Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 85 respecto a la semana anterior
Críticas / altas1403▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.1)0.85%—Ksix Zigbee Gateway ModuleAIKsix Door SensorAIKsix Motion SensorAI15/4/202517/6/2026
A replay attack vulnerability was discovered in a Zigbee smart home kit manufactured by Ksix (Zigbee Gateway Module = v1.0.3, Door Sensor = v1.0.7, Motion Sensor = v1.0.12), where the Zigbee anti-replay mechanism - based on the frame counter field - is improperly implemented. As a result, an attacker within wireless…
AplazadaMedia (5.3)0.63%—Comotion Course Booking SystemAI4/4/202517/6/2026
Missing Authorization vulnerability in ComMotion Course Booking System course-booking-system allows Accessing Functionality Not Properly Constrained by ACLs.This issue affects Course Booking System: from n/a through <= 6.1.
AplazadaAlta (7.1)0.39%—Emotionalonlinestorytelling Oracle Cards LiteAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in emotionalonlinestorytelling Oracle Cards Lite oracle-cards allows Reflected XSS.This issue affects Oracle Cards Lite: from n/a through <= 1.2.1.
AplazadaCrítica (9.3)2.9%—Commotion Course Booking SystemAI15/1/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in ComMotion Course Booking System course-booking-system allows SQL Injection.This issue affects Course Booking System: from n/a through <= 6.0.6.
AplazadaAlta (7)0.18%—Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic Step 7 SafetyAISiemens Simatic WinccAI+810/12/202417/6/2026
A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC S7-PLCSIM V18 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4), SIMATIC STEP 7 V17 (All versions < V17 Update…
AplazadaAlta (8.4)0.22%—Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+710/12/202417/6/2026
A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 9), SIMATIC STEP 7 Safety V18 (All versions), SIMATIC STEP 7 Safety V19 (All versions < V19 Update 4),…
AplazadaAlta (8.4)0.49%—B&R Mapp CockpitAIB&R Mapp ViewAIB&R Mapp ServicesAIB&R Mapp MotionAI+12/12/202417/6/2026
An “Authentication Bypass Using an Alternate Path or Channel” vulnerability in the OPC UA Server configuration required for B&R mapp Cockpit before 6.0, B&R mapp View before 6.0, B&R mapp Services before 6.0, B&R mapp Motion before 6.0 and B&R mapp Vision before 6.0 may be used by an unauthenticated network-based…
AplazadaAlta (7)0.22%—Siemens Simatic S7-plcsimAISiemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAI+712/11/202417/6/2026
A vulnerability has been identified in SIMATIC S7-PLCSIM V16 (All versions), SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 Safety V16 (All versions), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 8), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 5), SIMATIC STEP 7 V16 (All versions), SIMATIC STEP…
AplazadaMedia (5.4)0.32%—Creative Motion Clearfy CacheAI1/11/202417/6/2026
Missing Authorization vulnerability in Creative Motion Clearfy Cache allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Clearfy Cache: from n/a through 2.2.4.
AplazadaMedia (4.3)0.39%—Creativemotion Social Slider FeedAI1/11/202417/6/2026
Missing Authorization vulnerability in creativemotion Social Slider Feed allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Social Slider Feed: from n/a through 2.2.2.
AplazadaMedia (6.5)0.50%—Creative Motion Robin Image OptimizerAI1/11/202417/6/2026
Missing Authorization vulnerability in Creative Motion Robin image optimizer allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Robin image optimizer: from n/a through 1.6.9.
AplazadaMedia (6.5)0.49%—Creativemotion Titan Anti-spam SecurityAI1/11/202417/6/2026
Missing Authorization vulnerability in CreativeMotion Titan Anti-spam & Security allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Titan Anti-spam & Security: from n/a through 7.3.6.
