Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 64% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition ParameterVersionJavaSerializationCodec Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is not required to exploit this… | |
| Analizada | Alta (8.8) | 0.62% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition downloadLaunchClientJar Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must connect to a… | |
| Analizada | Alta (8.8) | 62% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition AbstractGatewayFunction Deserialization of Untrusted Data Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The… | |
| Analizada | Media (6.5) | 1.3% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition SimpleXMLReader XML External Entity Processing Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability. The… | |
| Analizada | Alta (8.8) | 60% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition OPC UA Quick Client Task Scheduling Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Authentication is required to exploit this vulnerability.… | |
| Analizada | Alta (8.8) | 1.2% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition OPC UA Quick Client Missing Authentication for Critical Function Authentication Bypass Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability… | |
| Analizada | Alta (7.2) | 1.9% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition OPC UA Quick Client Permissive Cross-domain Policy Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. Although authentication is required to exploit this vulnerability, the… | |
| Analizada | Crítica (9) | 1.2% | — | Inductiveautomation Ignition | 3/5/2024 | 17/6/2026 | Inductive Automation Ignition OPC UA Quick Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition. User interaction is required to exploit this vulnerability in that the target must… | |
| Modificada | Alta (8.8) | 0.24% | — | Saleswonder Webinarignition | 15/4/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Saleswonder Team: Tobias WebinarIgnition webinar-ignition.This issue affects WebinarIgnition: from n/a through <= 3.05.8. | |
| Modificada | Crítica (9.8) | 0.57% | — | Saleswonder Webinarignition | 31/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream &… | |
| Modificada | Alta (8.8) | 0.62% | — | Saleswonder Webinarignition | 29/12/2023 | 17/6/2026 | Deserialization of Untrusted Data vulnerability in Saleswonder Team Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition.This issue affects Webinar Plugin: Create live/evergreen/automated/instant webinars, stream & Zoom Meetings | WebinarIgnition: from n/a through… | |
| Analizada | Media (4.8) | 0.39% | — | Saleswonder Webinarignition | 7/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in Saleswonder.Biz Webinar ignition plugin <= 2.14.2 versions. | |
| Modificada | Crítica (9.8) | 1.0% | — | Inductiveautomation Ignition | 5/8/2022 | 17/6/2026 | Due to an XML external entity reference, the software parses XML in the backup/restore functionality without XML security flags, which may lead to a XXE attack while restoring the backup. | |
| Modificada | Alta (7.8) | 0.71% | — | Inductiveautomation Ignition | 25/7/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 0.70% | — | Inductiveautomation Ignition | 25/7/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The specific flaw exists within the… | |
| Modificada | Alta (7.8) | 39% | — | Inductiveautomation Ignition | 25/7/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within the authenticateAdSso method. The issue results from the lack of… | |
| Modificada | Alta (7.8) | 43% | — | Inductiveautomation Ignition | 25/7/2022 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Although authentication is required to exploit this vulnerability, the existing authentication mechanism can be bypassed. The specific flaw exists within… | |
| Modificada | Crítica (9.8) | 60% | — | Inductiveautomation Ignition | 25/7/2022 | 17/6/2026 | This vulnerability allows remote attackers to bypass authentication on affected installations of Inductive Automation Ignition 8.1.15 (b2022030114). Authentication is not required to exploit this vulnerability. The specific flaw exists within com.inductiveautomation.ignition.gateway.web.pages. The issue results from… | |
| Modificada | Alta (8.8) | 0.97% | — | Inductiveautomation Ignition | 20/7/2022 | 17/6/2026 | The affected product may allow an attacker with access to the Ignition web configuration to run arbitrary code. | |
| Modificada | Alta (7.2) | 2.7% | — | Inductiveautomation Ignition | 16/7/2022 | 17/6/2026 | An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. The ScriptInvoke function allows remote attackers to execute arbitrary code by supplying a Python script. | |
| Modificada | Crítica (9.8) | 2.0% | — | Inductiveautomation Ignition | 15/7/2022 | 17/6/2026 | An issue was discovered in Inductive Automation Ignition before 7.9.20 and 8.x before 8.1.17. Designer and Vision Client Session IDs are mishandled. An attacker can determine which session IDs were generated in the past and then hijack sessions assigned to these IDs via Randy. | |
| Modificada | Media (6.5) | 1.3% | — | Redhat IgnitionRedhat Openshift Container PlatformRedhat Enterprise LinuxFedoraproject Fedora | 17/5/2022 | 17/6/2026 | A vulnerability was found in Ignition where ignition configs are accessible from unprivileged containers in VMs running on VMware products. This issue is only relevant in user environments where the Ignition config contains secrets. The highest threat from this vulnerability is to data confidentiality. Possible… | |
| Modificada | Media (5.3) | 0.89% | — | Inductiveautomation Ignition | 1/4/2022 | 17/6/2026 | Sensitive information can be obtained through the handling of serialized data. The issue results from the lack of proper authentication required to query the server | |
| Modificada | Crítica (9.8) | 1.7% | — | Facade Ignition | 17/11/2021 | 17/6/2026 | The Ignition component before 1.16.15, and 2.0.x before 2.0.6, for Laravel has a "fix variable names" feature that can lead to incorrect access control. | |
| Modificada | Crítica (9.1) | 3.9% | — | Thrivethemes FocusblogThrivethemes IgnitionThrivethemes LuxeThrivethemes Minus+6 | 12/4/2021 | 17/6/2026 | Thrive “Legacy” Rise by Thrive Themes WordPress theme before 2.0.0, Luxe by Thrive Themes WordPress theme before 2.0.0, Minus by Thrive Themes WordPress theme before 2.0.0, Ignition by Thrive Themes WordPress theme before 2.0.0, FocusBlog by Thrive Themes WordPress theme before 2.0.0, Squared by Thrive Themes… |