Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 501 respecto a la semana anterior
Críticas / altas1301▼ 201 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 277 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.9% | — | Trihedral Vtscada | 11/12/2014 | 17/6/2026 | Integer overflow in Trihedral Engineering VTScada (formerly VTS) 6.5 through 9.x before 9.1.20, 10.x before 10.2.22, and 11.x before 11.1.07 allows remote attackers to cause a denial of service (server crash) via a crafted request, which triggers a large memory allocation. | |
| Modificada | Media (5) | 1.4% | — | Elipse ScadaElipse PowerElipse E3 | 6/12/2014 | 17/6/2026 | DNP Master Driver 3.02 and earlier in Elipse SCADA 2.29 build 141 and earlier, E3 1.0 through 4.6, and Elipse Power 1.0 through 4.6 allows remote attackers to cause a denial of service (CPU consumption) via malformed packets. | |
| Modificada | Media (4.3) | 1.7% | — | Nordex Control 2 Scada | 5/11/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the login script in the Wind Farm Portal on Nordex Control 2 (NC2) SCADA devices 15 and earlier allows remote attackers to inject arbitrary web script or HTML via the username parameter. | |
| Modificada | Media (5) | 1.0% | — | Aveva ClearscadaSchneider-electric Scada Expert Clearscada | 18/9/2014 | 17/6/2026 | Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 uses the MD5 algorithm for an X.509 certificate, which makes it easier for remote attackers to spoof servers via a cryptographic attack against this algorithm. | |
| Modificada | Media (5) | 1.6% | — | Aveva ClearscadaSchneider-electric Scada Expert Clearscada | 18/9/2014 | 17/6/2026 | Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allows remote attackers to read database records by leveraging access to the guest account. | |
| Modificada | Baja (3.5) | 1.3% | — | Aveva ClearscadaSchneider-electric Scada Expert Clearscada | 18/9/2014 | 17/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R3 through 2014 R1 allow remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.35% | — | Trianglemicroworks Scada Data Gateway | 30/5/2014 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows physically proximate attackers to cause a denial of service (excessive data processing) via a crafted DNP request over a serial line. | |
| Modificada | Media (5) | 1.8% | — | Trianglemicroworks Scada Data Gateway | 30/5/2014 | 17/6/2026 | Triangle MicroWorks SCADA Data Gateway before 3.00.0635 allows remote attackers to cause a denial of service (excessive data processing) via a crafted DNP3 packet. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Wellintech Kingscada | 12/4/2014 | 17/6/2026 | Stack-based buffer overflow in WellinTech KingSCADA before 3.1.2.13 allows remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Media (6.8) | 1.5% | — | Aveva Clearscada | 14/3/2014 | 17/6/2026 | The PLC driver in ServerMain.exe in the Kepware KepServerEX 4 component in Schneider Electric StruxureWare SCADA Expert ClearSCADA 2010 R2 build 71.4165, 2010 R2.1 build 71.4325, 2010 R3 build 72.4560, 2010 R3.1 build 72.4644, 2013 R1 build 73.4729, 2013 R1.1 build 73.4832, 2013 R1.1a build 73.4903, 2013 R1.2 build… | |
| Modificada | Alta (7.8) | 1.8% | — | Schneider-electric CitectscadaSchneider-electric Powerlogic ScadaSchneider-electric Struxureware Powerscada ExpertSchneider-electric Struxureware Scada Expert Vijeo Citect | 26/2/2014 | 16/6/2026 | Schneider Electric StruxureWare SCADA Expert Vijeo Citect 7.40, Vijeo Citect 7.20 through 7.30SP1, CitectSCADA 7.20 through 7.30SP1, StruxureWare PowerSCADA Expert 7.30 through 7.30SR1, and PowerLogic SCADA 7.20 through 7.20SR1 do not properly handle exceptions, which allows remote attackers to cause a denial of… | |
| Modificada | Alta (7.1) | 1.3% | — | Matrikonopc Scada Dnp3 OPC Server | 14/2/2014 | 16/6/2026 | MatrikonOPC SCADA DNP3 OPC Server 1.2.2.0 and earlier allows remote attackers to cause a denial of service (infinite loop) via a malformed DNP3 packet. | |
| Modificada | Alta (7.5) | 3.1% | — | Intelligent Platforms Proficy Hmi%2fscada CimplicityIntelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With Cimplicity | 25/1/2014 | 17/6/2026 | The CIMPLICITY Web-based access component, CimWebServer, does not check the location of shell files being loaded into the system. By modifying the source location, an attacker could send shell code to the CimWebServer which would deploy the nefarious files as part of any SCADA project. This could allow the attacker to… | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Intelligent Platforms Proficy Hmi%2fscada CimplicityIntelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With Cimplicity | 25/1/2014 | 17/6/2026 | Directory traversal vulnerability in gefebt.exe in the WebView CimWeb components in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY through 8.2 SIM 24, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary code via a crafted HTTP request, aka ZDI-CAN-1622. | |
