Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.56% | — | Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere | 26/9/2017 | 17/6/2026 | A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components. | |
| Modificada | Alta (8.8) | 0.63% | — | Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere | 26/9/2017 | 17/6/2026 | A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social… | |
| Modificada | Crítica (9.8) | 2.6% | — | Spidercontrol Scada Microbrowser | 25/8/2017 | 17/6/2026 | A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow. | |
| Modificada | Alta (7.5) | 3.8% | — | Spidercontrol Scada WEB Server | 25/8/2017 | 17/6/2026 | A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files. | |
| Modificada | Alta (7) | 1.4% | — | Simplight Scada | 14/8/2017 | 17/6/2026 | An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to place a malicious DLL file within the search path resulting in execution of arbitrary code. | |
| Modificada | Media (6.1) | 0.83% | — | Trihedral Vtscada | 21/6/2017 | 17/6/2026 | A Cross-Site Scripting issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A cross-site scripting vulnerability may allow JavaScript code supplied by the attacker to execute within the user's browser. | |
| Modificada | Alta (7.5) | 1.7% | — | Trihedral Vtscada | 21/6/2017 | 17/6/2026 | An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain sensitive configuration information. | |
| Modificada | Alta (7.5) | 1.7% | — | Trihedral Vtscada | 21/6/2017 | 17/6/2026 | A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that are utilized by an attacker, which can be used to consume more resources than are available. | |
| Modificada | Alta (7.3) | 0.32% | — | Leao Consultoria E Desenvolvimento DE Sistemas Ltda ME Laquis Scada | 19/5/2017 | 17/6/2026 | An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA. The following versions are affected: Versions 4.1 and prior versions released before January 20, 2017. An Improper Access Control vulnerability has been identified, which may allow an… | |
| Modificada | Alta (8.8) | 2.8% | — | Certec EDV Gmbh Atvise Scada | 6/5/2017 | 17/6/2026 | A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripting syntax" issue has been identified, which may allow remote code execution. | |
| Modificada | Media (5.4) | 1.0% | — | Certec EDV Gmbh Atvise Scada | 6/5/2017 | 17/6/2026 | A Cross-Site Scripting issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. This may allow remote code execution. | |
| Modificada | Alta (7.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 7/4/2017 | 17/6/2026 | A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path. | |
| Modificada | Alta (7.5) | 3.6% | — | Indasengineering WEB Scada | 5/10/2016 | 17/6/2026 | Directory traversal vulnerability in INDAS Web SCADA before 3 allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Crítica (9.1) | 28% | — | Trihedral Vtscada | 9/6/2016 | 17/6/2026 | Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname. | |
| Analizada | Alta (7.5) | 31% | ⚠ Explotación activa | Trihedral Vtscada | 9/6/2016 | 17/6/2026 | The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors. | |
| Modificada | Crítica (9.1) | 20% | — | Trihedral Vtscada | 9/6/2016 | 17/6/2026 | The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitrary files via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.35% | — | Ininet Solutions Scada WEB Server | 25/10/2015 | 17/6/2026 | IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors. | |
| Modificada | Media (5) | 2.1% | — | Ininet Solutions Scada WEB Server | 25/10/2015 | 17/6/2026 | Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname. | |
| Modificada | Media (6.4) | 1.4% | — | Ininet Solutions Scada WEB Server | 25/10/2015 | 17/6/2026 | IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string. | |
| Modificada | Alta (10) | 4.1% | — | Ininet Solutions Scada WEB Server | 25/10/2015 | 17/6/2026 | Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request. | |
| Modificada | Media (6.1) | 12% | 💥 Exploit | Nordex Control 2 Scada | 18/10/2015 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.6% | — | Scadaengine Bacnet OPC Server | 14/3/2015 | 17/6/2026 | The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbitrary database fields via unspecified vectors. | |
| Modificada | Alta (9) | 3.6% | — | Scadaengine Bacnet OPC Server | 14/3/2015 | 17/6/2026 | Format string vulnerability in BACnOPCServer.exe in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via format string specifiers in a request. | |
| Modificada | Alta (9) | 4.6% | — | Scadaengine Bacnet OPC Server | 14/3/2015 | 17/6/2026 | Heap-based buffer overflow in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Media (6.9) | 0.65% | — | Intelligent Platforms Proficy Hmi/scada Cimplicity | 17/1/2015 | 17/6/2026 | The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file. |