Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
130 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.52% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 FirmwareRockwellautomation Compactlogix 5480 FirmwareRockwellautomation Controllogix 5580 Firmware+2 | 8/10/2024 | 17/6/2026 | Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to… | |
| Analizada | Alta (8.7) | 0.56% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 3 FirmwareRockwellautomation Compactlogix 5480 Firmware+3 | 12/9/2024 | 17/6/2026 | A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover. | |
| Aplazada | Media (5.9) | 0.40% | — | KepwareAIRockwellautomation ControllogixAI | 16/8/2024 | 17/6/2026 | When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could deliver a response leading to unrestricted or unregulated resource allocation. This could cause a denial-of-service condition and crash the… | |
| Analizada | Alta (8.7) | 0.52% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 Firmware+2 | 14/8/2024 | 17/6/2026 | CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller. | |
| Analizada | Alta (8.7) | 0.50% | — | Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 Firmware+2 | 14/8/2024 | 17/6/2026 | CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller. | |
| Analizada | Alta (8.7) | 0.58% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 Firmware | 14/8/2024 | 17/6/2026 | CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service. | |
| Aplazada | Alta (7.3) | 11% | — | Rockwellautomation ControllogixAIRockwellautomation 1756AI | 1/8/2024 | 17/6/2026 | A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device… | |
| Analizada | Alta (8.3) | 0.31% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation 1756-en4 FirmwareRockwellautomation Compactlogix 5380 Firmware+2 | 14/6/2024 | 17/6/2026 | Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised. | |
| Aplazada | Crítica (9.8) | 0.54% | — | Glowlogix WP Frontend ProfileAI | 17/5/2024 | 17/6/2026 | Improper Privilege Management vulnerability in Glowlogix WP Frontend Profile allows Privilege Escalation.This issue affects WP Frontend Profile: from n/a through 1.3.1. | |
| Aplazada | Media (6.8) | 0.62% | — | Agilelogix Store LocatorAI | 18/4/2024 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in AGILELOGIX Store Locator WordPress.This issue affects Store Locator WordPress: from n/a through 1.4.14. | |
| Analizada | Alta (7.5) | 0.64% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 Firmware+4 | 15/4/2024 | 17/6/2026 | A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will… | |
| Aplazada | Baja (3.5) | 0.42% | — | Smartlogix Wp-insertAI | 8/4/2024 | 17/6/2026 | A vulnerability was found in namithjawahar Wp-Insert up to 2.0.8 and classified as problematic. Affected by this issue is some unknown functionality. The manipulation leads to cross site scripting. The attack may be launched remotely. Upgrading to version 2.0.9 is able to address this issue. The name of the patch is… | |
| Modificada | Alta (7.5) | 0.65% | — | Rockwellautomation Controllogix 5570 Controller FirmwareRockwellautomation Guardlogix 5570 Controller FirmwareRockwellautomation Controllogix 5570 Redundant Controller Firmware | 31/1/2024 | 17/6/2026 | A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could potentially experience a major nonrecoverable fault (MNRF). The device will restart itself to recover from the MNRF. | |
| Modificada | Crítica (9.1) | 0.56% | — | Magiclogix Msync | 20/12/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Magic Logix MSync.This issue affects MSync: from n/a through 1.0.0. | |
| Modificada | Media (6.1) | 0.76% | — | Agilelogix Post Timeline | 4/9/2023 | 17/6/2026 | The Post Timeline WordPress plugin before 2.2.6 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (6.1) | 0.69% | — | Agilelogix Store Locator | 4/9/2023 | 17/6/2026 | The Store Locator WordPress plugin before 1.4.13 does not sanitise and escape an invalid nonce before outputting it back in an AJAX response, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin | |
| Modificada | Media (4.8) | 0.40% | — | Agilelogix Store Locator | 22/6/2023 | 17/6/2026 | Auth. (editor+) Stored Cross-Site Scripting (XSS) vulnerability in AGILELOGIX Store Locator WordPress plugin <= 1.4.9 versions. | |
| Modificada | Media (4.8) | 0.37% | — | Smartlogix Wp-insert | 25/4/2023 | 17/6/2026 | Auth. (admin+) Stored Cross-Site Scripting (XSS) vulnerability in namithjawahar Wp-Insert plugin <= 2.5.0 versions. | |
| Modificada | Media (5.4) | 0.47% | — | Agilelogix Store Locator | 23/1/2023 | 17/6/2026 | The Store Locator WordPress plugin before 1.4.9 does not validate and escape some of its shortcode attributes before outputting them back in the page, which could allow users with a role as low as contributor to perform Stored Cross-Site Scripting attacks which could be used against high privilege users such as admins. | |
| Modificada | Alta (7.8) | 0.37% | — | Rockwellautomation Studio 5000 Logix Emulate | 27/12/2022 | 17/6/2026 | A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted… | |
| Modificada | Alta (7.5) | 1.3% | — | Rockwellautomation Compactlogix 5480 FirmwareRockwellautomation Compactlogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compact Guardlogix 5380 Firmware+1 | 19/12/2022 | 17/6/2026 | An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a major non-recoverable fault. If the target device becomes unavailable, a user would have to clear the… | |
| Modificada | Media (6.1) | 0.56% | — | Rockwellautomation Micrologix 1400 FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400-b FirmwareRockwellautomation Micrologix 1400-c Firmware+1 | 16/12/2022 | 17/6/2026 | Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site… | |
| Modificada | Alta (7.5) | 1.5% | — | Rockwellautomation Compactlogix 5370 FirmwareRockwellautomation Compact Guardlogix 5370 FirmwareRockwellautomation Compact Guardlogix 5380 FirmwareRockwellautomation Controllogix 5570 Firmware+2 | 16/12/2022 | 17/6/2026 | A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS). | |
| Modificada | Alta (7.5) | 0.70% | — | Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware | 16/12/2022 | 17/6/2026 | Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and… | |
| Modificada | Media (6.1) | 0.25% | — | Agilelogix Store Locator | 18/11/2022 | 17/6/2026 | Cross-Site Scripting (XSS) via Cross-Site Request Forgery (CSRF) vulnerability in Store Locator plugin <= 1.4.5 on WordPress. |