Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
230 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.64% | — | Advantech Webaccess HMI Designer | 15/11/2021 | 17/6/2026 | This vulnerability could allow an attacker to send malicious Javascript code resulting in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage, and performing unintended browser action. | |
| Modificada | Alta (7.8) | 0.29% | — | Advantech Webaccess HMI Designer | 15/11/2021 | 17/6/2026 | This vulnerability could allow an attacker to disclose information and execute arbitrary code on affected installations of WebAccess/MHI Designer | |
| Modificada | Media (5.3) | 0.95% | — | Advantech Webaccess/nms | 27/10/2021 | 17/6/2026 | WebAccess/NMS (Versions prior to v3.0.3_Build6299) has an improper authentication vulnerability, which may allow unauthorized users to view resources monitored and controlled by the WebAccess/NMS, as well as IP addresses and names of all the devices managed via WebAccess/NMS. | |
| Modificada | Crítica (9.8) | 10% | — | Advantech Webaccess | 18/10/2021 | 17/6/2026 | Advantech WebAccess versions 9.02 and prior are vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute code. | |
| Modificada | Crítica (9.8) | 2.3% | — | Advantech Webaccess | 18/10/2021 | 17/6/2026 | Advantech WebAccess versions 9.02 and prior are vulnerable to a heap-based buffer overflow, which may allow an attacker to remotely execute code. | |
| Modificada | Media (4.3) | 0.70% | — | Advantech Webaccess Scada | 15/10/2021 | 17/6/2026 | An authenticated user using Advantech WebAccess SCADA in versions 9.0.3 and prior can use API functions to disclose project names and paths from other users. | |
| Modificada | Crítica (9.8) | 12% | — | Advantech Webaccess | 9/9/2021 | 17/6/2026 | A stack-based buffer overflow vulnerability in Advantech WebAccess Versions 9.02 and prior caused by a lack of proper validation of the length of user-supplied data may allow remote code execution. | |
| Modificada | Crítica (9.8) | 1.9% | — | Advantech Webaccess/scada | 10/8/2021 | 17/6/2026 | The affected product is vulnerable to a stack-based buffer overflow, which may allow an attacker to remotely execute arbitrary code on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1). | |
| Modificada | Media (6.1) | 0.64% | — | Advantech Webaccess/scada | 10/8/2021 | 17/6/2026 | UserExcelOut.asp within WebAccess/SCADA is vulnerable to cross-site scripting (XSS), which could allow an attacker to send malicious JavaScript code. This could result in hijacking of cookie/session tokens, redirection to a malicious webpage, and unintended browser action on the WebAccess/SCADA (WebAccess/SCADA… | |
| Modificada | Media (6.5) | 1.1% | — | Advantech Webaccess/scada | 10/8/2021 | 17/6/2026 | The affected product is vulnerable to a relative path traversal condition, which may allow an attacker access to unauthorized files and directories on the WebAccess/SCADA (WebAccess/SCADA versions prior to 8.4.5, WebAccess/SCADA versions prior to 9.0.1). | |
| Modificada | Alta (7.8) | 0.95% | — | Advantech Webaccess/hmi Designer | 24/6/2021 | 17/6/2026 | The affected product is vulnerable to memory corruption condition due to lack of proper validation of user supplied files, which may allow an attacker to execute arbitrary code. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior). | |
| Modificada | Alta (7.8) | 0.97% | — | Advantech Webaccess/hmi Designer | 24/6/2021 | 17/6/2026 | Opening a maliciously crafted project file may cause an out-of-bounds write, which may allow an attacker to execute arbitrary code. User interaction is require on the WebAccess HMI Designer (versions 2.1.9.95 and prior). | |
| Modificada | Alta (7.8) | 1.0% | — | Advantech Webaccess/hmi Designer | 24/6/2021 | 17/6/2026 | Parsing a maliciously crafted project file may cause a heap-based buffer overflow, which may allow an attacker to perform arbitrary code execution. User interaction is required on the WebAccess HMI Designer (versions 2.1.9.95 and prior). | |
| Modificada | Media (6.1) | 0.70% | — | Advantech Webaccess/scada | 18/6/2021 | 17/6/2026 | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to redirection, which may allow an attacker to send a maliciously crafted URL that could result in redirecting a user to a malicious webpage. | |
| Modificada | Media (6.5) | 2.1% | — | Advantech Webaccess/scada | 18/6/2021 | 17/6/2026 | Advantech WebAccess/SCADA Versions 9.0.1 and prior is vulnerable to a directory traversal, which may allow an attacker to remotely read arbitrary files on the file system. | |
| Modificada | Media (6.1) | 0.87% | — | Advantech Webaccess | 11/6/2021 | 17/6/2026 | Advantech WebAccess 8.4.2 and 8.4.4 allows XSS via the username column of the bwRoot.asp page of WADashboard. | |
| Modificada | Alta (8.8) | 1.2% | — | Advantech Webaccess/scada | 26/4/2021 | 17/6/2026 | Incorrect permissions are set to default on the ‘Project Management’ page of WebAccess/SCADA portal of WebAccess/SCADA Versions 9.0.1 and prior, which may allow a low-privileged user to update an administrator’s password and login as an administrator to escalate privileges on the system. | |
| Modificada | Media (6.1) | 0.69% | — | Advantech Webaccess/scada | 18/3/2021 | 17/6/2026 | WebAccess/SCADA Versions 9.0 and prior is vulnerable to cross-site scripting, which may allow an attacker to send malicious JavaScript code to an unsuspecting user, which could result in hijacking of the user’s cookie/session tokens, redirecting the user to a malicious webpage and performing unintended browser actions. | |
| Modificada | Alta (7.8) | 0.55% | — | Advantech Webaccess/scada | 3/3/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. | |
| Modificada | Alta (8.8) | 1.6% | — | Advantech Webaccess/scada | 23/2/2021 | 17/6/2026 | The WADashboard component of WebAccess/SCADA Versions 9.0 and prior may allow an attacker to control or influence a path used in an operation on the filesystem and remotely execute code as an administrator. | |
| Modificada | Alta (8.8) | 0.50% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In COM Server Application Privilege Escalation, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. | |
| Modificada | Alta (8.8) | 0.50% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In webvrpcs Run Key Privilege Escalation in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. | |
| Modificada | Alta (8.8) | 0.50% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via multiple service executables in installation folder of WebAccess, an attacker can either replace binary or loaded modules to execute code with NT… | |
| Modificada | Alta (8.8) | 0.49% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | An exploitable local privilege elevation vulnerability exists in the file system permissions of Advantech WebAccess/SCADA 9.0.1 installation. In privilege escalation via PostgreSQL executable, an attacker can either replace binary or loaded modules to execute code with NT SYSTEM privilege. | |
| Modificada | Alta (7.7) | 3.5% | — | Advantech Webaccess/scada | 17/2/2021 | 17/6/2026 | A local file inclusion vulnerability exists in the installation functionality of Advantech WebAccess/SCADA 9.0.1. A specially crafted application can lead to information disclosure. An attacker can send an authenticated HTTP request to trigger this vulnerability. |