Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

927 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-763: Release of invalid pointer or reference vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing checks of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-416: Use after free vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to use of unchecked input data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-824: Access of uninitialized pointer vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack validation of user-supplied input data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.3%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied input data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.3%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of user-supplied data validation, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.3%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or remote code execution due to lack of sanity checks on user-supplied data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to lack of proper validation of user-supplied data, when a malicious CGF file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-125: Out-of-bounds read vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious WSP file is being parsed by IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in loss of data or remote code execution due to missing size checks, when a malicious WSP (Workspace) file is being parsed by IGSS Definition.
ModificadaAlta (7.8)0.85%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21140 and prior that could result in disclosure of information or execution of arbitrary code due to lack of input validation, when a malicious CGF (Configuration Group File) file is imported to IGSS Definition.
ModificadaAlta (7.8)1.2%—Schneider-electric Interactive Graphical Scada System11/6/202117/6/2026
A CWE-787: Out-of-bounds write vulnerability exists inIGSS Definition (Def.exe) V15.0.0.21041 and prior that could result in loss of data or remote code execution due to missing length checks, when a malicious CGF file is imported to IGSS Definition.
ModificadaMedia (4.7)0.21%—Intel Integrated Performance Primitives CryptographyIntel SGX DcapIntel SGX PSWIntel SGX SDK9/6/202117/6/2026
Observable timing discrepancy in Intel(R) IPP before version 2020 update 1 may allow authorized user to potentially enable information disclosure via local access.
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method ChartInterpreter::DoIt() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CMiniXMLParser::Parse() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method IgsData::freeMemory() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CiXMLIStreamRawBuffer::readRaw () which will trigger an…
ModificadaMedia (5.9)0.86%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CXmlUtility::CheckLength() which will trigger an internal…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method CDrawRaster::LoadImageFromMemory() which will trigger an…
ModificadaMedia (5.9)1.2%—SAP Netweaver AS Internet Graphics Server9/6/202117/6/2026
SAP Internet Graphics Service, versions - 7.20,7.20EXT,7.53,7.20_EX2,7.81, allows an unauthenticated attacker after retrieving an existing system state value can submit a malicious IGS request over a network which due to insufficient input validation in method Ups::AddPart() which will trigger an internal memory…
ModificadaAlta (7.5)2.2%—Hexagon Intergraph G!nius14/5/202117/6/2026
Hexagon G!nius Auskunftsportal before 5.0.0.0 allows SQL injection via the GiPWorkflow/Service/DownloadPublicFile id parameter.
ModificadaMedia (6.5)1.4%—Graphhopper13/5/202117/6/2026
GraphHopper is an open-source Java routing engine. In GrassHopper from version 2.0 and before version 2.4, there is a regular expression injection vulnerability that may lead to Denial of Service. This has been patched in 2.4 and 3.0 See this pull request for the fix:…
ModificadaAlta (7.8)0.26%—Teradici Pcoip Graphics Agent13/5/202117/6/2026
Teradici PCoIP Graphics Agent for Windows prior to 21.03 does not validate NVENC.dll. An attacker could replace the .dll and redirect pixels elsewhere.
ModificadaAlta (7.8)2.6%—GraphvizDebian LinuxFedoraproject Fedora29/4/202117/6/2026
Buffer Overflow in Graphviz Graph Visualization Tools from commit ID f8b9e035 and earlier allows remote attackers to execute arbitrary code or cause a denial of service (application crash) by loading a crafted file into the "lib/common/shapes.c" component.
ModificadaAlta (7.8)1.1%—Cairographics Cairo18/3/202117/6/2026
A flaw was found in cairo's image-compositor.c in all versions prior to 1.17.4. This flaw allows an attacker who can provide a crafted input file to cairo's image-compositor (for example, by convincing a user to open a file in an application using cairo, or if an application uses cairo on untrusted input) to cause a…
ModificadaAlta (7.8)0.93%—Schneider-electric Interactive Graphical Scada System11/3/202117/6/2026
A CWE-119:Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists in Interactive Graphical SCADA System (IGSS) Definition (Def.exe) V15.0.0.21041 and prior, which could result in arbitrary read or write conditions when malicious CGF (Configuration Group File) file is imported to…