Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

71 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.00%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+217/8/202217/6/2026
Softing Secure Integration Server, edgeConnector, and edgeAggregator software ships with the default administrator credentials as `admin` and password as `admin`. This allows Softing to log in to the server directly to perform administrative functions. Upon installation or upon first login, the application does not…
ModificadaAlta (7.5)1.5%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+217/8/202217/6/2026
A crafted HTTP packet with a -1 content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
ModificadaAlta (7.2)12%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+217/8/202217/6/2026
The application searches for a library dll that is not found. If an attacker can place a dll with this name, then the attacker can leverage it to execute arbitrary code on the targeted Softing Secure Integration Server V1.22.
ModificadaAlta (7.5)0.98%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+217/8/202217/6/2026
Softing OPC UA C++ Server SDK, Secure Integration Server, edgeConnector, edgeAggregator, OPC Suite, and uaGate are affected by a NULL pointer dereference vulnerability.
ModificadaAlta (7.2)13%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+217/8/202217/6/2026
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path…
ModificadaAlta (7.5)1.5%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+217/8/202217/6/2026
A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
ModificadaAlta (7.5)0.92%—Seagate Cortx-s3 Server7/4/202217/6/2026
A Denial of Service vulnerability exists in CORTX-S3 Server as of 11/7/2021 via the mempool_destroy method due to a failture to release locks pool->lock.
ModificadaAlta (7.5)1.3%—Softing Datafeed OPC SuiteSofting EdgeconnectorSofting OPCSofting Secure Integration Server+310/11/202117/6/2026
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.
ModificadaCrítica (9.8)2.3%—Genuagate3/3/202117/6/2026
An issue was discovered in genua genugate before 9.0 Z p19, 9.1.x through 9.6.x before 9.6 p7, and 10.x before 10.1 p4. The Web Interfaces (Admin, Userweb, Sidechannel) can use different methods to perform the authentication of a user. A specific authentication method during login does not check the provided data…
ModificadaAlta (8.8)3.3%—Softing Uagate SI FirmwareSofting Uagate MB FirmwareSofting Uagate 840d Firmware10/10/201917/6/2026
An issue was discovered in Softing uaGate (SI, MB, 840D) firmware through 1.71.00.1225. A CGI script is vulnerable to command injection via a maliciously crafted form parameter.
ModificadaAlta (7.5)1.2%—Softing Uagate SI Firmware10/10/201917/6/2026
An issue was discovered in Softing uaGate SI 1.60.01. A system default path for executables is user writable.
ModificadaAlta (8.8)3.5%—Softing Uagate SI Firmware10/10/201917/6/2026
An issue was discovered in Softing uaGate SI 1.60.01. A CGI script is vulnerable to command injection with a maliciously crafted url parameter.
ModificadaCrítica (9.8)2.0%—Softing Uagate SI Firmware10/10/201917/6/2026
An issue was discovered in Softing uaGate SI 1.60.01. A maintenance script, that is executable via sudo, is vulnerable to file path injection. This enables the Attacker to write files with superuser privileges in specific locations.
ModificadaAlta (7.8)0.41%—Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware7/6/201917/6/2026
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They replace secure and protected directory permissions (set as default by the underlying operating system) with highly insecure read, write, and execute directory permissions for all…
ModificadaCrítica (9.8)2.0%—Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware7/6/201917/6/2026
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They include a hard-coded SSH backdoor for remote SSH and SCP access as the root user. A command in the relocate and relocate_revB scripts copies the hardcoded key to the root user's…
ModificadaAlta (8.8)1.8%—Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware7/6/201917/6/2026
An issue was discovered on the ENTTEC Datagate MK2, Storm 24, Pixelator, and E-Streamer MK2 with firmware 70044_update_05032019-482. They allow high-privileged root access by www-data via sudo without requiring appropriate access control. (Furthermore, the user account that controls the web application service is…
ModificadaMedia (6.1)0.82%—Enttec Datagate MK2 FirmwareEnttec Storm 24 FirmwareEnttec Pixelator FirmwareEnttec E-streamer MK2 Firmware7/6/201917/6/2026
A number of stored XSS vulnerabilities have been identified in the web configuration feature in ENTTEC Datagate Mk2 70044_update_05032019-482 that could allow an unauthenticated threat actor to inject malicious code directly into the application. This affects, for example, the Profile Description field in JSON data to…
ModificadaMedia (6.1)0.83%—Seagate NAS OS13/5/201917/6/2026
Cross-site scripting in Application Manager in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via multiple application metadata fields: Short Description, Publisher Name, Publisher Contact, or Website URL.
ModificadaMedia (5.4)0.64%—Seagate NAS OS13/5/201917/6/2026
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via directory names.
ModificadaMedia (6.1)0.80%—Seagate NAS OS13/5/201917/6/2026
Missing HTTPOnly flag on session cookies in the Seagate NAS OS version 4.3.15.1 web application allows attackers to steal session tokens via cross-site scripting.
ModificadaAlta (7.5)1.4%—Seagate NAS OS13/5/201917/6/2026
Unvalidated URL in Download Manager in Seagate NAS OS version 4.3.15.1 allows attackers to access the loopback interface via a Download URL of 127.0.0.1 or localhost.
ModificadaMedia (6.1)3.1%—Seagate NAS OS13/5/201917/6/2026
Arbitrary Redirect in echo-server.html in Seagate NAS OS version 4.3.15.1 allows attackers to disclose information in the Referer header via the 'state' URL parameter.
ModificadaMedia (5.4)0.64%—Seagate NAS OS13/5/201917/6/2026
Cross-site scripting in filebrowser in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via uploaded file names.
ModificadaAlta (7.5)1.7%—Seagate NAS OS13/5/201917/6/2026
Directory Traversal in filebrowser in Seagate NAS OS 4.3.15.1 allows attackers to read files within the application's container via a URL path.
ModificadaMedia (6.1)0.69%—Seagate NAS OS13/5/201917/6/2026
Cross-site scripting in API error pages in Seagate NAS OS version 4.3.15.1 allows attackers to execute JavaScript via URL path names.