Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.51% | — | Rockwellautomation Power Monitor 1000AI | 18/12/2024 | 17/6/2026 | A denial-of-service vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in a buffer-overflow, potentially causing denial-of-service. | |
| Aplazada | Crítica (9.3) | 0.86% | — | Rockwellautomation Power Monitor 1000AI | 18/12/2024 | 17/6/2026 | A denial-of-service and possible remote code execution vulnerability exists in the Rockwell Automation Power Monitor 1000. The vulnerability results in corruption of the heap memory which may compromise the integrity of the system, potentially allowing for remote code execution or a denial-of-service attack. | |
| Aplazada | Crítica (9.3) | 0.55% | — | Rockwellautomation Power Monitor 1000AI | 18/12/2024 | 17/6/2026 | A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset. | |
| Aplazada | Alta (7.3) | 0.23% | — | CA Client AutomationAICA ItcmAI | 17/12/2024 | 17/6/2026 | CA Client Automation (ITCM) allows non-admin/non-root users to encrypt a string using CAF CLI and SD_ACMD CLI. This would allow the non admin user to access the critical encryption keys which further causes the exploitation of stored credentials. This fix doesn't allow a non-admin/non-root user to execute "caf… | |
| Aplazada | Crítica (9.3) | 1.5% | — | Siemens Opcenter Execution FoundationAISiemens Opcenter IntelligenceAISiemens Opcenter QualityAISiemens Opcenter RdnlAI+3 | 16/12/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Execution Foundation (All versions < V2501.0001), Opcenter Intelligence (All versions < V2501.0001), Opcenter Quality (All versions < V2512), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 3),… | |
| Aplazada | Alta (8.5) | 0.19% | — | Hornerautomation CscapeAI | 13/12/2024 | 17/6/2026 | Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code. | |
| Analizada | Alta (7.8) | 0.21% | — | Ivanti Automation | 11/12/2024 | 17/6/2026 | Under specific circumstances, insecure permissions in Ivanti Automation before version 2024.4.0.1 allows a local authenticated attacker to achieve local privilege escalation. | |
| Aplazada | Media (5.3) | 0.53% | — | Tungstenautomation TotalagilityAI | 6/12/2024 | 17/6/2026 | Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpScreenResolutionWidth parameter manipulation in a form sent to an endpoint /TotalAgility/Kofax/BrowserDevice/ScanFront.aspx This allows for injection of a malicious JavaScript code,… | |
| Aplazada | Media (5.3) | 0.53% | — | Kofax TotalagilityAITungstenautomation TotalagilityAI | 6/12/2024 | 17/6/2026 | Tungsten Automation (Kofax) TotalAgility in versions all through 7.9.0.25.0.954 is vulnerable to a Reflected XSS attacks through mfpConnectionId parameter manipulation in a form sent to endpoints "/TotalAgility/Kofax/BrowserDevice/ScanFront.aspx" and "/TotalAgility/Kofax/BrowserDevice/ScanFrontDebug.aspx" This allows… | |
| Analizada | Alta (8.5) | 0.15% | — | Openautomationsoftware Open Automation Software | 6/12/2024 | 17/6/2026 | A local low-level user on the server machine with credentials to the running OAS services can create and execute a report with an rdlx file on the server system itself. Any code within the rdlx file of the report executes with SYSTEM privileges, resulting in privilege escalation. | |
| Analizada | Alta (8.5) | 0.30% | — | Rockwellautomation Arena | 5/12/2024 | 17/6/2026 | An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To… | |
| Analizada | Alta (8.5) | 0.23% | — | Rockwellautomation Arena | 5/12/2024 | 17/6/2026 | An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To… | |
| Analizada | Alta (8.5) | 0.24% | — | Rockwellautomation Arena | 5/12/2024 | 17/6/2026 | An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a… | |
| Analizada | Alta (8.5) | 0.23% | — | Rockwellautomation Arena | 5/12/2024 | 17/6/2026 | A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this… | |
| Aplazada | Alta (7.1) | 0.17% | — | Docxpresso Document Data AutomationAI | 2/12/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in docxpresso Document & Data Automation document-data-automation allows Stored XSS.This issue affects Document & Data Automation: from n/a through <= 1.6.1. | |
| Aplazada | Crítica (9.8) | 1.9% | 💥 PoC | Information Technology Wawp Automation WEB PlatformAI | 28/11/2024 | 17/6/2026 | Authentication Bypass Using an Alternate Path or Channel vulnerability in Information Technology Wawp automation-web-platform allows Authentication Bypass.This issue affects Wawp: from n/a through < 3.0.18. | |
| Aplazada | Media (5) | 0.53% | — | Ansible Automation PlatformAI | 25/11/2024 | 17/6/2026 | A vulnerability was found in the Ansible Automation Platform (AAP). This flaw allows attackers to escalate privileges by improperly leveraging read-scoped OAuth2 tokens to gain write access. This issue affects API endpoints that rely on ansible_base.oauth2_provider for OAuth2 authentication. While the impact is… | |
| Analizada | Alta (7.8) | 0.31% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF PDF File Parsing Use-After-Free Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Baja (3.3) | 0.25% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Baja (3.3) | 0.25% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF OXPS File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Baja (3.3) | 0.25% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF PDF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Baja (3.3) | 0.25% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF PNG File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Baja (3.3) | 0.25% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF GIF File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target… | |
| Analizada | Media (4.3) | 0.54% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the… | |
| Analizada | Baja (3.3) | 0.25% | — | Tungstenautomation Power PDF | 22/11/2024 | 17/6/2026 | Tungsten Automation Power PDF JP2 File Parsing Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Tungsten Automation Power PDF. User interaction is required to exploit this vulnerability in that the target… |