Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
413 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 2.0% | — | Schneider-electric Etg3000 Factorycast HMI Gateway FirmwareSchneider-electric Tsxetg3000Schneider-electric Tsxetg3010Schneider-electric Tsxetg3021+1 | 27/1/2015 | 17/6/2026 | The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request. | |
| Modificada | Media (4.3) | 1.4% | — | IBM WEB Experience Factory | 26/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal… | |
| Modificada | Media (5.4) | 0.27% | — | Communityfactory Selfie Camera -facial Beauty- | 9/9/2014 | 17/6/2026 | The Selfie Camera -Facial Beauty- (aka com.cfinc.cunpic) application 1.2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (7.8) | 2.5% | — | Schneider-electric OPC Factory Server TlxcdlfofsSchneider-electric OPC Factory Server TlxcdltofsSchneider-electric OPC Factory Server TlxcdluofsSchneider-electric OPC Factory Server Tlxcdstofs+1 | 4/4/2014 | 17/6/2026 | Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a… | |
| Modificada | Alta (9.3) | 22% | 💥 Exploit | Schneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+9 | 1/4/2014 | 16/6/2026 | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header. | |
| Modificada | Media (6.9) | 0.47% | — | Schneider-electric OFS Test Client Tlxcdlfofs33Schneider-electric OFS Test Client Tlxcdltofs33Schneider-electric OFS Test Client Tlxcdluofs33Schneider-electric OFS Test Client Tlxcdstofs33+2 | 28/2/2014 | 17/6/2026 | Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file. | |
| Modificada | Alta (7.5) | 2.3% | 💥 Exploit | Cubicfactory Cubic CMS | 21/1/2014 | 17/6/2026 | Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQL commands via the (1) resource_id or (2) version_id parameter to recursos/agent.php or (3) login or (4) pass parameter to login.usuario. | |
| Modificada | Alta (7.8) | 3.2% | — | Rockwellautomation Factorytalk Services Platform | 18/4/2013 | 16/6/2026 | Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a… | |
| Modificada | Alta (7.8) | 3.2% | — | Rockwellautomation Factorytalk Services Platform | 18/4/2013 | 16/6/2026 | Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that… | |
| Modificada | Media (6) | 1.1% | — | Widgetfactorylimited COM JCE | 30/8/2012 | 16/6/2026 | Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details… | |
| Modificada | Media (5) | 3.5% | — | Rockwellautomation FactorytalkRockwellautomation Rslogix 5000 | 2/4/2012 | 16/6/2026 | The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet. | |
| Modificada | Media (5) | 10% | 💥 Exploit | Rockwellautomation FactorytalkRockwellautomation Rslogix 5000 | 2/4/2012 | 16/6/2026 | The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet. | |
| Modificada | Media (5.8) | 1.0% | — | Siemens Tecnomatix Factorylink | 8/1/2012 | 16/6/2026 | An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to create or overwrite arbitrary files via the save method. | |
| Modificada | Alta (9.3) | 4.6% | — | Siemens Tecnomatix Factorylink | 8/1/2012 | 16/6/2026 | Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL. | |
| Modificada | Media (4.3) | 1.2% | — | IBM WEB Experience Factory | 3/1/2012 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in IBM Web Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0 and 7.0.1 allow remote attackers to inject arbitrary web script or HTML via a (1) text INPUT element or (2) TEXTAREA element, related to an interaction between Smart Refresh and Dojo. | |
| Modificada | Alta (7.2) | 1.3% | — | Schneider-electric Monitor PROSchneider-electric OPC Factory ServerSchneider-electric PL7 PROSchneider-electric Telemecanique Driver Pack+2 | 4/11/2011 | 16/6/2026 | Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers,… | |
| Modificada | Alta (10) | 71% | 💥 Exploit | Azeotech Daqfactory | 16/9/2011 | 16/6/2026 | Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted NETB packet to UDP port 20034. | |
| Modificada | Media (6.9) | 0.64% | — | Rockwellautomation Factorytalk Diagnostics Viewer | 28/7/2011 | 16/6/2026 | Unspecified vulnerability in Rockwell Automation FactoryTalk Diagnostics Viewer before V2.30.00 (CPR9 SR3) allows local users to execute arbitrary code via a crafted FactoryTalk Diagnostics Viewer (.ftd) configuration file, which triggers memory corruption. | |
| Modificada | Alta (7.8) | 6.7% | 💥 Exploit | Azeotech Daqfactory | 28/7/2011 | 16/6/2026 | AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal. | |
| Modificada | Alta (9.3) | 42% | 💥 Exploit | Tomsawyer GET Extension FactoryVmware Virtual Infrastructure ClientVmware Infrastructure | 6/6/2011 | 16/6/2026 | Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within… | |
| Modificada | Media (6.9) | 0.34% | — | Novell Opensuse Factory | 30/3/2011 | 16/6/2026 | SUSE openSUSE Factory assigns ownership of the /var/log/cobbler/ directory tree to the web-service user account, which might allow local users to gain privileges by leveraging access to this account during root filesystem operations by the Cobbler daemon. | |
| Modificada | Alta (7.5) | 15% | 💥 Exploit | Thefactory COM Lovefactory | 19/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Love Factory (com_lovefactory) component 1.3.4 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 17% | 💥 Exploit | Thefactory COM Gadgetfactory | 19/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Gadget Factory (com_gadgetfactory) component 1.0.0 and 1.5.0 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. NOTE: some of these details are obtained from third party information. | |
| Modificada | Alta (7.5) | 18% | 💥 Exploit | Thefactory COM Blogfactory | 19/5/2010 | 16/6/2026 | Directory traversal vulnerability in the Deluxe Blog Factory (com_blogfactory) component 1.1.2 for Joomla! allows remote attackers to read arbitrary files via a .. (dot dot) in the controller parameter to index.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Thefactory COM Mediamall | 29/4/2010 | 16/6/2026 | SQL injection vulnerability in the Media Mall Factory (com_mediamall) component 1.0.4 for Joomla! allows remote attackers to execute arbitrary SQL commands via the category parameter to index.php. |