Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 551 respecto a la semana anterior
Críticas / altas1294▼ 234 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.30% | — | ABB Zenon | 24/7/2023 | 17/6/2026 | A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects… | |
| Modificada | Alta (8.1) | 0.31% | — | ABB Zenon | 24/7/2023 | 17/6/2026 | A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects… | |
| Modificada | Alta (8.8) | 0.37% | — | ABB Zenon | 24/7/2023 | 17/6/2026 | A vulnerability exists by allowing low-privileged users to read and update the data in various directories used by the Zenon system. An attacker could exploit the vulnerability by using specially crafted programs to exploit the vulnerabilities by allowing them to run on the zenon installed hosts. This issue affects… | |
| Analizada | Crítica (9.8) | 1.3% | — | Apache Eventmesh-connector-rabbitmq | 17/7/2023 | 17/6/2026 | CWE-502 Deserialization of Untrusted Data at the rabbitmq-connector plugin module in Apache EventMesh (incubating) V1.7.0\V1.8.0 on windows\linux\mac os e.g. platforms allows attackers to send controlled message and remote code execute via rabbitmq messages. Users can use the code under the master branch in project… | |
| Modificada | Alta (7.5) | 0.76% | — | Zabbix | 13/7/2023 | 17/6/2026 | Duktape is an 3rd-party embeddable JavaScript engine, with a focus on portability and compact footprint. When adding too many values in valstack JavaScript will crash. This issue occurs due to bug in Duktape 2.6 which is an 3rd-party solution that we use. | |
| Modificada | Media (6.1) | 0.57% | — | Zabbix Frontend | 13/7/2023 | 17/6/2026 | Reflected XSS attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script can be activated through Action form fields, which can be sent as request to a website with a vulnerability that enables execution of malicious scripts. | |
| Modificada | Media (5.4) | 0.56% | — | Zabbix Frontend | 13/7/2023 | 17/6/2026 | URL validation scheme receives input from a user and then parses it to identify its various components. The validation scheme can ensure that all URL components comply with internet standards. | |
| Modificada | Media (6.1) | 0.60% | — | Zabbix Frontend | 13/7/2023 | 17/6/2026 | Reflected XSS attacks, also known as non-persistent attacks, occur when a malicious script is reflected off a web application to the victim's browser. The script is activated through a link, which sends a request to a website with a vulnerability that enables execution of malicious scripts. | |
| Modificada | Media (5.4) | 0.57% | — | Zabbix Frontend | 13/7/2023 | 17/6/2026 | Stored or persistent cross-site scripting (XSS) is a type of XSS where the attacker first sends the payload to the web application, then the application saves the payload (e.g., in a database or server-side text files), and finally, the application unintentionally executes the payload for every victim visiting its web… | |
| Modificada | Media (5.4) | 64% | — | Zabbix | 13/7/2023 | 17/6/2026 | Currently, geomap configuration (Administration -> General -> Geographical maps) allows using HTML in the field “Attribution text” when selected “Other” Tile provider. | |
| Modificada | Alta (7.5) | 0.78% | — | Zabbix | 13/7/2023 | 17/6/2026 | Specially crafted string can cause a buffer overrun in the JSON parser library leading to a crash of the Zabbix Server or a Zabbix Proxy. | |
| Modificada | Alta (7.5) | 1.3% | — | Zabbix | 13/7/2023 | 17/6/2026 | JavaScript pre-processing can be used by the attacker to gain access to the file system (read-only access on behalf of user "zabbix") on the Zabbix Server or Zabbix Proxy, potentially leading to unauthorized access to sensitive data. | |
| Modificada | Media (4.9) | 1.2% | — | Zabbix | 13/7/2023 | 17/6/2026 | JavaScript preprocessing, webhooks and global scripts can cause uncontrolled CPU, memory, and disk I/O utilization. Preprocessing/webhook/global script configuration and testing are only available to Administrative roles (Admin and Superadmin). Administrative privileges should be typically granted to users who need to… | |
| Modificada | Alta (8) | 0.48% | — | ABB Txpert HUB Coretec 4 Firmware | 28/6/2023 | 17/6/2026 | A vulnerability exists that can be exploited by an authenticated client that is connected to the same network segment as the CoreTec 4, having any level of access VIEWER to ADMIN. To exploit the vulnerability the attacker can inject shell commands through a particular field of the web user interface that will be… | |
