Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

435 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (9.3)3.1%—Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With CimplicityIntelligent Platforms Proficy Process Systems27/1/201316/6/2026
CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet.
ModificadaMedia (4.3)19%—Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With CimplicityIntelligent Platforms Proficy Process Systems27/1/201316/6/2026
Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet.
ModificadaAlta (10)21%💥 ExploitSchneider-electric Interactive Graphical Scada System21/1/201316/6/2026
Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol.
ModificadaMedia (4.3)1.2%—Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With CimplicityIntelligent Platforms Proficy Process Systems17/1/201316/6/2026
Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request.
ModificadaAlta (7.8)2.2%—C3-ilex Eoscada13/11/201216/6/2026
eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 12000.
ModificadaMedia (5)1.7%—C3-ilex Eoscada13/11/201216/6/2026
eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP port 12000.
ModificadaAlta (7.8)2.2%—C3-ilex Eoscada13/11/201216/6/2026
EOSDataServer.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 24006.
ModificadaMedia (5)1.9%—C3-ilex Eoscada13/11/201216/6/2026
EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP port (1) 5050 or (2) 24004.
ModificadaAlta (7.8)2.6%—Fultek Wintr Scada25/9/201216/6/2026
Directory traversal vulnerability in the web server in Fultek WinTr Scada 4.0.5 and earlier allows remote attackers to read arbitrary files via a crafted request.
ModificadaMedia (4.6)0.47%—Mitsubishi-automation MX4 ScadaSchneider-electric Citectscada15/9/201216/6/2026
Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric CitectSCADA before 7.20 and Mitsubishi MX4 SCADA before 7.20 allows local users to execute arbitrary code via a long string in a login sequence.
ModificadaMedia (6.9)0.45%—Invensys Foxboro Control SoftwareInvensys Infusion Ce/fe/scadaInvensys IntouchInvensys Intouch/wonderware Application Server+326/7/201216/6/2026
Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified…
ModificadaAlta (9.3)40%💥 ExploitIntelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy HistorianIntelligent Platforms Proficy Hmi/scada IfixIntelligent Platforms Proficy Pulse+15/7/201216/6/2026
An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows…
ModificadaAlta (9.3)28%💥 ExploitEMC Captiva Quickscan PROEMC Documentum Applicationxtender DesktopIntelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy Historian+35/7/201216/6/2026
Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5;…
ModificadaAlta (7.2)0.48%—Measuresoft Scadapro ClientMeasuresoft Scadapro Server25/5/201216/6/2026
Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory.
ModificadaMedia (6.8)27%💥 ExploitCraig Peterson Turbopower AbbreviaScadatec ModbustagserverScadatec Scadaphone3/4/201216/6/2026
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.
ModificadaMedia (6.8)3.2%—Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+42/4/201216/6/2026
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit…
ModificadaMedia (6.8)3.2%—Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+42/4/201216/6/2026
Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit…
ModificadaMedia (5)1.7%—Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports2/12/201116/6/2026
Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors.
ModificadaMedia (4.3)2.0%—Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports2/12/201116/6/2026
Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (9.3)13%💥 ExploitSchneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports2/12/201116/6/2026
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors.
ModificadaMedia (4.3)1.5%—Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports2/12/201116/6/2026
Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to cause a denial of service via unspecified vectors.
ModificadaAlta (10)57%💥 ExploitMeasuresoft Scadapro16/9/201116/6/2026
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method.
ModificadaAlta (10)14%💥 ExploitMeasuresoft Scadapro16/9/201116/6/2026
service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command.
ModificadaAlta (10)10%💥 ExploitMeasuresoft Scadapro16/9/201116/6/2026
Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command.
ModificadaAlta (10)36%💥 ExploitMeasuresoft Scadapro16/9/201116/6/2026
Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long command to port 11234, as demonstrated with the TF command.