Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
76 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.19% | — | Jungo WindriverMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+31 | 2/7/2024 | 17/6/2026 | Improper privilege management in Jungo WinDriver before 12.1.0 allows local attackers to escalate privileges and execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.1% | — | Mitsubishielectric EzsocketMitsubishielectric FR Configurator2Mitsubishielectric Got1000Mitsubishielectric Got2000+6 | 30/1/2024 | 17/6/2026 | Use of Externally-Controlled Input to Select Classes or Code ('Unsafe Reflection') vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX… | |
| Modificada | Alta (7.5) | 0.95% | — | Mitsubishielectric EzsocketMitsubishielectric FR Configurator2Mitsubishielectric Got1000Mitsubishielectric Got2000+6 | 30/1/2024 | 17/6/2026 | Missing Authentication for Critical Function vulnerability in Mitsubishi Electric Corporation EZSocket versions 3.0 to 5.92, GT Designer3 Version1(GOT1000) versions 1.325P and prior, GT Designer3 Version1(GOT2000) versions 1.320J and prior, GX Works2 versions 1.11M to 1.626C, GX Works3 versions 1.106L and prior,… | |
| Modificada | Alta (7.5) | 1.0% | — | Wago Telecontrol ConfiguratorWagoapprtu | 5/12/2023 | 17/6/2026 | The MMS Interpreter of WagoAppRTU in versions below 1.4.6.0 which is used by the WAGO Telecontrol Configurator is vulnerable to malformed packets. An remote unauthenticated attacker could send specifically crafted packets that lead to a denial-of-service condition until restart of the affected device. | |
| Modificada | Alta (7.5) | 0.76% | — | Loytec L-inx Configurator | 30/11/2023 | 17/6/2026 | LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. An admin credential is passed as a value of URL parameters without encryption, so it allows remote attackers to steal the password and gain full control of Loytec device configuration. | |
| Modificada | Alta (7.5) | 1.5% | — | Loytec L-inx Configurator | 30/11/2023 | 17/6/2026 | LOYTEC electronics GmbH LINX Configurator (all versions) is vulnerable to Insecure Permissions. Cleartext storage of credentials allows remote attackers to disclose admin password and bypass an authentication to login Loytec device. | |
| Modificada | Alta (7.5) | 1.4% | — | Loytec L-inx Configurator | 30/11/2023 | 17/6/2026 | LOYTEC electronics GmbH LINX Configurator (all versions) uses HTTP Basic Authentication, which transmits usernames and passwords in base64-encoded cleartext and allows remote attackers to steal the password and gain full control of Loytec device configuration. | |
| Modificada | Crítica (9.8) | 0.52% | — | Dmconcept Configurator | 19/10/2023 | 17/6/2026 | DM Concept configurator before v4.9.4 was discovered to contain a SQL injection vulnerability via the component ConfiguratorAttachment::getAttachmentByToken. | |
| Modificada | Alta (8.8) | 0.45% | — | Selinc Sel-5037 SEL Grid Configurator | 31/8/2023 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run arbitrary commands on managed devices by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details.… | |
| Modificada | Crítica (9.8) | 0.43% | — | Selinc Sel-5037 SEL Grid Configurator | 31/8/2023 | 17/6/2026 | An Execution with Unnecessary Privileges vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to run system commands with the highest level privilege on the system. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue… | |
| Modificada | Media (6.5) | 0.24% | — | Selinc Sel-5037 SEL Grid Configurator | 31/8/2023 | 17/6/2026 | A Cross-Site Request Forgery (CSRF) vulnerability in the Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator could allow an attacker to embed instructions that could be executed by an authorized device operator. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue… | |
| Modificada | Alta (8.4) | 0.21% | — | Selinc Sel-5037 SEL Grid Configurator | 31/8/2023 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Schweitzer Engineering Laboratories SEL-5037 SEL Grid Configurator on Windows allows Authentication Bypass. See Instruction Manual Appendix A and Appendix E dated 20230615 for more details. This issue affects SEL-5037 SEL Grid Configurator: before 4.5.0.20. | |
| Modificada | Media (6.1) | 0.37% | — | Login Configurator Project Login Configurator | 30/8/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Login Configurator Project Login Configurator | 25/7/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in GrandSlambert Login Configurator plugin <= 2.1 versions. | |
| Modificada | Media (6.1) | 0.72% | 💥 Exploit | Login Configurator Project Login Configurator | 17/7/2023 | 17/6/2026 | The Login Configurator WordPress plugin through 2.1 does not properly escape a URL parameter before outputting it to the page, leading to a reflected cross-site scripting vulnerability targeting site administrators. | |
| Modificada | Alta (7.5) | 0.85% | — | Mitsubishielectric GX Works3Mitsubishielectric MX OPC UA Module Configurator-r | 25/11/2022 | 17/6/2026 | Cleartext Storage of Sensitive Information vulnerability in Mitsubishi Electric GX Works3 versions from 1.000A to 1.095Z and Mitsubishi Electric MX OPC UA Module Configurator-R versions 1.08J and prior allows a remote unauthenticated attacker to disclose sensitive information. As a result, unauthenticated attackers… | |
| Modificada | Media (5.5) | 0.23% | — | Pilz PAS 4000Pliz PascalPliz PasconnectPliz Pasmotion+1 | 24/11/2022 | 17/6/2026 | A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability. | |
| Modificada | Alta (7.8) | 0.22% | — | Intel Enpirion Digital Power Configurator GUI | 18/8/2022 | 17/6/2026 | Uncontrolled search path element in the Intel(R) Enpirion(R) Digital Power Configurator GUI software, all versions may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.1) | 1.7% | — | Product Configurator FOR Woocommerce Project Product Configurator FOR Woocommerce | 27/6/2022 | 17/6/2026 | The Product Configurator for WooCommerce WordPress plugin before 1.2.32 suffers from an arbitrary file deletion vulnerability via an AJAX action, accessible to unauthenticated users, which accepts user input that is being used in a path and passed to unlink() without validation first | |
| Modificada | Crítica (9.8) | 0.85% | — | Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+25 | 19/5/2022 | 17/6/2026 | Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,… | |
| Modificada | Alta (7.8) | 0.37% | — | Zyxel AP Configurator | 11/4/2022 | 17/6/2026 | A local privilege escalation vulnerability caused by incorrect permission assignment in some directories of the Zyxel AP Configurator (ZAC) version 1.1.4, which could allow an attacker to execute arbitrary code as a local administrator. | |
| Modificada | Crítica (9.8) | 2.3% | — | Mitsubishielectric CW ConfiguratorMitsubishielectric FR Configurator2Mitsubishielectric GX Works2Mitsubishielectric GX Works3+16 | 11/2/2022 | 17/6/2026 | Multiple Mitsubishi Electric Factory Automation products have a vulnerability that allows an attacker to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.3% | — | Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+42 | 11/2/2022 | 17/6/2026 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition. | |
| Modificada | Alta (8.1) | 1.1% | — | Oracle Configurator | 19/1/2022 | 17/6/2026 | Vulnerability in the Oracle Configurator product of Oracle E-Business Suite (component: UI Servlet). Supported versions that are affected are 12.2.3-12.2.11. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Configurator. Successful attacks of this… | |
| Modificada | Alta (8.1) | 0.99% | — | Oracle Legal Entity Configurator | 22/4/2021 | 17/6/2026 | Vulnerability in the Oracle Legal Entity Configurator product of Oracle E-Business Suite (component: Create Contracts). Supported versions that are affected are 12.1.1-12.1.3. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise Oracle Legal Entity Configurator.… |