Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

42 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.5%—Myscada Mypro23/12/202117/6/2026
An unauthenticated remote attacker can access mySCADA myPRO Versions 8.20.0 and prior without any form of authentication or authorization.
ModificadaCrítica (9.8)1.2%—Myscada Mypro23/12/202117/6/2026
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the firmware can be updated, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
ModificadaCrítica (9.8)1.2%—Myscada Mypro23/12/202117/6/2026
mySCADA myPRO: Versions 8.20.0 and prior has a feature to send emails, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
ModificadaCrítica (9.8)1.2%—Myscada Mypro23/12/202117/6/2026
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
ModificadaCrítica (9.8)1.2%—Myscada Mypro23/12/202117/6/2026
mySCADA myPRO: Versions 8.20.0 and prior has a feature where the API password can be specified, which may allow an attacker to inject arbitrary operating system commands through a specific parameter.
ModificadaAlta (7.4)0.49%—Siemens Sinumerik Analyse Mycondition FirmwareSiemens Sinumerik Analyze Myperformance FirmwareSiemens Sinumerik Integrate Client FirmwareSiemens Sinumerik Integrate FOR Production Firmware+613/7/202117/6/2026
A vulnerability has been identified in SINUMERIK Analyse MyCondition (All versions), SINUMERIK Analyze MyPerformance (All versions), SINUMERIK Analyze MyPerformance /OEE-Monitor (All versions), SINUMERIK Analyze MyPerformance /OEE-Tuning (All versions), SINUMERIK Integrate Client 02 (All versions >= V02.00.12 <…
ModificadaAlta (7.5)2.0%—Myprolyz Project Myprolyz7/6/201817/6/2026
myprolyz is a static file server. myprolyz is vulnerable to a directory traversal issue, giving an attacker access to the filesystem by placing "../" in the url.
ModificadaMedia (5.3)2.1%💥 PoCMyscada Mypro28/5/201817/6/2026
mySCADA myPRO 7 allows remote attackers to discover all ProjectIDs in a project by sending all of the prj parameter values from 870000 to 875000 in t=0&rq=0 requests to TCP port 11010.
ModificadaCrítica (9.1)15%💥 ExploitMyscada Mypro20/5/201817/6/2026
A hardcoded FTP username of myscada and password of Vikuk63 in 'myscadagate.exe' in mySCADA myPRO 7 allows remote attackers to access the FTP server on port 2121, and upload files or list directories, by entering these credentials.
ModificadaCrítica (9.9)3.7%—Mybiz Myprocurenet14/5/201817/6/2026
An issue was discovered in MyBiz MyProcureNet 5.0.0. A malicious file can be uploaded to the webserver by an attacker. It is possible for an attacker to upload a script to issue operating system commands. This vulnerability occurs because an attacker is able to adjust the…
ModificadaMedia (6.1)0.69%—Mybiz Myprocurenet14/5/201817/6/2026
An XSS issue was discovered in MyBiz MyProcureNet 5.0.0. This vulnerability within "ProxyPage.aspx" allows an attacker to inject malicious client side scripting which will be executed in the browser of users if they visit the manipulated site.
ModificadaAlta (7.8)0.73%—Myscada Mypro6/10/201717/6/2026
An Unquoted Search Path issue was discovered in mySCADA myPRO Versions 7.0.26 and prior. Application services utilize unquoted search path elements, which could allow an attacker to execute arbitrary code with elevated privileges.
ModificadaMedia (4.3)1.6%—Ncsa MyproxyGlobus Toolkit2/2/201116/6/2026
MyProxy 5.0 through 5.2, as used in Globus Toolkit 5.0.0 through 5.0.2, does not properly verify the (1) hostname or (2) identity in the X.509 certificate for the myproxy-server, which allows remote attackers to spoof the server and conduct man-in-the-middle (MITM) attacks via a crafted certificate when executing (a)…
ModificadaMedia (6.8)1.2%—Phpmyprofiler26/9/200716/6/2026
PHP remote file inclusion vulnerability in include/plugin/block.t.php in Peter Schmidt phpmyProfiler 0.9.6b allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter. NOTE: this issue is disputed by CVE because the applicable require_once is in a function that is not called on a…
ModificadaMedia (5.1)4.0%💥 ExploitPhpmyprofiler10/10/200616/6/2026
PHP remote file inclusion vulnerability in functions.php in phpMyProfiler 0.9.6 and earlier, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the pmp_rel_path parameter.
ModificadaMedia (4.6)2.1%—Myproxy31/12/200416/6/2026
MyProxy 6.58 allows remote authenticated users in the Users Tab to connect to arbitrary hosts from the MyProxy server, possibly bypassing access restrictions, by connecting to the proxy and issuing a CONNECT command.
ModificadaMedia (6.8)2.2%💥 ExploitMyproxy11/3/200416/6/2026
Cross-site scripting (XSS) vulnerability in MyProxy 20030629 allows remote attackers to inject arbitrary web script or HTML via the URL.
Orbitaley — Vulnerabilidades