Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

35 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.2)13%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+217/8/202217/6/2026
The “restore configuration” feature of Softing Secure Integration Server V1.22 is vulnerable to a directory traversal vulnerability when processing zip files. An attacker can craft a zip file to load an arbitrary dll and execute code. Using the "restore configuration" feature to upload a zip file containing a path…
ModificadaAlta (7.5)1.5%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPCSofting OPC UA C++ Software Development KIT+217/8/202217/6/2026
A crafted HTTP packet with a large content-length header can create a denial-of-service condition in Softing Secure Integration Server V1.22.
ModificadaAlta (7.5)0.96%—Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server11/3/202217/6/2026
An issue was discovered in Softing OPC UA C++ SDK before 5.70. A malformed OPC/UA message abort packet makes the client crash with a NULL pointer dereference.
ModificadaMedia (6.5)0.83%—Softing Datafeed OPC SuiteSofting OPC UA C++ Software Development KITSofting Secure Integration Server11/3/202217/6/2026
An issue was discovered in Softing OPC UA C++ SDK before 5.70. An invalid XML element in the type dictionary makes the OPC/UA client crash due to an out-of-memory condition.
ModificadaAlta (7.5)1.3%—Softing Datafeed OPC SuiteSofting EdgeconnectorSofting OPCSofting Secure Integration Server+310/11/202117/6/2026
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted.
ModificadaAlta (7.5)1.3%—Softing Datafeed OPC SuiteSofting OPCSofting Secure Integration ServerSofting TH Scope10/11/202117/6/2026
An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a OPC/UA client. The client process may crash unexpectedly because of a wrong type cast, and must be restarted.
AnalizadaAlta (8.8)72%⚠ Explotación activaMicrosoft Commerce ServerMicrosoft Host Integration ServerMicrosoft OfficeMicrosoft Office WEB Components+315/8/201216/6/2026
The TabStrip ActiveX control in the Common Controls in MSCOMCTL.OCX in Microsoft Office 2003 SP3, Office 2003 Web Components SP3, Office 2007 SP2 and SP3, Office 2010 SP1, SQL Server 2000 SP4, SQL Server 2005 SP4, SQL Server 2008 SP2, SP3, R2, R2 SP1, and R2 SP2, Commerce Server 2002 SP4, Commerce Server 2007 SP2,…
ModificadaMedia (5)21%—Microsoft Host Integration Server12/10/201116/6/2026
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Access of Unallocated Memory DoS Vulnerability."
ModificadaMedia (5)23%—Microsoft Host Integration Server12/10/201116/6/2026
Microsoft Host Integration Server (HIS) 2004 SP1, 2006 SP1, 2009, and 2010 allows remote attackers to cause a denial of service (SNA Server service outage) via crafted TCP or UDP traffic, aka "Endless Loop DoS in snabase.exe Vulnerability."
ModificadaAlta (10)78%—Microsoft Host Integration Server 2000Microsoft Host Integration Server 2004Microsoft Host Integration Server 200615/10/200816/6/2026
Microsoft Host Integration Server (HIS) 2000, 2004, and 2006 does not limit RPC access to administrative functions, which allows remote attackers to bypass authentication and execute arbitrary programs via a crafted SNA RPC message using opcode 1 or 6 to call the CreateProcess function, aka "HIS Command Execution…