Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3020▼ 63 respecto a la semana anterior
Críticas / altas1413▲ 57 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.18% | — | Contec Conprosys HMI System | 1/6/2023 | 17/6/2026 | Incorrect permission assignment for critical resource exists in CONPROSYS HMI System (CHS) versions prior to 3.5.3. ACL (Access Control List) is not appropriately set to the local folder where the affected product is installed, therefore a wide range of privileges is permitted to a user of the PC where the affected… | |
| Modificada | Media (5.3) | 1.0% | — | Contec Conprosys HMI System | 31/5/2023 | 17/6/2026 | A denial of service vulnerability exists in Contec CONPROSYS HMI System versions 3.5.2 and prior. When there is a time-zone mismatch in certain configuration files, a remote, unauthenticated attacker may deny logins for an extended period of time. | |
| Modificada | Crítica (9.8) | 24% | — | Supcontech Simfield Firmware | 27/5/2023 | 17/6/2026 | A vulnerability, which was classified as critical, has been found in Supcon SimField up to 1.80.00.00. Affected by this issue is some unknown functionality of the file /admin/reportupload.aspx. The manipulation of the argument files[] leads to unrestricted upload. The attack may be launched remotely. The exploit has… | |
| Modificada | Media (4.3) | 1.8% | — | Contec Sv-cpt-mc310f FirmwareContec Sv-cpt-mc310 Firmware | 23/5/2023 | 17/6/2026 | Improper access control vulnerability in the system date/time setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to alter system date/time of the affected product. | |
| Modificada | Alta (8.8) | 1.9% | — | Contec Sv-cpt-mc310f FirmwareContec Sv-cpt-mc310 Firmware | 23/5/2023 | 17/6/2026 | OS command injection vulnerability in the mail setting page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows remote authenticated attackers to execute an arbitrary OS command. | |
| Modificada | Alta (8.8) | 1.5% | — | Contec Sv-cpt-mc310f FirmwareContec Sv-cpt-mc310 Firmware | 23/5/2023 | 17/6/2026 | Buffer overflow vulnerability in the multiple setting pages of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute arbitrary code. | |
| Modificada | Alta (8.8) | 1.9% | — | Contec Sv-cpt-mc310f FirmwareContec Sv-cpt-mc310 Firmware | 23/5/2023 | 17/6/2026 | OS command injection vulnerability in the download page of SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10 and SV-CPT-MC310F versions prior to Ver.8.10 allows a remote authenticated attacker to execute an arbitrary OS command. | |
| Modificada | Alta (7.2) | 1.0% | — | Contec Sv-cpt-mc310f FirmwareContec Sv-cpt-mc310 Firmware | 23/5/2023 | 17/6/2026 | Use of hard-coded credentials exists in SolarView Compact SV-CPT-MC310 versions prior to Ver.8.10, and SV-CPT-MC310F versions prior to Ver.8.10, which may allow a remote authenticated attacker to login the affected product with an administrative privilege and perform an unintended operation. | |
| Modificada | Crítica (9.1) | 60% | — | Contec Solarview Compact Firmware | 23/5/2023 | 17/6/2026 | SolarView Compact <= 6.0 is vulnerable to Insecure Permissions. Any file on the server can be read or modified because texteditor.php is not restricted. | |
| Modificada | Alta (8.8) | 1.9% | — | Contec Cps-mg341-adsc1-111 FirmwareContec Cps-mg341-adsc1-931 FirmwareContec Cps-mg341g-adsc1-111 FirmwareContec Cps-mg341g-adsc1-930 Firmware+15 | 11/4/2023 | 17/6/2026 | OS command injection vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker who can access Network Maintenance page to execute arbitrary OS commands with a root privilege. The affected products and versions are as follows: M2M Gateway with the firmware Ver.3.7.10 and earlier… | |
| Modificada | Alta (7.2) | 0.52% | — | Contec Cps-mg341-adsc1-111 FirmwareContec Cps-mg341-adsc1-931 FirmwareContec Cps-mg341g-adsc1-111 FirmwareContec Cps-mg341g-adsc1-930 Firmware+15 | 11/4/2023 | 17/6/2026 | Inadequate encryption strength vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker with an administrative privilege to apply a specially crafted Firmware update file, alter the information, cause a denial-of-service (DoS) condition, and/or execute arbitrary code. The affected… | |
