Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
–

574 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)6.3%—Rockwellautomation Factorytalk Energrymetrix28/7/201617/6/2026
SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.8)3.1%—Mindbite Sitefactory CMS11/9/201517/6/2026
Absolute path traversal vulnerability in SiteFactory CMS 5.5.9 allows remote attackers to read arbitrary files via a full pathname in the file parameter to assets/download.aspx.
ModificadaMedia (6.9)0.69%—Rockwellautomation Factorytalk Services PlatformRockwellautomation Factorytalk View Studio31/3/201517/6/2026
Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (10)4.2%—Schneider-electric Etg3000 Factorycast HMI Gateway FirmwareSchneider-electric Tsxetg3000Schneider-electric Tsxetg3010Schneider-electric Tsxetg3021+127/1/201517/6/2026
The FTP server on the Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware through 1.60 IR 04 has hardcoded credentials, which makes it easier for remote attackers to obtain access via an FTP session.
ModificadaAlta (7.8)2.0%—Schneider-electric Etg3000 Factorycast HMI Gateway FirmwareSchneider-electric Tsxetg3000Schneider-electric Tsxetg3010Schneider-electric Tsxetg3021+127/1/201517/6/2026
The Schneider Electric ETG3000 FactoryCast HMI Gateway with firmware before 1.60 IR 04 stores rde.jar under the web root with insufficient access control, which allows remote attackers to obtain sensitive setup and configuration information via a direct request.
ModificadaMedia (4.3)1.4%—IBM WEB Experience Factory26/11/201417/6/2026
Cross-site scripting (XSS) vulnerability in IBM Web Experience Factory (WEF) 6.1.5 through 8.5.0.1, as used in WebSphere Dashboard Framework (WDF) and Lotus Widget Factory (LWF), allows remote attackers to inject arbitrary web script or HTML by leveraging a Dojo builder error in an unspecified WebSphere Portal…
ModificadaMedia (5.4)0.27%—Magzter Human Factor19/10/201417/6/2026
The Human Factor (aka com.magzter.thehumanfactor) application 3.01 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaMedia (5.4)0.27%—Communityfactory Selfie Camera -facial Beauty-9/9/201417/6/2026
The Selfie Camera -Facial Beauty- (aka com.cfinc.cunpic) application 1.2.7 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate.
ModificadaAlta (7.8)2.5%—Schneider-electric OPC Factory Server TlxcdlfofsSchneider-electric OPC Factory Server TlxcdltofsSchneider-electric OPC Factory Server TlxcdluofsSchneider-electric OPC Factory Server Tlxcdstofs+14/4/201417/6/2026
Multiple buffer overflows in the OPC Automation 2.0 Server Object ActiveX control in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 3.5 and earlier, TLXCDSTOFS33 3.5 and earlier, TLXCDLUOFS33 3.5 and earlier, TLXCDLTOFS33 3.5 and earlier, and TLXCDLFOFS33 3.5 and earlier allow remote attackers to cause a…
ModificadaAlta (9.3)22%💥 ExploitSchneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+91/4/201416/6/2026
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.
ModificadaMedia (6.9)0.47%—Schneider-electric OFS Test Client Tlxcdlfofs33Schneider-electric OFS Test Client Tlxcdltofs33Schneider-electric OFS Test Client Tlxcdluofs33Schneider-electric OFS Test Client Tlxcdstofs33+228/2/201417/6/2026
Stack-based buffer overflow in the C++ sample client in Schneider Electric OPC Factory Server (OFS) TLXCDSUOFS33 - 3.35, TLXCDSTOFS33 - 3.35, TLXCDLUOFS33 - 3.35, TLXCDLTOFS33 - 3.35, and TLXCDLFOFS33 - 3.35 allows local users to gain privileges via vectors involving a malformed configuration file.
ModificadaAlta (7.5)2.3%💥 ExploitCubicfactory Cubic CMS21/1/201417/6/2026
Multiple SQL injection vulnerabilities in Cubic CMS 5.1.1, 5.1.2, and 5.2 allow remote attackers to execute arbitrary SQL commands via the (1) resource_id or (2) version_id parameter to recursos/agent.php or (3) login or (4) pass parameter to login.usuario.