| Modificada | Media (5.5) | 0.22% | — | Rabbitmq-c Project Rabbitmq-c | 16/6/2023 | 17/6/2026 | An issue was discovered in the C AMQP client library (aka rabbitmq-c) through 0.13.0 for RabbitMQ. Credentials can only be entered on the command line (e.g., for amqp-publish or amqp-consume) and are thus visible to local attackers by listing a process and its arguments. | |
| Modificada | Media (6.1) | 0.29% | — | ABB Rex640 Pcl1 FirmwareABB Rex640 Pcl2 FirmwareABB Rex640 Pcl3 Firmware | 13/6/2023 | 17/6/2026 | Sensitive Cookie Without 'HttpOnly' Flag vulnerability in ABB REX640 PCL1 (firmware modules), ABB REX640 PCL2 (Firmware modules), ABB REX640 PCL3 (firmware modules) allows Cross-Site Scripting (XSS).This issue affects REX640 PCL1: from 1.0;0 before 1.0.8; REX640 PCL2: from 1.0;0 before 1.1.4; REX640 PCL3: from 1.0;0… | |
| Modificada | Crítica (9.8) | 1.4% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-12 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/6/2023 | 17/6/2026 | Improper Input Validation vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021,… | |
| Modificada | Crítica (9.8) | 0.37% | — | ABB Aspect-ent-2 FirmwareABB Aspect-ent-12 FirmwareABB Aspect-ent-256 FirmwareABB Aspect-ent-96 Firmware+15 | 5/6/2023 | 17/6/2026 | Improper Privilege Management vulnerability in ABB Ltd. ASPECT®-Enterprise on ASPECT®-Enterprise, Linux (2CQG103201S3021, 2CQG103202S3021, 2CQG103203S3021, 2CQG103204S3021 modules), ABB Ltd. NEXUS Series on NEXUS Series, Linux (2CQG100102R2021, 2CQG100104R2021, 2CQG100105R2021, 2CQG100106R2021, 2CQG100110R2021,… | |
| Modificada | Media (5.5) | 0.23% | — | ABB Platform Engineering ToolsABB QCS 800xa FirmwareABB QCS Ac450 Firmware | 22/5/2023 | 17/6/2026 | Insertion of Sensitive Information into Log File vulnerability in ABB QCS 800xA, ABB QCS AC450, ABB Platform Engineering Tools. An attacker, who already has local access to the QCS nodes, could successfully obtain the password for a system user account. Using this information, the attacker could have the potential to… | |
| Modificada | Media (4.3) | 0.16% | — | ABB Terra AC Wallbox Ul40 FirmwareABB Terra AC Wallbox 80A FirmwareABB Terra AC Wallbox Ul32a FirmwareABB Terra AC Wallbox JP Firmware+4 | 17/5/2023 | 17/6/2026 | Cleartext Transmission of Sensitive Information vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox… | |
| Modificada | Alta (8.8) | 0.35% | — | ABB Terra AC Wallbox Ul40 FirmwareABB Terra AC Wallbox 80A FirmwareABB Terra AC Wallbox Ul32a FirmwareABB Terra AC Wallbox JP Firmware+4 | 17/5/2023 | 17/6/2026 | Improper Authentication vulnerability in ABB Terra AC wallbox (UL40/80A), ABB Terra AC wallbox (UL32A), ABB Terra AC wallbox (CE) (Terra AC MID), ABB Terra AC wallbox (CE) Terra AC Juno CE, ABB Terra AC wallbox (CE) Terra AC PTB, ABB Terra AC wallbox (CE) Symbiosis, ABB Terra AC wallbox (JP).This issue affects Terra… | |
| Modificada | Crítica (9.8) | 0.71% | — | Home.cern White Rabbit Switch Firmware | 24/4/2023 | 17/6/2026 | White Rabbit Switch contains a vulnerability which makes it possible for an attacker to perform system commands under the context of the web application (the default installation makes the webserver run as the root user). | |
| Modificada | Alta (7.5) | 0.75% | — | Home.cern White Rabbit Switch Firmware | 24/4/2023 | 17/6/2026 | Within White Rabbit Switch it's possible as an unauthenticated user to retrieve sensitive information such as password hashes and the SNMP community strings. | |
| Modificada | Crítica (9.8) | 0.46% | — | ABB MY Control System | 6/4/2023 | 17/6/2026 | Insecure Storage of Sensitive Information vulnerability in ABB My Control System (on-premise) allows an attacker who successfully exploited this vulnerability to gain access to the secure application data or take control of the application. Of the services that make up the My Control System (on-premise) application,… | |
| Modificada | Media (5.3) | 0.56% | — | ABB Ac500 CPU Firmware | 31/3/2023 | 17/6/2026 | Improper Input Validation vulnerability in ABB AC500 V2 PM5xx allows Client-Server Protocol Manipulation.This issue affects AC500 V2: from 2.0.0 before 2.8.6. |