Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
107 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.55% | — | Embedded-solutions Freemodbus | 8/7/2024 | 17/6/2026 | Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component. | |
| Modificada | Media (4.3) | 0.47% | — | Libmodbus | 31/5/2024 | 17/6/2026 | An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. | |
| Modificada | Alta (7.5) | 0.61% | — | Libmodbus | 31/5/2024 | 17/6/2026 | libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. | |
| Modificada | Alta (7.5) | 0.79% | — | Libmodbus | 31/5/2024 | 17/6/2026 | libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. | |
| Analizada | Alta (7.5) | 0.52% | — | Libmodbus | 8/5/2024 | 17/6/2026 | libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors. | |
| Analizada | Crítica (9.8) | 0.73% | — | Libmodbus | 1/5/2024 | 17/6/2026 | libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c. | |
| Modificada | Media (6.5) | 1.4% | — | Freedesktop DbusFedoraproject FedoraDebian Linux | 8/6/2023 | 17/6/2026 | D-Bus before 1.15.6 sometimes allows unprivileged users to crash dbus-daemon. If a privileged user with control over the dbus-daemon is using the org.freedesktop.DBus.Monitoring interface to monitor message bus traffic, then an unprivileged user with the ability to connect to the same dbus-daemon can cause a… | |
| Modificada | Alta (7.5) | 1.2% | — | Opcfoundation UA Java LegacyProsysopc UA HistorianProsysopc UA Modbus ServerProsysopc UA Simulation Server | 15/5/2023 | 17/6/2026 | The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications. | |
| Modificada | Media (4.3) | 0.85% | — | Rockwellautomation Modbus TCP Server ADD ON Instructions | 17/3/2023 | 17/6/2026 | Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP… | |
| Modificada | Alta (7.5) | 0.40% | — | Prosysopc UA Modbus ServerProsysopc UA Simulation Server | 3/1/2023 | 17/6/2026 | Prosys OPC UA Simulation Server version prior to v5.3.0-64 and UA Modbus Server versions 1.4.18-5 and prior do not sufficiently protect credentials, which could allow an attacker to obtain user credentials and gain access to system data. | |
| Modificada | Alta (7.8) | 0.66% | — | Modbustools Modbus Poll | 30/12/2022 | 17/6/2026 | A vulnerability was found in Modbus Tools Modbus Poll up to 9.10.0 and classified as critical. Affected by this issue is some unknown functionality of the file mbpoll.exe of the component mbp File Handler. The manipulation leads to buffer overflow. The attack may be launched remotely. The exploit has been disclosed to… | |
| Modificada | Alta (7.8) | 0.59% | — | Modbustools Modbus Slave | 30/12/2022 | 17/6/2026 | A vulnerability has been found in Modbus Tools Modbus Slave up to 7.5.1 and classified as critical. Affected by this vulnerability is an unknown functionality of the file mbslave.exe of the component mbs File Handler. The manipulation leads to buffer overflow. The attack can be launched remotely. The exploit has been… | |
| Modificada | Alta (7.8) | 0.16% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/12/2022 | 17/6/2026 | Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards. | |
| Modificada | Media (6.5) | 1.8% | — | Freedesktop DbusFedoraproject Fedora | 10/10/2022 | 17/6/2026 | An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash by sending a message with attached file descriptors in an unexpected format. | |
| Modificada | Media (6.5) | 1.8% | — | Freedesktop DbusFedoraproject Fedora | 10/10/2022 | 17/6/2026 | An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message where an array length is inconsistent with the size of the element type. | |
| Modificada | Media (6.5) | 1.1% | — | Freedesktop DbusFedoraproject Fedora | 10/10/2022 | 17/6/2026 | An issue was discovered in D-Bus before 1.12.24, 1.13.x and 1.14.x before 1.14.4, and 1.15.x before 1.15.2. An authenticated attacker can cause dbus-daemon and other programs that use libdbus to crash when receiving a message with certain invalid type signatures. | |
| Modificada | Alta (7.8) | 0.46% | — | LibmodbusFedoraproject Extra Packages FOR Enterprise LinuxFedoraproject FedoraDebian Linux | 29/8/2022 | 17/6/2026 | A heap-based buffer overflow flaw was found in libmodbus in function modbus_reply() in src/modbus.c. | |
| Modificada | Media (5.5) | 0.18% | — | Emerson Deltav Distributed Control SystemEmerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block Firmware+21 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using… | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Media (5.5) | 0.24% | — | Emerson Deltav Distributed Control System SQ Controller FirmwareEmerson Deltav Distributed Control System SX Controller FirmwareEmerson Se4002s1t2b6 High Side 40-pin Mass I/O Terminal Block FirmwareEmerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware+20 | 26/7/2022 | 17/6/2026 | The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350. | |
| Modificada | Alta (7.5) | 2.3% | — | Dbus-broker Project Dbus-broker | 17/7/2022 | 17/6/2026 | An issue was discovered in dbus-broker before 31. Multiple NULL pointer dereferences can be found when supplying a malformed XML config file. | |
| Modificada | Alta (7.5) | 2.3% | — | Dbus-broker Project Dbus-broker | 17/7/2022 | 17/6/2026 | An issue was discovered in dbus-broker before 31. It depends on c-uitl/c-shquote to parse the DBus service's Exec line. c-shquote contains a stack-based buffer over-read if a malicious Exec line is supplied. | |
| Modificada | Alta (7.5) | 1.3% | — | Siemens En100 Ethernet Module Dnp3 IP FirmwareSiemens En100 Ethernet Module IEC 104 FirmwareSiemens En100 Ethernet Module IEC 61850 FirmwareSiemens En100 Ethernet Module Modbus TCP Firmware+1 | 12/7/2022 | 17/6/2026 | A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.40), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All… | |
| Modificada | Alta (7.5) | 1.2% | — | Siemens En100 Ethernet Module Dnp3 FirmwareSiemens En100 Ethernet Module IEC 104 FirmwareSiemens En100 Ethernet Module IEC 61850 FirmwareSiemens En100 Ethernet Module Modbus TCP Firmware+1 | 14/6/2022 | 17/6/2026 | A vulnerability has been identified in EN100 Ethernet module DNP3 IP variant (All versions), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All… |