Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3034▼ 62 respecto a la semana anterior
Críticas / altas1427▲ 61 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
71 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.5% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP ACK message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions.… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). The DHCP client application does not validate the length of the Domain Name Server IP option(s) (0x06) when processing DHCP ACK packets. This may lead to… | |
| Modificada | Alta (7.5) | 1.5% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP OFFER message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions.… | |
| Modificada | Crítica (9.1) | 2.0% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+7 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). The total length of an ICMP payload… | |
| Modificada | Crítica (9.1) | 1.6% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+6 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information… | |
| Modificada | Media (6.9) | 1.5% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+7 | 9/11/2021 | 17/6/2026 | A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). ICMP echo packets with fake IP… | |
| Modificada | Crítica (9.8) | 3.4% | — | Siemens Apogee MBC (ppc) (P2 Ethernet) FirmwareSiemens Apogee MEC (ppc) (P2 Ethernet) FirmwareSiemens Apogee PXC Bacnet Automation Controller FirmwareSiemens Apogee PXC Compact (P2 Ethernet) Firmware+4 | 14/9/2021 | 17/6/2026 | A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3),… | |
| Modificada | Alta (8.8) | 0.75% | — | Dell Openmanage EnterpriseDell Openmanage Enterprise-modular | 9/8/2021 | 17/6/2026 | Dell OpenManage Enterprise versions 3.4 through 3.6.1 and Dell OpenManage Enterprise Modular versions 1.20.00 through 1.30.00, contain a remote code execution vulnerability. A malicious attacker with access to the immediate subnet may potentially exploit this vulnerability leading to information disclosure and a… | |
| Modificada | Media (6.5) | 0.81% | — | Dell Openmanage EnterpriseDell Openmanage Enterprise-modular | 9/8/2021 | 17/6/2026 | Dell OpenManage Enterprise version 3.5 and OpenManage Enterprise-Modular version 1.30.00 contain an information disclosure vulnerability. An authenticated low privileged attacker may potentially exploit this vulnerability leading to disclosure of the OIDC server credentials. | |
| Modificada | Alta (8.1) | 1.0% | — | Dell EMC Openmanage EnterpriseDell EMC Openmanage Enterprise-modular | 19/7/2021 | 17/6/2026 | Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an injection vulnerability. A remote authenticated malicious user with low privileges could potentially exploit this vulnerability to gain access to sensitive information or cause… | |
| Modificada | Crítica (9.1) | 2.3% | — | Dell EMC Openmanage Enterprise-modular | 19/7/2021 | 17/6/2026 | Dell EMC OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a command injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit the vulnerability to execute arbitrary shell commands on the affected system. | |
| Modificada | Alta (7.6) | 0.94% | — | Dell EMC Openmanage EnterpriseDell EMC Openmanage Enterprise-modular | 19/7/2021 | 17/6/2026 | Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain an improper input validation vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to spawn tasks with elevated… | |
| Modificada | Alta (7.2) | 0.93% | — | Dell EMC Openmanage EnterpriseDell EMC Openmanage Enterprise-modular | 19/7/2021 | 17/6/2026 | Dell EMC OpenManage Enterprise (OME) versions prior to 3.2 and OpenManage Enterprise-Modular (OME-M) versions prior to 1.10.00 contain a SQL injection vulnerability. A remote authenticated malicious user with high privileges could potentially exploit this vulnerability to execute SQL commands to perform unauthorized… | |
