Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2740▼ 483 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.7% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds read, which may cause a system crash, allow data exfiltration, or remote code execution. | |
| Modificada | Baja (3.3) | 3.7% | — | Lcds Laquis Scada | 1/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration. | |
| Modificada | Alta (8.8) | 2.6% | — | Lcds Laquis Scada | 1/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltration, or cause a system crash. | |
| Modificada | Alta (7.5) | 1.6% | — | Wellintech Kingscada | 24/12/2018 | 17/6/2026 | WellinTech KingSCADA before 3.7.0.0.1 contains a stack-based buffer overflow. The vulnerability is triggered when sending a specially crafted packet to the AlarmServer (AEserver.exe) service listening on TCP port 12401. | |
| Modificada | Alta (7.3) | 2.3% | — | Advantech Webaccess/scada | 19/12/2018 | 17/6/2026 | WebAccess/SCADA, WebAccess/SCADA Version 8.3.2 installed on Windows 2008 R2 SP1. Lack of proper validation of user supplied input may allow an attacker to cause the overflow of a buffer on the stack. | |
| Modificada | Media (6.1) | 0.76% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Scada Operation | 17/12/2018 | 17/6/2026 | A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module,… | |
| Modificada | Media (6.1) | 0.85% | — | Spidercontrol Scada Webserver | 4/12/2018 | 17/6/2026 | Reflected cross-site scripting (non-persistent) in SCADA WebServer (Versions prior to 2.03.0001) could allow an attacker to send a crafted URL that contains JavaScript, which can be reflected off the web application to the victim's browser. | |
| Modificada | Alta (7.8) | 3.2% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remote code execution. | |
| Modificada | Alta (7.8) | 1.6% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input prior to performing write operations on a stack object, which may allow an attacker to execute code under the current process. | |
| Modificada | Alta (8.8) | 8.1% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution. | |
| Modificada | Crítica (9.8) | 6.0% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution. | |
| Modificada | Crítica (9.8) | 4.8% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior has several out-of-bounds read vulnerabilities, which may allow remote code execution. | |
| Modificada | Crítica (9.8) | 6.4% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior has an untrusted pointer dereference vulnerability, which may allow remote code execution. | |
| Modificada | Media (6.5) | 1.7% | — | Circontrol Circarlife Scada | 26/9/2018 | 17/6/2026 | An issue was discovered in CIRCONTROL CirCarLife before 4.3. Due to the storage of multiple sensitive information elements in a JSON format at /services/system/setup.json, an authenticated but unprivileged user can exfiltrate critical setup information. | |
| Modificada | Media (5.3) | 8.9% | 💥 Exploit | Circontrol Circarlife Scada | 18/9/2018 | 17/6/2026 | An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is system software information disclosure due to lack of authentication for /html/device-id. | |
| Modificada | Media (5.3) | 25% | 💥 Exploit | Circontrol Circarlife Scada | 18/9/2018 | 17/6/2026 | An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is PLC status disclosure due to lack of authentication for /html/devstat.html. | |
| Modificada | Media (5.3) | 9.5% | 💥 Exploit | Circontrol Circarlife Scada | 18/9/2018 | 17/6/2026 | An issue was discovered in CIRCONTROL CirCarLife before 4.3. There is internal installation path disclosure due to the lack of authentication for /html/repository. | |
| Modificada | Alta (7.5) | 0.89% | — | Circontrol Scada | 22/6/2018 | 17/6/2026 | CirCarLife Scada v4.2.4 allows unauthorized upgrades via requests to the html/upgrade.html and services/system/firmware.upgrade URIs. | |
| Modificada | Crítica (9.8) | 56% | 💥 Exploit | Circontrol Circarlife Scada | 22/6/2018 | 17/6/2026 | CirCarLife Scada before 4.3 allows remote attackers to obtain sensitive information via a direct request for the html/log or services/system/info.html URI. | |
| Modificada | Media (5.3) | 2.1% | 💥 PoC | Myscada Mypro | 28/5/2018 | 17/6/2026 | mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010. | |
| Modificada | Crítica (9.1) | 15% | 💥 Exploit | Myscada Mypro | 20/5/2018 | 17/6/2026 | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials. | |
| Modificada | Crítica (9.8) | 5.6% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a heap-based buffer overflow vulnerability has been identified, which may allow an attacker to… | |
| Modificada | Alta (7.8) | 0.36% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may allow an authenticated user to modify files… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization,… | |
| Modificada | Alta (7.5) | 2.5% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to disclose… |