Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.4) | 0.42% | — | Siemens Climatix Pol909 Firmware | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Climatix POL909 (AWB module) (All versions < V11.42), Climatix POL909 (AWM module) (All versions < V11.34). The web server of affected devices transmits data without TLS encryption. This could allow an unauthenticated remote attacker in a man-in-the-middle position to read… | |
| Modificada | Media (6.1) | 0.66% | — | Siemens Climatix Pol908 FirmwareSiemens Climatix Pol909 Firmware | 14/4/2020 | 17/6/2026 | A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (All versions < V11.32). A persistent cross-site scripting (XSS) vulnerability exists in the web server access log page of the affected devices that could allow an attacker to inject arbitrary… | |
| Modificada | Media (6.1) | 0.66% | — | Siemens Climatix Pol908 FirmwareSiemens Climatix Pol909 Firmware | 14/4/2020 | 17/6/2026 | A vulnerability has been identified in Climatix POL908 (BACnet/IP module) (All versions), Climatix POL909 (AWM module) (All versions < V11.32). A persistent cross-site scripting (XSS) vulnerability exists in the "Server Config" web interface of the affected devices that could allow an attacker to inject arbitrary… | |
| Modificada | Alta (7.8) | 1.2% | — | Schneider-electric Proclima | 15/7/2019 | 17/6/2026 | A CWE-427: Uncontrolled Search Path Element vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow a malicious DLL file, with the same name of any resident DLLs inside the software installation, to execute arbitrary code in all versions of ProClima prior to version 8.0.0. | |
| Modificada | Crítica (9.8) | 4.5% | — | Schneider-electric Proclima | 15/7/2019 | 17/6/2026 | A CWE-119: Buffer Errors vulnerability exists in ProClima (all versions prior to version 8.0.0) which allows an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0. | |
| Modificada | Crítica (9.8) | 5.0% | — | Schneider-electric Proclima | 15/7/2019 | 17/6/2026 | A CWE-94: Code Injection vulnerability exists in ProClima (all versions prior to version 8.0.0) which could allow an unauthenticated, remote attacker to execute arbitrary code on the targeted system in all versions of ProClima prior to version 8.0.0. | |
| Modificada | Media (6.8) | 3.8% | — | Schneider-electric Proclima | 15/12/2015 | 17/6/2026 | The F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allows remote attackers to execute arbitrary code or cause a denial of service (memory corruption) via a crafted integer value to the (1) AttachToSS, (2) CopyAll, (3) CopyRange, (4) CopyRangeEx, or (5) SwapTable method, a different… | |
| Modificada | Media (6.8) | 5.7% | — | Schneider-electric Proclima | 15/12/2015 | 17/6/2026 | Multiple buffer overflows in the F1BookView ActiveX control in F1 Bookview in Schneider Electric ProClima before 6.2 allow remote attackers to execute arbitrary code via the (1) Attach, (2) DefinedName, (3) DefinedNameLocal, (4) ODBCPrepareEx, (5) ObjCreatePolygon, (6) SetTabbedTextEx, or (7) SetValidationRule method,… | |
| Modificada | Media (4.3) | 2.5% | — | Siemens Climatix Bacnet/ip | 28/6/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the integrated web server on the Siemens Climatix BACnet/IP communication module with firmware before 10.34 allows remote attackers to inject arbitrary web script or HTML via a crafted URL. | |
| Modificada | Alta (9) | 6.3% | — | Schneider Electric Proclima | 27/12/2014 | 17/6/2026 | Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-8514. NOTE: this may be clarified later based on details provided by researchers. | |
| Modificada | Alta (7.5) | 4.0% | — | Schneider Electric Proclima | 27/12/2014 | 17/6/2026 | Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8513 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers. | |
| Modificada | Alta (7.5) | 2.9% | — | Schneider Electric Proclima | 27/12/2014 | 17/6/2026 | Buffer overflow in an ActiveX control in MDraw30.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8514 and CVE-2014-9188. NOTE: this may be clarified later based on details provided by researchers. | |
| Modificada | Alta (7.5) | 3.9% | — | Schneider Electric Proclima | 27/12/2014 | 17/6/2026 | Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8511. NOTE: this may be clarified later based on details provided by researchers. | |
| Modificada | Alta (10) | 4.4% | — | Schneider-electric Proclima | 27/12/2014 | 17/6/2026 | Buffer overflow in an ActiveX control in Atx45.ocx in Schneider Electric ProClima before 6.1.7 allows remote attackers to execute arbitrary code via unspecified vectors, a different vulnerability than CVE-2014-8512. NOTE: this may be clarified later based on details provided by researchers. | |
| Modificada | Media (6.8) | 3.6% | — | JUN Furuse Camlimages | 4/8/2009 | 16/6/2026 | Multiple integer overflows in CamlImages 2.2 might allow context-dependent attackers to execute arbitrary code via images containing large width and height values that trigger a heap-based buffer overflow, related to (1) crafted GIF files (gifread.c) and (2) crafted JPEG files (jpegread.c), a different vulnerability… | |
| Modificada | Alta (7.5) | 2.6% | — | JUN Furuse Camlimages | 5/7/2009 | 16/6/2026 | Multiple integer overflows in CamlImages 2.2 and earlier might allow context-dependent attackers to execute arbitrary code via a crafted PNG image with large width and height values that trigger a heap-based buffer overflow in the (1) read_png_file or (2) read_png_file_as_rgb24 function. |