Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.55% | — | Tungstenautomation Power PDF | 6/6/2024 | 17/6/2026 | Kofax Power PDF PSD File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Alta (7.8) | 0.55% | — | Tungstenautomation Power PDF | 6/6/2024 | 17/6/2026 | Kofax Power PDF PDF File Parsing Out-Of-Bounds Write Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open… | |
| Analizada | Alta (7.8) | 0.53% | — | Tungstenautomation Power PDF | 6/6/2024 | 17/6/2026 | Kofax Power PDF PSD File Parsing Heap-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kofax Power PDF. User interaction is required to exploit this vulnerability in that the target must visit a malicious page… | |
| Analizada | Crítica (9.8) | 1.2% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to trigger this vulnerability.This CVE… | |
| Analizada | Crítica (9.8) | 1.2% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the Programming Software Connection FileSelect functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to stack-based buffer overflow. An attacker can send an unauthenticated packet to trigger this vulnerability.This CVE… | |
| Analizada | Alta (8.2) | 0.54% | — | Automationdirect P3-550e Firmware | 28/5/2024 | 17/6/2026 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks… | |
| Analizada | Alta (8.2) | 0.54% | — | Automationdirect P3-550e Firmware | 28/5/2024 | 17/6/2026 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks… | |
| Analizada | Alta (8.2) | 0.49% | — | Automationdirect P3-550e Firmware | 28/5/2024 | 17/6/2026 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks… | |
| Analizada | Alta (8.2) | 0.54% | — | Automationdirect P3-550e Firmware | 28/5/2024 | 17/6/2026 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks… | |
| Analizada | Alta (8.2) | 0.49% | — | Automationdirect P3-550e Firmware | 28/5/2024 | 17/6/2026 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks… | |
| Analizada | Alta (8.2) | 0.54% | — | Automationdirect P3-550e Firmware | 28/5/2024 | 17/6/2026 | Several out-of-bounds write vulnerabilities exist in the Programming Software Connection FileSystem API functionality of AutomationDirect P3-550E 1.2.10.9. Specially crafted network packets can lead to heap-based memory corruption. An attacker can send malicious packets to trigger these vulnerabilities.This CVE tracks… | |
| Analizada | Alta (8.2) | 0.84% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these vulnerability.This CVE tracks the heap… | |
| Analizada | Alta (8.2) | 0.78% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the Programming Software Connection CurrDir functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to denial of service. An attacker can send an unauthenticated packet to trigger these vulnerability.This CVE tracks the heap… | |
| Analizada | Alta (7.5) | 1.4% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A heap-based buffer overflow vulnerability exists in the Programming Software Connection FiBurn functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a buffer overflow. An attacker can send an unauthenticated packet to trigger this vulnerability. | |
| Analizada | Crítica (9.8) | 0.72% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A code injection vulnerability exists in the scan_lib.bin functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted scan_lib.bin can lead to arbitrary code execution. An attacker can provide a malicious file to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 0.96% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A read-what-where vulnerability exists in the Programming Software Connection IMM 01A1 Memory Read functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to a disclosure of sensitive information. An attacker can send an unauthenticated packet to trigger this vulnerability. | |
| Analizada | Crítica (9.1) | 1.0% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A write-what-where vulnerability exists in the Programming Software Connection Remote Memory Diagnostics functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted network packet can lead to an arbitrary write. An attacker can send an unauthenticated packet to trigger this vulnerability. | |
| Analizada | Crítica (9.8) | 1.5% | — | Automationdirect P3-550e FirmwareAutomationdirect P3-550 FirmwareAutomationdirect P3-530 FirmwareAutomationdirect P2-550 Firmware+2 | 28/5/2024 | 17/6/2026 | A leftover debug code vulnerability exists in the Telnet Diagnostic Interface functionality of AutomationDirect P3-550E 1.2.10.9. A specially crafted series of network requests can lead to unauthorized access. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Analizada | Alta (7.5) | 0.24% | — | Progress Moveit Automation | 22/5/2024 | 17/6/2026 | The Progress MOVEit Automation configuration export function prior to 2024.0.0 uses a cryptographic method with insufficient bit length. | |
| Analizada | Alta (8.8) | 0.65% | — | Rockwellautomation Factorytalk View | 16/5/2024 | 17/6/2026 | A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure,… | |
| Aplazada | Alta (7) | 0.27% | 💥 PoC | Rockwellautomation Factorytalk Remote AccessAI | 16/5/2024 | 17/6/2026 | An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a… | |
| Analizada | Alta (7.2) | 0.17% | — | Br-automation Automation Studio | 14/5/2024 | 17/6/2026 | Improper DLL loading algorithms in B&R Automation Studio versions >=4.0 and <4.12 may allow an authenticated local attacker to execute code in the context of the product. | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Aplazada | Alta (8.2) | 0.26% | — | Siemens Security Configuration ToolAISiemens Simatic Automation ToolAISiemens Simatic BatchAISiemens Simatic NET PC SoftwareAI+15 | 14/5/2024 | 17/6/2026 | A vulnerability has been identified in Security Configuration Tool (SCT) (All versions), SIMATIC Automation Tool (All versions < V5.0 SP2), SIMATIC BATCH V9.1 (All versions < V9.1 SP2 Upd5), SIMATIC NET PC Software V16 (All versions < V16 Update 8), SIMATIC NET PC Software V17 (All versions), SIMATIC NET PC Software… | |
| Analizada | Alta (7.5) | 0.59% | — | F5 Big-ip Access Policy ManagerF5 Big-ip Advanced Firewall ManagerF5 Big-ip Advanced WEB Application FirewallF5 Big-ip Analytics+17 | 8/5/2024 | 17/6/2026 | When IPsec is configured on a virtual server, undisclosed traffic can cause the Traffic Management Microkernel (TMM) to terminate. Note: Software versions which have reached End of Technical Support (EoTS) are not evaluated. |