Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
130 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.27% | — | Siemens Versicharge Blue EV ChargerAISiemens IEC EV ChargerAI | 13/5/2025 | 17/6/2026 | A vulnerability has been identified in IEC 1Ph 7.4kW Child socket (8EM1310-2EH04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Child socket/ shutter (8EM1310-2EN04-0GA0) (All versions < V2.135), IEC 1Ph 7.4kW Parent cable 7m (8EM1310-2EJ04-3GA1) (All versions < V2.135), IEC 1Ph 7.4kW Parent cable 7m incl. SIM… | |
| Aplazada | Media (5.9) | 0.22% | — | CookiecodeAI | 7/5/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in cookiecode CookieCode cookiecode allows Stored XSS.This issue affects CookieCode: from n/a through <= 2.4.4. | |
| Aplazada | Alta (7.1) | 0.14% | — | Lukaszwiecek Smart DofollowAI | 7/2/2025 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in LukaszWiecek Smart DoFollow smart-dofollow allows Stored XSS.This issue affects Smart DoFollow: from n/a through <= 1.0.2. | |
| Aplazada | Media (6.5) | 0.23% | — | Eric Mcniece Emc2 Alert BoxesAI | 7/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Eric McNiece EMC2 Alert Boxes allows Stored XSS.This issue affects EMC2 Alert Boxes: from n/a through 1.3. | |
| Aplazada | Media (6.5) | 0.34% | — | Wojciechborowicz Smooth MapsAI | 19/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wojciechborowicz Smooth Maps colour-smooth-maps allows Stored XSS.This issue affects Smooth Maps: from n/a through <= 1.1. | |
| Analizada | Crítica (9.8) | 0.61% | — | Mz-automation Libiec61850 | 15/11/2024 | 17/6/2026 | Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit 1f52be9ddeae00e69cd43e4cac3cb4f0c880c4f0 allow a malicious server to cause a stack-based buffer overflow via the MMS IdentifyResponse message. | |
| Analizada | Crítica (9.8) | 0.61% | — | Mz-automation Libiec61850 | 15/11/2024 | 17/6/2026 | Multiple Buffer overflows in the MMS Client in MZ Automation LibIEC61850 before commit ac925fae8e281ac6defcd630e9dd756264e9c5bc allow a malicious server to cause a stack-based buffer overflow via the MMS FileDirResponse message. | |
| Aplazada | Alta (7.5) | 0.49% | — | Mz-automation Libiec1850AI | 15/11/2024 | 17/6/2026 | NULL pointer dereference in the MMS Client in MZ Automation LibIEC1850 before commit 7afa40390b26ad1f4cf93deaa0052fe7e357ef33 allows a malicious server to Cause a Denial-of-Service via the MMS InitiationResponse message. | |
| Aplazada | Alta (7.1) | 0.27% | — | Wojciechborowicz Conversion-helperAI | 9/11/2024 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in wojciechborowicz Conversion Helper conversion-helper allows Reflected XSS.This issue affects Conversion Helper: from n/a through <= 1.12. | |
| Analizada | Media (6.9) | 0.39% | — | Jgniecki Minecraft Motd Parser | 4/10/2024 | 17/6/2026 | Minecraft MOTD Parser is a PHP library to parse minecraft server motd. The HtmlGenerator class is subject to potential cross-site scripting (XSS) attack through a parsed malformed Minecraft server MOTD. The HtmlGenerator iterates through objects of MotdItem that are contained in an object of MotdItemCollection to… | |
| Analizada | Alta (7.5) | 0.44% | — | Trianglemicroworks IEC 61850 Source Code LibrarySiemens Sicam A8000 FirmwareSiemens Sicam SCC FirmwareSiemens Sicam EGS Firmware+2 | 18/9/2024 | 17/6/2026 | Triangle Microworks TMW IEC 61850 Client source code libraries before 12.2.0 lack a buffer size check when processing received messages. The resulting buffer overflow can cause a crash, resulting in a denial of service. | |
