Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2743▼ 518 respecto a la semana anterior
Críticas / altas1293▼ 226 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.52% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 FirmwareRockwellautomation Compactlogix 5480 FirmwareRockwellautomation Controllogix 5580 Firmware+2 | 8/10/2024 | 17/6/2026 | Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to… | |
| Aplazada | Media (6.1) | 0.84% | 💥 Exploit | Elaines Realtime CRM AutomationAI | 7/10/2024 | 5/7/2026 | A reflected cross-site scripting (XSS) vulnerability in Elaine's Realtime CRM Automation v6.18.17 allows attackers to execute arbitrary JavaScript code in the web browser of a user via injecting a crafted payload into the dialog parameter at wrapper_dialog.php. | |
| Analizada | Alta (8.7) | 2.1% | — | Rockwellautomation Sequencemanager | 27/9/2024 | 17/6/2026 | An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user to send malformed packets to the server and cause a denial-of-service condition. If exploited, the device would become unresponsive, and a manual restart will be required for recovery. Additionally,… | |
| Aplazada | Crítica (9.3) | 0.42% | — | Talent Software BAP AutomationAI | 25/9/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation (XSS or 'Cross-site Scripting') vulnerability in Talent Software BAP Automation allows Stored XSS. This issue affects BAP Automation: before 30840. | |
| Aplazada | Media (6.9) | 0.38% | — | Yordam Information Technology Yordam Library Automation SystemAI | 18/9/2024 | 17/6/2026 | Improper Restriction of Excessive Authentication Attempts vulnerability in Yordam Information Technology Yordam Library Automation System allows Interface Manipulation. This issue affects Yordam Library Automation System: before 20.1. | |
| Analizada | Media (4.9) | 0.32% | — | IBM Business Automation Workflow | 18/9/2024 | 17/6/2026 | IBM Business Automation Workflow 22.0.2, 23.0.1, 23.0.2, and 24.0.0 could allow a privileged user to perform unauthorized activities due to improper client side validation. | |
| Analizada | Alta (8.6) | 0.96% | — | Rockwellautomation Pavilion8 | 12/9/2024 | 17/6/2026 | A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution. | |
| Analizada | Alta (8.8) | 0.45% | — | Rockwellautomation Pavilion8 | 12/9/2024 | 17/6/2026 | The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not. | |
| Analizada | Alta (7.7) | 1.3% | — | Rockwellautomation 2800c Optixpanel Compact FirmwareRockwellautomation 2800s Optixpanel Standard FirmwareRockwellautomation Embedded Edge Compute Module Firmware | 12/9/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges. | |
| Analizada | Alta (8.7) | 0.56% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 3 FirmwareRockwellautomation Compactlogix 5480 Firmware+3 | 12/9/2024 | 17/6/2026 | A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover. | |
| Aplazada | Media (6.6) | 0.43% | — | Ansible Automation ControllerAI | 12/9/2024 | 17/6/2026 | An improper authorization flaw exists in the Ansible Automation Controller. This flaw allows an attacker using the k8S API server to send an HTTP request with a service account token mounted via `automountServiceAccountToken: true`, resulting in privilege escalation to a service account. | |
| Analizada | Alta (8.5) | 12% | — | Rockwellautomation Thinmanager | 12/9/2024 | 17/6/2026 | CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If exploited, a user can install an executable file. | |
| Analizada | Alta (8.7) | 0.52% | — | Rockwellautomation 5015-u8ihft Firmware | 12/9/2024 | 17/6/2026 | CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service. | |
| Analizada | Crítica (9.2) | 0.54% | — | Rockwellautomation Factorytalk Batch View | 12/9/2024 | 17/6/2026 | CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication. | |
| Analizada | Crítica (9.2) | 1.3% | — | Rockwellautomation Factorytalk View | 12/9/2024 | 17/6/2026 | CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this… | |
| Aplazada | Crítica (9.2) | 11% | — | Siemens Automation License ManagerAI | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in Automation License Manager V5 (All versions), Automation License Manager V6.0 (All versions < V6.0 SP12 Upd3), Automation License Manager V6.2 (All versions < V6.2 Upd3). Affected applications do not properly validate certain fields in incoming network packets on port 4410/tcp.… | |
| Aplazada | Crítica (9.3) | 1.1% | — | Siemens Opcenter QualityAISiemens Opcenter RdnlAISiemens Simatic PCS NEOAISiemens Sinec NMSAI+2 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in Opcenter Quality (All versions < V2406), Opcenter RDnL (All versions < V2410), SIMATIC PCS neo V4.0 (All versions), SIMATIC PCS neo V4.1 (All versions < V4.1 Update 2), SIMATIC PCS neo V5.0 (All versions < V5.0 Update 1), SINEC NMS (All versions), SINEMA Remote Connect Client… | |
| Analizada | Media (5.9) | 0.95% | 💥 PoC | Identityautomation Rapididentity | 5/9/2024 | 17/6/2026 | RapidIdentity LTS through 2023.0.2 and Cloud through 2024.08.0 improperly restricts excessive authentication attempts and allows a remote attacker to cause a denial of service via the username parameters. | |
| Analizada | Media (5.1) | 0.25% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session | |
| Analizada | Media (5.4) | 0.17% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges. | |
| Analizada | Alta (7.3) | 0.17% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges. | |
| Analizada | Crítica (9.3) | 4.8% | — | Rockwellautomation Thinmanager Thinserver | 26/8/2024 | 17/6/2026 | A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten. | |
| Analizada | Alta (8.5) | 0.32% | — | Rockwellautomation Thinmanager Thinserver | 26/8/2024 | 17/6/2026 | A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files. | |
| Analizada | Media (6.8) | 0.56% | — | Rockwellautomation Thinmanager | 23/8/2024 | 17/6/2026 | A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat actor can exploit this vulnerability by abusing the ThinServer™ service to read arbitrary files by creating a junction that points to the target directory. | |
| Modificada | Alta (7.5) | 2.6% | — | Redhat Build OF Apache Camel - HawtioRedhat Build OF Apache Camel FOR Spring BootRedhat Build OF KeycloakRedhat Data Grid+5 | 21/8/2024 | 24/9/2026 | A vulnerability was found in Undertow where the ProxyProtocolReadListener reuses the same StringBuilder instance across multiple requests. This issue occurs when the parseProxyProtocolV1 method processes multiple requests on the same HTTP connection. As a result, different requests may share the same StringBuilder… |