1126290. Before installing this patch, the… | |
| Modificada | Alta (8.1) | 53% | 💥 Exploit | Rockwellautomation Factorytalk View | 20/7/2020 | 17/6/2026 | In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk… | |
| Modificada | Media (4.3) | 53% | 💥 Exploit | Rockwellautomation Factorytalk View | 20/7/2020 | 17/6/2026 | All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users… | |
| Modificada | Alta (7.8) | 47% | 💥 Exploit | Rockwellautomation Factorytalk View | 20/7/2020 | 17/6/2026 | All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before… | |
| Modificada | Alta (8.8) | 0.74% | — | Ufactory Xarm 5 Lite FirmwareUfactory Xarm 6 FirmwareUfactory Xarm 7 Firmware | 15/7/2020 | 17/6/2026 | the main user account has restricted privileges but is in the sudoers group and there is not any mechanism in place to prevent sudo su or sudo -i to be run gaining unrestricted access to sensible files, encryption, or issue orders that disrupt robot operation. | |
| Modificada | Crítica (9.8) | 1.3% | — | Ufactory Xarm 5 Lite Firmware | 15/7/2020 | 17/6/2026 | The authentication implementation on the xArm controller has very low entropy, making it vulnerable to a brute-force attack. There is no mechanism in place to mitigate or lockout automated attempts to gain access. | |
| Modificada | Crítica (9.1) | 1.4% | — | Ufactory Xarm Studio | 15/7/2020 | 17/6/2026 | No authentication is required to control the robot inside the network, moreso the latest available user manual shows an option that lets the user to add a password to the robot but as in xarm_studio 1.3.0 the option is missing from the menu. Assuming manual control, even by forcefully removing the current operator… | |
| Modificada | Alta (8.8) | 1.1% | — | Rockwellautomation Factorytalk Services Platform | 23/6/2020 | 17/6/2026 | In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges. | |
| Modificada | Alta (7.5) | 1.8% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (7.5) | 5.2% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Crítica (9.8) | 12% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (8.1) | 2.8% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (7.5) | 1.1% | — | Jfrog Artifactory | 25/3/2020 | 17/6/2026 | Jenkins Artifactory Plugin 3.6.0 and earlier transmits configured passwords in plain text as part of its global Jenkins configuration form, potentially resulting in their exposure. | |
| Modificada | Media (6.5) | 0.80% | — | Jfrog Artifactory | 25/3/2020 | 17/6/2026 | Jenkins Artifactory Plugin 3.5.0 and earlier stores its Artifactory server password unencrypted in its global configuration file on the Jenkins master where it can be viewed by users with access to the master file system. |