Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (3.7) | 1.0% | — | Oracle GraalvmOracle Graalvm FOR JDKOracle JDKOracle JRE+5 | 16/7/2024 | 17/6/2026 | Vulnerability in the Oracle Java SE, Oracle GraalVM for JDK, Oracle GraalVM Enterprise Edition product of Oracle Java SE (component: Hotspot). Supported versions that are affected are Oracle Java SE: 8u411, 8u411-perf, 11.0.23, 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM for JDK: 17.0.11, 21.0.3, 22.0.1; Oracle GraalVM… | |
| Modificada | Baja (1.8) | 0.18% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 16/7/2024 | 17/6/2026 | An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are… | |
| Modificada | Media (6) | 0.30% | — | Rockwellautomation Factorytalk Policy Manager | 16/7/2024 | 17/6/2026 | The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html by implementing CIP… | |
| Modificada | Alta (8.7) | 2.1% | — | Rockwellautomation 5015-aenftxt Firmware | 16/7/2024 | 17/6/2026 | An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result in a major nonrecoverable fault. If exploited, a power cycle is required to recover the product. | |
| Analizada | Alta (8.7) | 0.49% | — | Rockwellautomation Pavilion8 | 16/7/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileges. If exploited, an attacker could read sensitive data, and create users. For example, a malicious… | |
| Modificada | Alta (8.1) | 0.47% | — | Vmware Aria AutomationVmware Cloud Foundation | 11/7/2024 | 17/6/2026 | VMware Aria Automation does not apply correct input validation which allows for SQL-injection in the product. An authenticated malicious user could enter specially crafted SQL queries and perform unauthorised read/write operations in the database. | |
| Aplazada | Media (5.3) | 0.46% | — | Siemens Simatic Energy Manager BasicAISiemens Simatic Energy Manager PROAISiemens Simatic IPC DiagbaseAISiemens Simatic IPC DiagmonitorAI+2 | 9/7/2024 | 17/6/2026 | A vulnerability has been identified in SIMATIC Energy Manager Basic (All versions < V7.5), SIMATIC Energy Manager PRO (All versions < V7.5), SIMATIC IPC DiagBase (All versions), SIMATIC IPC DiagMonitor (All versions), SIMIT V10 (All versions), SIMIT V11 (All versions < V11.1). Unified Automation .NET based OPC UA… | |
| Modificada | Alta (8.8) | 0.47% | — | Zoho Marketing Automation | 9/7/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Zoho Marketing Automation.This issue affects Zoho Marketing Automation: from n/a through 1.2.7. | |
| Modificada | Media (5.4) | 0.26% | — | IBM Cloud PAK FOR Business Automation | 8/7/2024 | 17/6/2026 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 is vulnerable to cross-site scripting. This vulnerability allows a privileged user to embed arbitrary JavaScript code in the Web UI thus altering the… | |
| Modificada | Media (4.3) | 0.30% | — | IBM Cloud PAK FOR Business Automation | 8/7/2024 | 17/6/2026 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, 22.0.2, 23.0.1, and 23.0.2 vulnerable to server-side request forgery (SSRF). This may allow an authenticated attacker to send unauthorized requests from the system, potentially… | |
| Aplazada | Media (6.9) | 0.59% | — | Parsec Automation TraksysAI | 30/6/2024 | 17/6/2026 | A vulnerability classified as problematic has been found in Parsec Automation TrakSYS 11.x.x. Affected is an unknown function of the file TS/export/contentpage of the component Export Page. The manipulation of the argument ID leads to direct request. It is possible to launch the attack remotely. The exploit has been… | |
| Modificada | Alta (8.7) | 2.3% | — | Rockwellautomation ThinmanagerRockwellautomation Thinserver | 25/6/2024 | 17/6/2026 | Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device. | |
| Modificada | Crítica (9.3) | 2.4% | — | Rockwellautomation ThinmanagerRockwellautomation Thinserver | 25/6/2024 | 17/6/2026 | Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™. | |
| Modificada | Crítica (9.3) | 2.7% | — | Rockwellautomation ThinmanagerRockwellautomation Thinserver | 25/6/2024 | 17/6/2026 | Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™. | |
| Aplazada | Media (6.9) | 2.0% | 💥 Exploit | Parsec Automation TracksysAI | 20/6/2024 | 17/6/2026 | A vulnerability was found in Parsec Automation TrackSYS 11.x.x and classified as problematic. This issue affects some unknown processing of the file /TS/export/pagedefinition. The manipulation of the argument ID leads to direct request. The attack may be initiated remotely. The exploit has been disclosed to the public… | |
| Analizada | Alta (8.3) | 0.31% | — | Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation 1756-en4 FirmwareRockwellautomation Compactlogix 5380 Firmware+2 | 14/6/2024 | 17/6/2026 | Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised. | |
| Analizada | Alta (8.5) | 0.33% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system. | |
| Analizada | Alta (8.2) | 0.50% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication… | |
| Modificada | Alta (8.2) | 0.50% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification. | |
| Modificada | Alta (7.4) | 0.25% | — | Mz-automation Libiec61850 | 11/6/2024 | 9/7/2026 | libiec61850 v1.5 was discovered to contain a heap overflow via the BerEncoder_encodeLength function at /asn1/ber_encoder.c. | |
| Analizada | Baja (3.3) | 0.38% | — | Tungstenautomation Power PDF | 6/6/2024 | 17/6/2026 | Kofax Power PDF AcroForm Annotation Out-Of-Bounds Read Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious… | |
| Analizada | Alta (7.8) | 0.41% | — | Tungstenautomation Power PDF | 6/6/2024 | 17/6/2026 | Kofax Power PDF PDF File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a… | |
| Analizada | Alta (7.8) | 0.40% | — | Tungstenautomation Power PDF | 6/6/2024 | 17/6/2026 | Kofax Power PDF PDF File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Analizada | Alta (7.8) | 0.41% | — | Tungstenautomation Power PDF | 6/6/2024 | 17/6/2026 | Kofax Power PDF TGA File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Modificada | Alta (7.8) | 0.60% | — | Tungstenautomation Power PDF | 6/6/2024 | 17/6/2026 | Kofax Power PDF JPF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… |