Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (9.3) | 3.1% | — | Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With CimplicityIntelligent Platforms Proficy Process Systems | 27/1/2013 | 16/6/2026 | CimWebServer in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to execute arbitrary commands or cause a denial of service (daemon crash) via a crafted packet. | |
| Modificada | Media (4.3) | 19% | — | Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With CimplicityIntelligent Platforms Proficy Process Systems | 27/1/2013 | 16/6/2026 | Directory traversal vulnerability in substitute.bcl in the WebView CimWeb subsystem in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to read arbitrary files via a crafted packet. | |
| Modificada | Alta (10) | 21% | 💥 Exploit | Schneider-electric Interactive Graphical Scada System | 21/1/2013 | 16/6/2026 | Stack-based buffer overflow in Schneider Electric Interactive Graphical SCADA System (IGSS) 10 and earlier allows remote attackers to execute arbitrary code by sending TCP port-12397 data that does not comply with a protocol. | |
| Modificada | Media (4.3) | 1.2% | — | Intelligent Platforms Proficy Hmi/scada CimplicityIntelligent Platforms Proficy Process Systems With CimplicityIntelligent Platforms Proficy Process Systems | 17/1/2013 | 16/6/2026 | Integer overflow in CimWebServer.exe in GE Intelligent Platforms Proficy HMI/SCADA - CIMPLICITY 4.01 through 8.0, and Proficy Process Systems with CIMPLICITY, allows remote attackers to cause a denial of service (daemon crash) via a malformed HTTP request. | |
| Modificada | Alta (7.8) | 2.2% | — | C3-ilex Eoscada | 13/11/2012 | 16/6/2026 | eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 12000. | |
| Modificada | Media (5) | 1.7% | — | C3-ilex Eoscada | 13/11/2012 | 16/6/2026 | eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP port 12000. | |
| Modificada | Alta (7.8) | 2.2% | — | C3-ilex Eoscada | 13/11/2012 | 16/6/2026 | EOSDataServer.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 24006. | |
| Modificada | Media (5) | 1.9% | — | C3-ilex Eoscada | 13/11/2012 | 16/6/2026 | EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP port (1) 5050 or (2) 24004. | |
| Modificada | Alta (7.8) | 2.6% | — | Fultek Wintr Scada | 25/9/2012 | 16/6/2026 | Directory traversal vulnerability in the web server in Fultek WinTr Scada 4.0.5 and earlier allows remote attackers to read arbitrary files via a crafted request. | |
| Modificada | Media (4.6) | 0.47% | — | Mitsubishi-automation MX4 ScadaSchneider-electric Citectscada | 15/9/2012 | 16/6/2026 | Buffer overflow in an unspecified third-party component in the Batch module for Schneider Electric CitectSCADA before 7.20 and Mitsubishi MX4 SCADA before 7.20 allows local users to execute arbitrary code via a long string in a login sequence. | |
| Modificada | Media (6.9) | 0.45% | — | Invensys Foxboro Control SoftwareInvensys Infusion Ce/fe/scadaInvensys IntouchInvensys Intouch/wonderware Application Server+3 | 26/7/2012 | 16/6/2026 | Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified… | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | Intelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy HistorianIntelligent Platforms Proficy Hmi/scada IfixIntelligent Platforms Proficy Pulse+1 | 5/7/2012 | 16/6/2026 | An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows… | |
| Modificada | Alta (9.3) | 28% | 💥 Exploit | EMC Captiva Quickscan PROEMC Documentum Applicationxtender DesktopIntelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy Historian+3 | 5/7/2012 | 16/6/2026 | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5;… | |
| Modificada | Alta (7.2) | 0.48% | — | Measuresoft Scadapro ClientMeasuresoft Scadapro Server | 25/5/2012 | 16/6/2026 | Untrusted search path vulnerability in Measuresoft ScadaPro Client before 4.0.0 and ScadaPro Server before 4.0.0 allows local users to gain privileges via a Trojan horse DLL in the current working directory. | |
| Modificada | Media (6.8) | 27% | 💥 Exploit | Craig Peterson Turbopower AbbreviaScadatec ModbustagserverScadatec Scadaphone | 3/4/2012 | 16/6/2026 | Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file. | |
| Modificada | Media (6.8) | 3.2% | — | Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+4 | 2/4/2012 | 16/6/2026 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit… | |
| Modificada | Media (6.8) | 3.2% | — | Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+4 | 2/4/2012 | 16/6/2026 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit… | |
| Modificada | Media (5) | 1.7% | — | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Alta (10) | 57% | 💥 Exploit | Measuresoft Scadapro | 16/9/2011 | 16/6/2026 | service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary DLL functions via the XF function, possibly related to an insecure exposed method. | |
| Modificada | Alta (10) | 14% | 💥 Exploit | Measuresoft Scadapro | 16/9/2011 | 16/6/2026 | service.exe in Measuresoft ScadaPro 4.0.0 and earlier allows remote attackers to execute arbitrary commands via shell metacharacters in the (1) BF, (2) OF, or (3) EF command. | |
| Modificada | Alta (10) | 10% | 💥 Exploit | Measuresoft Scadapro | 16/9/2011 | 16/6/2026 | Multiple directory traversal vulnerabilities in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to read, modify, or delete arbitrary files via the (1) RF, (2) wF, (3) UF, or (4) NF command. | |
| Modificada | Alta (10) | 36% | 💥 Exploit | Measuresoft Scadapro | 16/9/2011 | 16/6/2026 | Multiple stack-based buffer overflows in service.exe in Measuresoft ScadaPro 4.0.0 and earlier allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a long command to port 11234, as demonstrated with the TF command. |