| Modificada | Media (4.3) | 1.2% | — | Aveva Clearscada | 15/1/2014 | 17/6/2026 | DNP3Driver.exe in the DNP3 driver in Schneider Electric ClearSCADA 2010 R2 through 2010 R3.1 and SCADA Expert ClearSCADA 2013 R1 through 2013 R1.2 allows remote attackers to cause a denial of service (resource consumption) via IP packets containing errors that trigger event-journal messages. | |
| Modificada | Alta (7.5) | 48% | 💥 Exploit | Wellintech Kingalarm&eventWellintech KinggraphicWellintech Kingscada | 15/1/2014 | 16/6/2026 | An unspecified ActiveX control in WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 allows remote attackers to download arbitrary DLL code onto a client machine and execute this code via the ProjectURL property value. | |
| Modificada | Media (6.4) | 1.8% | — | Wellintech Kingalarm&eventWellintech KinggraphicWellintech Kingscada | 15/1/2014 | 16/6/2026 | WellinTech KingSCADA before 3.1.2, KingAlarm&Event before 3.1, and KingGraphic before 3.1.2 perform authentication on the KAEClientManager console rather than on the server, which allows remote attackers to bypass intended access restrictions and discover credentials via a crafted packet to TCP port 8130. | |
| Modificada | Media (4.7) | 0.76% | — | Catapultsoftware Catapult Dnp3 I/O DriverIntelligent Platforms Proficy Dnp3 I/O DriverIntelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Hmi/scada Ifix | 22/11/2013 | 16/6/2026 | The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow physically proximate attackers to cause a denial of service… | |
| Modificada | Alta (7.1) | 1.8% | — | Catapultsoftware Catapult Dnp3 I/O DriverIntelligent Platforms Proficy Dnp3 I/O DriverIntelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Hmi/scada Ifix | 22/11/2013 | 16/6/2026 | The (1) Catapult DNP3 I/O driver before 7.2.0.60 and the (2) GE Intelligent Platforms Proficy DNP3 I/O driver before 7.20k, as used in DNPDrv.exe (aka the DNP master station server) in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY and iFIX, allow remote attackers to cause a denial of service (infinite loop)… | |
| Modificada | Media (4.9) | 0.32% | — | Trianglemicroworks Ansi C Source Code LibrariesTrianglemicroworks .net Communication Protocol ComponentsTrianglemicroworks Scada Data Gateway | 9/9/2013 | 16/6/2026 | Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow physically proximate attackers to cause a denial of service (infinite loop) via crafted input over a serial line. | |
| Modificada | Alta (7.8) | 1.5% | — | Trianglemicroworks .net Communication Protocol ComponentsTrianglemicroworks Ansi C Source Code LibrariesTrianglemicroworks Scada Data Gateway | 9/9/2013 | 16/6/2026 | Triangle MicroWorks SCADA Data Gateway 2.50.0309 through 3.00.0616, DNP3 .NET Protocol components 3.06.0.171 through 3.15.0.369, and DNP3 C libraries 3.06.0000 through 3.15.0000 allow remote attackers to cause a denial of service (infinite loop) via a crafted DNP3 TCP packet. | |
| Modificada | Alta (7.1) | 1.3% | — | Matrikonopc Scada Dnp3 OPC Server | 9/9/2013 | 16/6/2026 | MatrikonOPC SCADA DNP3 OPC Server 1.2.0 allows remote attackers to cause a denial of service (master-station daemon crash) via a malformed DNP3 TCP packet from the IP address of an outstation. | |
| Modificada | Media (6.9) | 0.73% | — | Schneider-electric CitectscadaSchneider-electric Powerlogic ScadaSchneider-electric Vijeo Citect | 9/8/2013 | 16/6/2026 | Schneider Electric Vijeo Citect 7.20 and earlier, CitectSCADA 7.20 and earlier, and PowerLogic SCADA 7.20 and earlier allow remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity… | |
| Modificada | Alta (9.3) | 3.8% | — | Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With Cimplicity | 31/7/2013 | 16/6/2026 | Multiple buffer overflows in CimWebServer.exe in the WebView component in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY before 8.0 SIM 27, 8.1 before SIM 25, and 8.2 before SIM 19, and Proficy Process Systems with CIMPLICITY, allow remote attackers to execute arbitrary code via crafted data in packets to TCP… | |
| Modificada | Alta (10) | 11% | 💥 Exploit | Mitsubishi-automation Mitsubishi MX ComponentSchneider-electric CitectfacilitiesSchneider-electric Citectscada | 19/4/2013 | 16/6/2026 | Multiple buffer overflows in ActUWzd.dll 1.0.0.1 in Mitsubishi MX Component 3, as distributed in Citect CitectFacilities 7.10 and CitectScada 7.10r1, allow remote attackers to execute arbitrary code via a long string, as demonstrated by a long WzTitle property value to a certain ActiveX control. |