AplazadaAlta (7)0.21%—Siemens Simatic Step 7 SafetyAISiemens Simatic Step 7AISiemens Simatic Wincc UnifiedAISiemens Simatic WinccAI+79/7/202417/6/2026
A vulnerability has been identified in SIMATIC STEP 7 Safety V16 (All versions < V16 Update 7), SIMATIC STEP 7 Safety V17 (All versions < V17 Update 7), SIMATIC STEP 7 Safety V18 (All versions < V18 Update 2), SIMATIC STEP 7 V16 (All versions < V16 Update 7), SIMATIC STEP 7 V17 (All versions < V17 Update 7), SIMATIC…
AplazadaMedia (4.3)0.19%—Creative Motion Clearfy CacheAI17/5/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Creative Motion Clearfy Cache.This issue affects Clearfy Cache: from n/a through 2.2.1.
ModificadaAlta (7.5)0.54%—Seweurodrive Movitools Motionstudio1/2/202417/6/2026
When SEW-EURODRIVE MOVITOOLS MotionStudio processes XML information unrestricted file access can occur.
ModificadaAlta (7.8)0.26%—Mitsubishielectric GX Works3Mitsubishielectric Melsoft IQ AppportalMitsubishielectric Melsoft NavigatorMitsubishielectric Motion Control Setting30/11/202317/6/2026
Malicious Code Execution Vulnerability due to External Control of File Name or Path in multiple Mitsubishi Electric FA Engineering Software Products allows a malicious attacker to execute a malicious code by having legitimate users open a specially crafted project file, which could result in information disclosure,…
ModificadaMedia (4.6)0.28%—Siemens Simotion D425-2 DP FirmwareSiemens Simotion D425-2 Dp/pn FirmwareSiemens Simotion D435-2 DP FirmwareSiemens Simotion D435-2 Dp/pn Firmware+913/6/202317/6/2026
A vulnerability has been identified in SIMOTION C240 (All versions >= V5.4 < V5.5 SP1), SIMOTION C240 PN (All versions >= V5.4 < V5.5 SP1), SIMOTION D410-2 DP (All versions >= V5.4 < V5.5 SP1), SIMOTION D410-2 DP/PN (All versions >= V5.4 < V5.5 SP1), SIMOTION D425-2 DP (All versions >= V5.4 < V5.5 SP1), SIMOTION…
ModificadaAlta (7.8)0.31%—Genymotion Desktop13/2/202317/6/2026
Genymotion Desktop v3.3.2 was discovered to contain a DLL hijacking vulnerability that allows attackers to escalate privileges and execute arbitrary code via a crafted DLL.
ModificadaMedia (5.5)0.21%—Omron Cx-motion PRO30/1/202317/6/2026
Improper restriction of XML external entity reference (XXE) vulnerability exists in OMRON CX-Motion Pro 1.4.6.013 and earlier. If a user opens a specially crafted project file created by an attacker, sensitive information in the file system where CX-Motion Pro is installed may be disclosed.
ModificadaAlta (7.8)0.20%—Omron Cx-motion-mch Firmware17/1/202317/6/2026
CX-Motion-MCH v2.32 and earlier contains an access of uninitialized pointer vulnerability. Having a user to open a specially crafted project file may lead to information disclosure and/or arbitrary code execution.
ModificadaMedia (6.5)0.89%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs26/12/202217/6/2026
In Philips (formerly Carestream) Vue MyVue PACS through 12.2.x.x, the VideoStream function allows Path Traversal by authenticated users to access files stored outside of the web root.
ModificadaMedia (5.5)0.23%—Pilz PAS 4000Pliz PascalPliz PasconnectPliz Pasmotion+124/11/202217/6/2026
A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability.
ModificadaAlta (7.5)0.69%—Softmotions Iowow21/10/202217/6/2026
IOWOW is a C utility library and persistent key/value storage engine. Versions 1.4.15 and prior contain a stack buffer overflow vulnerability that allows for Denial of Service (DOS) when it parses scientific notation numbers present in JSON. A patch for this issue is available at commit…
ModificadaAlta (7.8)0.25%—Genymobile Genymotion Desktop13/9/202217/6/2026
Genymotion Desktop v3.2.1 was discovered to contain a DLL hijacking vulnerability which allows attackers to escalate privileges and execute arbitrary code via a crafted binary.
ModificadaAlta (7.5)1.2%—Rice Open Motion Planning Library17/6/202217/6/2026
Memory leaks in LazyPRM.cpp of OMPL v1.5.0 can cause unexpected behavior.