| Modificada | Media (4.3) | 0.69% | — | Contec Cps-mg341-adsc1-111 FirmwareContec Cps-mg341-adsc1-931 FirmwareContec Cps-mg341g-adsc1-111 FirmwareContec Cps-mg341g-adsc1-930 Firmware+15 | 11/4/2023 | 17/6/2026 | Improper access control vulnerability in CONPROSYS IoT Gateway products allows a remote authenticated attacker to bypass access restriction and access Network Maintenance page, which may result in obtaining the network information of the product. The affected products and versions are as follows: M2M Gateway with the… | |
| Modificada | Crítica (9.8) | 99% | — | Contec Solarview Compact Firmware | 6/2/2023 | 17/6/2026 | There is a command injection vulnerability in SolarView Compact through 6.00, attackers can execute commands by bypassing internal restrictions through downloader.php. | |
| Modificada | Media (6.5) | 1.3% | — | Contec Conprosys HMI System | 30/1/2023 | 17/6/2026 | SQL injection vulnerability in the CONPROSYS HMI System (CHS) Ver.3.5.0 and earlier allows a remote authenticated attacker to execute an arbitrary SQL command. As a result, information stored in the database may be obtained. | |
| Modificada | Media (5.4) | 1.9% | — | Contec Conprosys HMI System | 20/1/2023 | 17/6/2026 | Cross-site scripting vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to inject an arbitrary script and obtain the sensitive information. | |
| Modificada | Alta (7.5) | 1.1% | — | Contec Conprosys HMI System | 20/1/2023 | 17/6/2026 | Improper access control vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to bypass access restriction and obtain the server certificate including the private key of the product. | |
| Modificada | Media (5.3) | 0.88% | — | Contec Conprosys HMI System | 20/1/2023 | 17/6/2026 | Use of password hash instead of password for authentication vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote authenticated attacker to obtain user credentials information via a man-in-the-middle attack. | |
| Modificada | Alta (7.5) | 1.0% | — | Contec Conprosys HMI System | 20/1/2023 | 17/6/2026 | Use of default credentials vulnerability in CONPROSYS HMI System (CHS) Ver.3.4.5 and earlier allows a remote unauthenticated attacker to alter user credentials information. | |
| Modificada | Crítica (9.8) | 70% | — | Contec Conprosys HMI System | 19/12/2022 | 17/6/2026 | CONPROSYS HMI System (CHS) Ver.3.4.4?and earlier allows a remote unauthenticated attacker to execute an arbitrary OS command on the server where the product is running by sending a specially crafted request. | |
| Modificada | Media (6.1) | 1.7% | — | Contec Solarview Compact Firmware | 29/11/2022 | 17/6/2026 | SolarView Compact 7.0 is vulnerable to Cross-site Scripting (XSS) via /network_test.php. | |
| Modificada | Crítica (9.8) | 1.6% | — | Contec Solarview Compact Firmware | 29/11/2022 | 17/6/2026 | SolarView Compact 4.0 and 5.0 is vulnerable to Unrestricted File Upload via a crafted php file. | |
| Modificada | Crítica (9.8) | 30% | — | Contec Solarview Compact Firmware | 17/11/2022 | 17/6/2026 | SolarView Compact 6.00 was discovered to contain a command injection vulnerability via network_test.php | |
| Modificada | Alta (8.8) | 1.0% | — | Contec Fxa3000 FirmwareContec Fxa3020 FirmwareContec Fxa3200 FirmwareContec Fxa2000 Firmware | 26/9/2022 | 17/6/2026 | Contec FXA3200 version 1.13 and under were discovered to contain a hard coded hash password for root stored in the component /etc/shadow. As the password strength is weak, it can be cracked in few minutes. Through this credential, a malicious actor can access the Wireless LAN Manager interface and open the telnet port… | |
| Modificada | Alta (8) | 1.6% | — | Contec Fxa3000 FirmwareContec Fxa3020 FirmwareContec Fxa3200 FirmwareContec Fxa2000 Firmware | 26/9/2022 | 17/6/2026 | Contec FXA3200 version 1.13.00 and under suffers from Insecure Permissions in the Wireless LAN Manager interface which allows malicious actors to execute Linux commands with root privilege via a hidden web page (/usr/www/ja/mnt_cmd.cgi). | |
| Modificada | Media (5.7) | 0.30% | — | Contechealth Cms8000 Firmware | 13/9/2022 | 17/6/2026 | The CMS8000 device does not properly control or sanitize the SSID name of a new Wi-Fi access point. A threat actor could create an SSID with a malicious name, including non-standard characters that, when the device attempts connecting to the malicious SSID, the device can be exploited to write arbitrary files or… |