Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

474 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.8%—Schneider-electric Wonderware Indusoft WEB StudioSchneider-electric Wonderware Intouch13/11/201717/6/2026
A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution with high…
ModificadaCrítica (9.8)5.1%—Schneider-electric Wonderware Indusoft WEB StudioSchneider-electric Wonderware Intouch3/10/201717/6/2026
A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing…
ModificadaCrítica (9.8)27%💥 ExploitMobile-friendly-app-builder-by-easytouch Project Mobile-friendly-app-builder-by-easytouch14/9/201717/6/2026
Vulnerability in wordpress plugin mobile-friendly-app-builder-by-easytouch v3.0, The code in file ./mobile-friendly-app-builder-by-easytouch/server/images.php doesn't require authentication or check that the user is allowed to upload content.
ModificadaAlta (7.8)0.37%—EMC Elan Touchpad Driver29/8/201717/6/2026
An unquoted service path vulnerability was identified in the driver for the ElanTech Touchpad, various versions, used on some Lenovo brand notebooks (not ThinkPads). This could allow an attacker with local privileges to execute code with administrative privileges.
ModificadaMedia (5.3)0.45%—Fujielectric Monitouch V-sft14/8/201717/6/2026
An Improper Privilege Management issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. Monitouch V-SFT is installed in a directory with weak access controls by default, which could allow an authenticated attacker with local access to escalate privileges.
ModificadaAlta (8.8)5.1%—Fujielectric Monitouch V-sft14/8/201717/6/2026
A Heap-Based Buffer Overflow was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. A heap-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.
ModificadaAlta (8.8)5.2%—Fujielectric Monitouch V-sft14/8/201717/6/2026
A Stack-Based Buffer Overflow issue was discovered in Fuji Electric Monitouch V-SFT versions prior to Version 5.4.43.0. The stack-based buffer overflow vulnerability has been identified, which may cause a crash or allow remote code execution.
ModificadaCrítica (9.8)0.47%—Pdqinc Laserwash G5 FirmwarePdqinc Laserwash G5 S FirmwarePdqinc Laserwash M5 FirmwarePdqinc Laserwash 360 Firmware+77/8/201717/6/2026
A Missing Encryption of Sensitive Data issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions, ProTouch Tandem, all versions, ProTouch…
ModificadaCrítica (9.4)1.2%—Pdqinc Laserwash G5 FirmwarePdqinc Laserwash G5 S FirmwarePdqinc Laserwash M5 FirmwarePdqinc Laserwash 360 Firmware+77/8/201717/6/2026
An Improper Authentication issue was discovered in PDQ Manufacturing LaserWash G5 and G5 S Series all versions, LaserWash M5, all versions, LaserWash 360 and 360 Plus, all versions, LaserWash AutoXpress and AutoExpress Plus, all versions, LaserJet, all versions, ProTouch Tandem, all versions, ProTouch ICON, all…
ModificadaMedia (5.5)3.9%💥 ExploitSurina Soundtouch27/7/201717/6/2026
The TDStretchSSE::calcCrossCorr function in source/SoundTouch/sse_optimized.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (heap-based buffer over-read and application crash) via a crafted wav file.
ModificadaMedia (5.5)6.1%💥 ExploitSurina Soundtouch27/7/201717/6/2026
The TDStretch::acceptNewOverlapLength function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (memory allocation error and application crash) via a crafted wav file.
ModificadaMedia (5.5)4.2%💥 ExploitSurina Soundtouch27/7/201717/6/2026
The TDStretch::processSamples function in source/SoundTouch/TDStretch.cpp in SoundTouch 1.9.2 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted wav file.
ModificadaCrítica (9.1)2.0%—Bose Soundtouch 301/5/201717/6/2026
The Multicast DNS (mDNS) responder used in BOSE Soundtouch 30 inadvertently responds to IPv4 unicast queries with source addresses that are not link-local, which allows remote attackers to cause a denial of service (traffic amplification) or obtain potentially sensitive information via port-5353 UDP packets.
