Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
42 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Myscada Mypro | 23/12/2021 | 17/6/2026 | An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization. | |
| Modificada | Crítica (9.8) | 1.2% | — | Myscada Mypro | 23/12/2021 | 17/6/2026 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Myscada Mypro | 23/12/2021 | 17/6/2026 | mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Myscada Mypro | 23/12/2021 | 17/6/2026 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | |
| Modificada | Crítica (9.8) | 1.2% | — | Myscada Mypro | 23/12/2021 | 17/6/2026 | mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter. | |
| Modificada | Alta (7.4) | 0.49% | — | Siemens Sinumerik Analyse Mycondition FirmwareSiemens Sinumerik Analyze Myperformance FirmwareSiemens Sinumerik Integrate Client FirmwareSiemens Sinumerik Integrate FOR Production Firmware+6 | 13/7/2021 | 17/6/2026 | A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 <… | |
| Modificada | Alta (7.5) | 2.0% | — | Myprolyz Project Myprolyz | 7/6/2018 | 17/6/2026 | myprolyz is a static file server. myprolyz is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url. | |
| Modificada | Media (5.3) | 2.1% | 💥 PoC | Myscada Mypro | 28/5/2018 | 17/6/2026 | mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010. | |
| Modificada | Crítica (9.1) | 15% | 💥 Exploit | Myscada Mypro | 20/5/2018 | 17/6/2026 | A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials. | |
| Modificada | Crítica (9.9) | 3.7% | — | Mybiz Myprocurenet | 14/5/2018 | 17/6/2026 | An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker to upload a script to issue operating system commands. This vulnerability occurs because an attacker is able to adjust the… | |
| Modificada | Media (6.1) | 0.69% | — | Mybiz Myprocurenet | 14/5/2018 | 17/6/2026 | An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site. | |
| Modificada | Alta (7.8) | 0.73% | — | Myscada Mypro | 6/10/2017 | 17/6/2026 | An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize unquoted search path elements, which could allow an attacker to execute arbitrary code with elevated privileges. | |
| Modificada | Media (4.3) | 1.6% | — | Ncsa MyproxyGlobus Toolkit | 2/2/2011 | 16/6/2026 | MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a)… | |
| Modificada | Media (6.8) | 1.2% | — | Phpmyprofiler | 26/9/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in include/plugin/block.t.php in Peter Schmidt phpmyProfiler 0.9.6b allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. NOTE: this issue is disputed by CVE because the applicable require_once is in a function that is not called on a… | |
| Modificada | Media (5.1) | 4.0% | 💥 Exploit | Phpmyprofiler | 10/10/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. | |
| Modificada | Media (4.6) | 2.1% | — | Myproxy | 31/12/2004 | 16/6/2026 | MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command. | |
| Modificada | Media (6.8) | 2.2% | 💥 Exploit | Myproxy | 11/3/2004 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL. |