| Modificada | Alta (7.5) | 1.6% | — | Hitachienergy Relion 670 FirmwareHitachienergy Relion 650 FirmwareHitachienergy Relion Sam600-io FirmwareHitachienergy Rtu500 Firmware+5 | 14/6/2021 | 17/6/2026 | Improper Input Validation vulnerability in Hitachi ABB Power Grids Relion 670 Series, Relion 670/650 Series, Relion 670/650/SAM600-IO, Relion 650, REB500, RTU500 Series, FOX615 (TEGO1), MSM, GMS600, PWC600 allows an attacker with access to the IEC 61850 network with knowledge of how to reproduce the attack, as well as… | |
| Modificada | Alta (8.8) | 0.92% | — | Dell Openmanage Enterprise-modular | 30/4/2021 | 17/6/2026 | Dell OpenManage Enterprise-Modular (OME-M) versions prior to 1.30.00 contain a security bypass vulnerability. An authenticated malicious user with low privileges may potentially exploit the vulnerability to escape from the restricted environment and gain access to sensitive information in the system, resulting in… | |
| Modificada | Alta (7.1) | 0.71% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus ReadystartSiemens Nucleus Safetycert+22 | 16/1/2020 | 17/6/2026 | A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8.2 < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8.2… | |
| Modificada | Alta (8.8) | 4.3% | — | Dell Idrac6 ModularDell Idrac6 Monolithic | 2/7/2018 | 17/6/2026 | The web-based diagnostics console in Dell EMC iDRAC6 (Monolithic versions prior to 2.91 and Modular all versions) contains a command injection vulnerability. A remote authenticated malicious iDRAC user with access to the diagnostics console could potentially exploit this vulnerability to execute arbitrary commands as… | |
| Modificada | Media (5.3) | 7.3% | — | Siemens Apogee PXC FirmwareSiemens Apogee PXC Modular FirmwareSiemens Talon TC Compact FirmwareSiemens Talon TC Modular Firmware | 23/10/2017 | 17/6/2026 | A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system… | |
| Modificada | Alta (7.5) | 25% | — | Siemens Apogee PXC FirmwareSiemens Apogee PXC Modular FirmwareSiemens Talon TC Compact FirmwareSiemens Talon TC Modular Firmware | 23/10/2017 | 17/6/2026 | A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device. | |
| Modificada | Alta (7.5) | 0.76% | — | Systech Syslink Sl-1000 Modular Gateway Firmware | 25/4/2016 | 17/6/2026 | SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 use the same hardcoded encryption key across different customers' installations, which allows attackers to defeat cryptographic protection mechanisms by leveraging knowledge of this key from another installation. | |
| Modificada | Alta (8.8) | 2.8% | — | Systech Syslink Sl-1000 Modular Gateway Firmware | 25/4/2016 | 17/6/2026 | flu.cgi in the web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 allows remote authenticated users to execute arbitrary commands via the 5066 (aka dnsmasq) parameter. | |
| Modificada | Crítica (9.8) | 2.5% | — | Systech Syslink Sl-1000 Modular Gateway Firmware | 25/4/2016 | 17/6/2026 | The web interface on SysLINK SL-1000 Machine-to-Machine (M2M) Modular Gateway devices with firmware before 01A.8 has a default password, which makes it easier for remote attackers to obtain access via unspecified vectors. | |
| Modificada | Crítica (9.8) | 2.4% | — | Cisco Modular Encoding Platform D9036 Software | 22/1/2016 | 17/6/2026 | Cisco Modular Encoding Platform D9036 Software before 02.04.70 has hardcoded (1) root and (2) guest passwords, which makes it easier for remote attackers to obtain access via an SSH session, aka Bug ID CSCut88070. | |
| Modificada | Media (5) | 19% | — | Dell Idrac6 ModularDell Idrac7Intel IpmiDell Idrac6 Monolithic | 19/12/2014 | 17/6/2026 | The IPMI 1.5 functionality in Dell iDRAC6 modular before 3.65, iDRAC6 monolithic before 1.98, and iDRAC7 before 1.57.57 does not properly select session ID values, which makes it easier for remote attackers to execute arbitrary commands via a brute-force attack. | |
| Modificada | Alta (9.3) | 2.3% | — | Softmotion3d SoftmotionFesto Cecx-x-m1 Modular Controller3s-software Codesys Runtime SystemFesto Cecx-x-c1 Modular Master Controller | 25/4/2014 | 17/6/2026 | The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log… |