ModificadaMedia (5.3)0.55%—Aveva Wonderware Intouch Access Anywhere20/4/201717/6/2026
An Inadequate Encryption Strength issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The software will connect via Transport Layer Security without verifying the peer's SSL certificate properly.
ModificadaCrítica (9.8)2.4%—Aveva Wonderware Intouch Access Anywhere20/4/201717/6/2026
An Information Exposure issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. Credentials may be exposed to external systems via specific URL parameters, as arbitrary destination addresses may be specified.
ModificadaAlta (8.8)0.96%—Aveva Wonderware Intouch Access Anywhere20/4/201717/6/2026
A Cross-Site Request Forgery issue was discovered in Schneider Electric Wonderware InTouch Access Anywhere, version 11.5.2 and prior. The client request may be forged from a different site. This will allow an external site to access internal RDP systems on behalf of the currently logged in user.
ModificadaMedia (5.9)1.6%—ApparmorCanonical Ubuntu CoreCanonical Ubuntu Touch24/3/201717/6/2026
An issue was discovered in AppArmor before 2.12. Incorrect handling of unknown AppArmor profiles in AppArmor init scripts, upstart jobs, and/or systemd unit files allows an attacker to possibly have increased attack surfaces of processes that were intended to be confined by AppArmor. This is due to the common logic to…
ModificadaAlta (7.5)2.2%—Schneider-electric Magelis GTU Universal Panel FirmwareSchneider-electric Magelis GTO Advanced Optimum Panel FirmwareSchneider-electric Magelis Sto5 Small Panel FirmwareSchneider-electric Magelis STU Small Panel Firmware+413/2/201717/6/2026
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard,…
ModificadaMedia (5.3)4.3%💥 PoCSchneider-electric Magelis GTU Universal Panel FirmwareSchneider-electric Magelis GTO Advanced Optimum Panel FirmwareSchneider-electric Magelis Sto5 Small Panel FirmwareSchneider-electric Magelis STU Small Panel Firmware+413/2/201717/6/2026
An issue was discovered in Schneider Electric Magelis HMI Magelis GTO Advanced Optimum Panels, all versions, Magelis GTU Universal Panel, all versions, Magelis STO5xx and STU Small panels, all versions, Magelis XBT GH Advanced Hand-held Panels, all versions, Magelis XBT GK Advanced Touchscreen Panels with Keyboard,…
ModificadaAlta (8.8)27%💥 ExploitCisco Activetouch General Plugin ContainerCisco Download ManagerCisco Gpccontainer ClassCisco Webex+21/2/201717/6/2026
An issue was discovered in the Cisco WebEx Extension before 1.0.7 on Google Chrome, the ActiveTouch General Plugin Container before 106 on Mozilla Firefox, the GpcContainer Class ActiveX control plugin before 10031.6.2017.0126 on Internet Explorer, and the Download Manager ActiveX control plugin before 2.1.0.10 on…
ModificadaMedia (4.4)0.30%—Lenovo BiosLenovo Notebook 110 14ibr BiosLenovo Notebook 110 15ibr BiosLenovo Notebook B70 80 Bios+2529/11/201617/6/2026
A vulnerability has been identified in some Lenovo Notebook and ThinkServer systems where an attacker with administrative privileges on a system could install a program that circumvents Intel Management Engine (ME) protections. This could result in a denial of service or privilege escalation attack on the system.
ModificadaCrítica (9.8)4.5%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices mishandle acknowledgements, which makes it easier for remote attackers to bypass authentication via a custom communication protocol.
ModificadaCrítica (9.8)4.5%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices allow remote attackers to bypass authentication via replay attacks.
ModificadaAlta (7.5)3.9%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices do not properly generate random numbers, which makes it easier for remote attackers to spoof meters by sniffing the network and then engaging in an authentication handshake.
ModificadaAlta (7.5)2.2%—Animas Onetouch Ping Firmware5/10/201617/6/2026
Johnson & Johnson Animas OneTouch Ping devices do not use encryption for certain data, which might allow remote attackers to obtain sensitive information by sniffing the network.