Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2741▼ 480 respecto a la semana anterior
Críticas / altas1308▼ 182 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

435 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.56%—Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere26/9/201717/6/2026
A vulnerability exists in Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 that allows the ability to specify Arbitrary Server Target Nodes in connection requests to the Secure Gateway and Server components.
ModificadaAlta (8.8)0.63%—Schneider-electric Powerscada AnywhereSchneider-electric Citect Anywhere26/9/201717/6/2026
A cross-site request forgery vulnerability exists on the Secure Gateway component of Schneider Electric's PowerSCADA Anywhere v1.0 redistributed with PowerSCADA Expert v8.1 and PowerSCADA Expert v8.2 and Citect Anywhere version 1.0 for multiple state-changing requests. This type of attack requires some level of social…
ModificadaCrítica (9.8)2.6%—Spidercontrol Scada Microbrowser25/8/201717/6/2026
A Stack-based Buffer Overflow issue was discovered in SpiderControl SCADA MicroBrowser Versions 1.6.30.144 and prior. Opening a maliciously crafted html file may cause a stack overflow.
ModificadaAlta (7.5)3.8%—Spidercontrol Scada WEB Server25/8/201717/6/2026
A Directory Traversal issue was discovered in SpiderControl SCADA Web Server. An attacker may be able to use a simple GET request to perform a directory traversal into system files.
ModificadaAlta (7)1.4%—Simplight Scada14/8/201717/6/2026
An Uncontrolled Search Path Element issue was discovered in SIMPlight SCADA Software version 4.3.0.27 and prior. The uncontrolled search path element vulnerability has been identified, which may allow an attacker to place a malicious DLL file within the search path resulting in execution of arbitrary code.
ModificadaMedia (6.1)0.83%—Trihedral Vtscada21/6/201717/6/2026
A Cross-Site Scripting issue was discovered in Trihedral VTScada Versions prior to 11.2.26. A cross-site scripting vulnerability may allow JavaScript code supplied by the attacker to execute within the user's browser.
ModificadaAlta (7.5)1.7%—Trihedral Vtscada21/6/201717/6/2026
An Information Exposure issue was discovered in Trihedral VTScada Versions prior to 11.2.26. Some files are exposed within the web server application to unauthenticated users. These files may contain sensitive configuration information.
ModificadaAlta (7.5)1.7%—Trihedral Vtscada21/6/201717/6/2026
A Resource Consumption issue was discovered in Trihedral VTScada Versions prior to 11.2.26. The client does not properly validate the input or limit the amount of resources that are utilized by an attacker, which can be used to consume more resources than are available.
ModificadaAlta (7.3)0.32%—Leao Consultoria E Desenvolvimento DE Sistemas Ltda ME Laquis Scada19/5/201717/6/2026
An Improper Access Control issue was discovered in LCDS - Leao Consultoria e Desenvolvimento de Sistemas LTDA ME LAquis SCADA. The following versions are affected: Versions 4.1 and prior versions released before January 20, 2017. An Improper Access Control vulnerability has been identified, which may allow an…
ModificadaAlta (8.8)2.8%—Certec EDV Gmbh Atvise Scada6/5/201717/6/2026
A Header Injection issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. An "improper neutralization of HTTP headers for scripting syntax" issue has been identified, which may allow remote code execution.
ModificadaMedia (5.4)1.0%—Certec EDV Gmbh Atvise Scada6/5/201717/6/2026
A Cross-Site Scripting issue was discovered in Certec EDV GmbH atvise scada prior to Version 3.0. This may allow remote code execution.
ModificadaAlta (7.8)1.3%—Schneider-electric Interactive Graphical Scada System7/4/201717/6/2026
A DLL Hijacking issue was discovered in Schneider Electric Interactive Graphical SCADA System (IGSS) Software, Version 12 and previous versions. The software will execute a malicious file if it is named the same as a legitimate file and placed in a location that is earlier in the search path.
ModificadaAlta (7.5)3.6%—Indasengineering WEB Scada5/10/201617/6/2026
Directory traversal vulnerability in INDAS Web SCADA before 3 allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaCrítica (9.1)28%—Trihedral Vtscada9/6/201617/6/2026
Directory traversal vulnerability in the WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to read arbitrary files via a crafted pathname.
AnalizadaAlta (7.5)31%⚠ Explotación activaTrihedral Vtscada9/6/201617/6/2026
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to cause a denial of service (out-of-bounds read and application crash) via unspecified vectors.
ModificadaCrítica (9.1)20%—Trihedral Vtscada9/6/201617/6/2026
The WAP interface in Trihedral VTScada (formerly VTS) 8.x through 11.x before 11.2.02 allows remote attackers to bypass authentication and read arbitrary files via unspecified vectors.
ModificadaBaja (2.1)0.35%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
IniNet embeddedWebServer (aka eWebServer) before 2.02 for Windows CE uses cleartext for password storage, which allows context-dependent attackers to obtain sensitive information via unspecified vectors.
ModificadaMedia (5)2.1%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
Directory traversal vulnerability in IniNet embeddedWebServer (aka eWebServer) before 2.02 allows remote attackers to read arbitrary files via a crafted pathname.
ModificadaMedia (6.4)1.4%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
IniNet embeddedWebServer (aka eWebServer) before 2.02 mishandles URL encoding, which allows remote attackers to write to or delete files via a crafted string.
ModificadaAlta (10)4.1%—Ininet Solutions Scada WEB Server25/10/201517/6/2026
Multiple stack-based buffer overflows in IniNet embeddedWebServer (aka eWebServer) before 2.02 allow remote attackers to execute arbitrary code via a long field in an HTTP request.
ModificadaMedia (6.1)12%💥 ExploitNordex Control 2 Scada18/10/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the Wind Farm Portal application in Nordex Control 2 (NC2) SCADA 16 and earlier allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)2.6%—Scadaengine Bacnet OPC Server14/3/201517/6/2026
The SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to bypass authentication and read or write to arbitrary database fields via unspecified vectors.
ModificadaAlta (9)3.6%—Scadaengine Bacnet OPC Server14/3/201517/6/2026
Format string vulnerability in BACnOPCServer.exe in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via format string specifiers in a request.
ModificadaAlta (9)4.6%—Scadaengine Bacnet OPC Server14/3/201517/6/2026
Heap-based buffer overflow in the SOAP web interface in SCADA Engine BACnet OPC Server before 2.1.371.24 allows remote attackers to execute arbitrary code via a crafted packet.
ModificadaMedia (6.9)0.65%—Intelligent Platforms Proficy Hmi/scada Cimplicity17/1/201517/6/2026
The (1) CimView and (2) CimEdit components in GE Proficy HMI/SCADA-CIMPLICITY 8.2 and earlier allow remote attackers to gain privileges via a crafted CIMPLICITY screen (aka .CIM) file.