Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

66 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.9%—Iconics AnalytixIconics Genesis64Iconics Hyper HistorianIconics Mobilehmi+121/1/202217/6/2026
Incomplete List of Disallowed Inputs vulnerability in Mitsubishi Electric MC Works64 versions 4.00A (10.95.201.23) to 4.04E (10.95.210.01), ICONICS GENESIS64 versions 10.95.3 to 10.97, ICONICS Hyper Historian versions 10.95.3 to 10.97, ICONICS AnalytiX versions 10.95.3 to 10.97 and ICONICS MobileHMI versions 10.95.3…
ModificadaAlta (7.1)0.30%—Wibu Codemeter RuntimeSiemens PSS CapeSiemens PSS ESiemens PSS Odms+614/11/202117/6/2026
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
ModificadaAlta (8.1)0.80%—Siemens Simatic Process Historian 2013Siemens Simatic Process Historian 2014Siemens Simatic Process Historian 2019Siemens Simatic Process Historian 202012/10/202117/6/2026
A vulnerability has been identified in SIMATIC Process Historian 2013 and earlier (All versions), SIMATIC Process Historian 2014 (All versions < SP3 Update 6), SIMATIC Process Historian 2019 (All versions), SIMATIC Process Historian 2020 (All versions). An interface in the software that is used for critical…
ModificadaAlta (7.5)2.6%—Opcfoundation Local Discover ServerSiemens Simatic Process Historian OPC UA Server FirmwareSiemens Simatic NET PCSiemens Simatic Wincc+327/8/202117/6/2026
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
ModificadaCrítica (9.1)33%—Wibu CodemeterSiemens PSS CapeSiemens Sicam 230 FirmwareSiemens Simatic Information Server+616/6/202117/6/2026
A buffer over-read vulnerability exists in Wibu-Systems CodeMeter versions < 7.21a. An unauthenticated remote attacker can exploit this issue to disclose heap memory contents or crash the CodeMeter Runtime Server.
ModificadaMedia (5.9)64%💥 PoCOpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+10225/3/202117/6/2026
An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer…
ModificadaCrítica (9.8)1.5%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network…
ModificadaAlta (7)0.28%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.
ModificadaCrítica (9.8)1.9%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.
ModificadaAlta (8.8)1.5%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.
ModificadaAlta (8.8)1.4%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data.
ModificadaAlta (7.8)0.43%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.
ModificadaCrítica (9.8)1.2%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process.
ModificadaAlta (8.8)3.1%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
ModificadaCrítica (9.8)1.1%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some…
ModificadaCrítica (9.8)1.2%—Aveva Edna Enterprise Data Historian24/9/202017/6/2026
Parameter psClass in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.
ModificadaCrítica (9.8)1.2%—Aveva Edna Enterprise Data Historian24/9/202017/6/2026
Parameter AttFilterValue in ednareporting.asmx is vulnerable to unauthenticated SQL injection attacks. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. An attacker can send unauthenticated HTTP requests to trigger this vulnerability.
ModificadaCrítica (9.8)2.9%—Aveva Edna Enterprise Data Historian24/9/202017/6/2026
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstanceName in CHaD.asmx is vulnerable to unauthenticated SQL injection…
ModificadaCrítica (9.8)2.9%—Aveva Edna Enterprise Data Historian24/9/202017/6/2026
SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter ClassName in CHaD.asmx is vulnerable to unauthenticated SQL injection attacks.
ModificadaCrítica (9.8)2.9%—Aveva Edna Enterprise Data Historian24/9/202017/6/2026
An SQL injection vulnerability exists in the CHaD.asmx web service functionality of eDNA Enterprise Data Historian 3.0.1.2/7.5.4989.33053. Specially crafted SOAP web requests can cause SQL injections resulting in data compromise. Parameter InstancePath in CHaD.asmx is vulnerable to unauthenticated SQL injection…
ModificadaAlta (7.5)2.0%—Mitsubishielectric MC WorksMitsubishielectric MC Works32Iconics Energy AnalytixIconics Facility Analytix+716/7/202017/6/2026
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition due to improper deserialization. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 version 3.00A (9.50.255.02); ICONICS…
ModificadaCrítica (9.1)3.0%—Mitsubishielectric MC Works32Mitsubishielectric MC Works64Iconics Energy AnalytixIconics Facility Analytix+716/7/202017/6/2026
A specially crafted WCF client that interfaces to the may allow the execution of certain arbitrary SQL commands remotely. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS GenBroker64, Platform…
ModificadaCrítica (9.8)3.9%—Mitsubishielectric MC WorksMitsubishielectric MC Works32Iconics Energy AnalytixIconics Facility Analytix+716/7/202017/6/2026
A specially crafted communication packet sent to the affected devices could allow remote code execution and a denial-of-service condition due to a deserialization vulnerability. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32…
ModificadaAlta (7.5)3.6%—Mitsubishielectric MC WorksMitsubishielectric MC Works32Iconics Energy AnalytixIconics Facility Analytix+716/7/202017/6/2026
A specially crafted communication packet sent to the affected device could cause a denial-of-service condition due to a deserialization vulnerability. This affects: Mitsubishi Electric MC Works64 Version 4.02C (10.95.208.31) and earlier, all versions; Mitsubishi Electric MC Works32 Version 3.00A (9.50.255.02); ICONICS…
ModificadaCrítica (9.8)29%—Mitsubishielectric MC WorksMitsubishielectric MC Works32Iconics Energy AnalytixIconics Facility Analytix+716/7/202017/6/2026
A specially crafted communication packet sent to the affected systems could cause a denial-of-service condition or allow remote code execution. This issue affects: Mitsubishi Electric MC Works64 version 4.02C (10.95.208.31) and earlier, all versions; MC Works32 version 3.00A (9.50.255.02); ICONICS GenBroker64,…
Orbitaley — Vulnerabilidades