ModificadaAlta (7.8)3.2%—Rockwellautomation Factorytalk Services Platform18/4/201316/6/2026
Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that specifies a…
ModificadaAlta (7.8)3.2%—Rockwellautomation Factorytalk Services Platform18/4/201316/6/2026
Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage or RNADiagReceiver.exe daemon crash) via UDP data that…
ModificadaMedia (6)1.1%—Widgetfactorylimited COM JCE30/8/201216/6/2026
Unrestricted file upload vulnerability in editor/extensions/browser/file.php in the JCE component before 2.0.18 for Joomla! allows remote authenticated users with the author privileges to execute arbitrary PHP code by uploading a file with a double extension, as demonstrated by .php.gif. NOTE: some of these details…
ModificadaMedia (5)3.5%—Rockwellautomation FactorytalkRockwellautomation Rslogix 50002/4/201216/6/2026
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet.
ModificadaMedia (5)10%💥 ExploitRockwellautomation FactorytalkRockwellautomation Rslogix 50002/4/201216/6/2026
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet.
ModificadaMedia (5.8)1.0%—Siemens Tecnomatix Factorylink8/1/201216/6/2026
An unspecified ActiveX control in ActBar.ocx in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to create or overwrite arbitrary files via the save method.
ModificadaAlta (9.3)4.6%—Siemens Tecnomatix Factorylink8/1/201216/6/2026
Buffer overflow in the WebClient ActiveX control in Siemens Tecnomatix FactoryLink 6.6.1 (aka 6.6 SP1), 7.5.217 (aka 7.5 SP2), and 8.0.2.54 allows remote attackers to execute arbitrary code via a long string in a parameter associated with the location URL.
ModificadaMedia (4.3)1.2%—IBM WEB Experience Factory3/1/201216/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in IBM Web Experience Factory (aka WEF, formerly WebSphere Portlet Factory) 7.0 and 7.0.1 allow remote attackers to inject arbitrary web script or HTML via a (1) text INPUT element or (2) TEXTAREA element, related to an interaction between Smart Refresh and Dojo.
ModificadaAlta (7.2)1.3%—Schneider-electric Monitor PROSchneider-electric OPC Factory ServerSchneider-electric PL7 PROSchneider-electric Telemecanique Driver Pack+24/11/201116/6/2026
Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers,…
ModificadaAlta (10)71%💥 ExploitAzeotech Daqfactory16/9/201116/6/2026
Stack-based buffer overflow in Azeotech DAQFactory 5.85 build 1853 and earlier allows remote attackers to cause a denial of service (crash) and execute arbitrary code via a crafted NETB packet to UDP port 20034.
ModificadaMedia (6.9)0.64%—Rockwellautomation Factorytalk Diagnostics Viewer28/7/201116/6/2026
Unspecified vulnerability in Rockwell Automation FactoryTalk Diagnostics Viewer before V2.30.00 (CPR9 SR3) allows local users to execute arbitrary code via a crafted FactoryTalk Diagnostics Viewer (.ftd) configuration file, which triggers memory corruption.
ModificadaAlta (7.8)6.7%💥 ExploitAzeotech Daqfactory28/7/201116/6/2026
AzeoTech DAQFactory before 5.85 (Build 1842) does not perform authentication for certain signals, which allows remote attackers to cause a denial of service (system reboot or shutdown) via a signal.
ModificadaAlta (9.3)42%💥 ExploitTomsawyer GET Extension FactoryVmware Virtual Infrastructure ClientVmware Infrastructure6/6/201116/6/2026
Certain ActiveX controls in (1) tsgetxu71ex552.dll and (2) tsgetx71ex552.dll in Tom Sawyer GET Extension Factory 5.5.2.237, as used in VI Client (aka VMware Infrastructure Client) 2.0.2 before Build 230598 and 2.5 before Build 204931 in VMware Infrastructure 3, do not properly handle attempted initialization within…
Orbitaley — Vulnerabilidades