| Aplazada | Alta (8.2) | 0.45% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Media (5.9) | 0.43% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Aplazada | Alta (8.2) | 0.45% | — | Siemens Simatic CP 1242-7 V2AISiemens Simatic CP 1243-1AISiemens Simatic CP 1243-1 Dnp3AISiemens Simatic CP 1243-1 IECAI+8 | 10/9/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.5.20), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions <… | |
| Modificada | Alta (7.4) | 0.25% | — | Mz-automation Libiec61850 | 11/6/2024 | 9/7/2026 | libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c. | |
| Analizada | Alta (7.5) | 0.74% | — | Mz-automation Libiec61850 | 21/3/2024 | 17/6/2026 | In mz-automation libiec61850 v1.4.0, a NULL Pointer Dereference was detected in the mmsServer_handleFileCloseRequest.c function of src/mms/iso_mms/server/mms_file_service.c. The vulnerability manifests as SEGV and causes the application to crash | |
| Analizada | Alta (7.5) | 0.78% | — | Mz-automation Libiec61850 | 13/3/2024 | 17/6/2026 | An issue in mz-automation libiec61850 v.1.5.3 and before, allows a remote attacker to cause a denial of service (DoS) via the mmsServer_handleDeleteNamedVariableListRequest function of src/mms/iso_mms/server/mms_named_variable_list_service.c. | |
| Analizada | Media (6.2) | 0.87% | — | Mz-automation Libiec61850 | 20/2/2024 | 17/6/2026 | Buffer Overflow vulnerability in mz-automation.de libiec61859 v.1.4.0 allows a remote attacker to cause a denial of service via the mmsServer_handleGetNameListRequest function to the mms_getnamelist_service component. | |
| Modificada | Alta (8.2) | 0.60% | — | Geniecompany Aladdin Connect Garage Door Opener Firmware | 3/1/2024 | 17/6/2026 | Unauthenticated access permitted to web interface page The Genie Company Aladdin Connect (Retrofit-Kit Model ALDCM) "Garage Door Control Module Setup" and modify the Garage door's SSID settings. | |
| Modificada | Alta (8.8) | 0.55% | — | Geniecompany Aladdin Connect Garage Door Opener Firmware | 3/1/2024 | 17/6/2026 | When the Genie Company Aladdin Connect garage door opener (Retrofit-Kit Model ALDCM) is placed into configuration mode the web servers “Garage Door Control Module Setup” page is vulnerable to XSS via a broadcast SSID name containing malicious code with client side Java Script and/or HTML. This allows the attacker to… | |
| Modificada | Media (6.8) | 0.42% | — | Geniecompany Aladdin Connect | 3/1/2024 | 17/6/2026 | Users’ product account authentication data was stored in clear text in The Genie Company Aladdin Connect Mobile Application Version 5.65 Build 2075 (and below) on Android Devices. This allows the attacker, with access to the android device, to potentially retrieve users' clear text authentication credentials. | |
| Modificada | Alta (8.7) | 0.96% | — | Siemens 6gk7243-8rx30-0xe0 FirmwareSiemens 6gk7543-1ax00-0xe0 FirmwareSiemens 6ag1543-1ax00-2xe0 FirmwareSiemens Simatic CP 1242-7 V2 Firmware+5 | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.91% | — | Mz-automation Libiec61850 | 13/4/2023 | 17/6/2026 | libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c. | |
| Modificada | Alta (7.5) | 0.95% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Alta (7.5) | 0.72% | — | Siemens Simatic CP 1242-7 V2 FirmwareSiemens Simatic CP 1243-1 FirmwareSiemens Simatic CP 1243-1 Dnp3 FirmwareSiemens Simatic CP 1243-1 IEC Firmware+20 | 11/4/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (6GK7242-7KX31-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 (6GK7243-1BX30-0XE0) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… |