Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2677▼ 656 respecto a la semana anterior
Críticas / altas1264▼ 294 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 258 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 3.9% | 💥 Exploit | ABB Flow-x/m FirmwareABB Flow-x/c FirmwareABB Flow-x/k FirmwareABB Flow-x/s Firmware+4 | 31/3/2023 | 17/6/2026 | Exposure of Sensitive Information to an Unauthorized Actor vulnerability in ABB Flow-X firmware on Flow-X embedded hardware (web service modules) allows Footprinting.This issue affects Flow-X: before 4.0. | |
| Modificada | Crítica (9.8) | 0.62% | — | ABB Rccmd | 27/3/2023 | 17/6/2026 | Use of Default Password vulnerability in ABB RCCMD on Windows, Linux, MacOS allows Try Common or Default Usernames and Passwords.This issue affects RCCMD: before 4.40 230207. | |
| Modificada | Media (4.3) | 0.43% | — | ABB H5692448 G104 FirmwareABB H5692448 G842 FirmwareABB H5692448 G224l FirmwareABB H5692448 G630-4 Firmware+3 | 16/3/2023 | 17/6/2026 | Use of Insufficiently Random Values vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode 150047415. | |
| Modificada | Alta (8.8) | 0.35% | — | ABB Symphony Plus S+ Operations | 2/3/2023 | 17/6/2026 | Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2. | |
| Modificada | Media (5.5) | 0.17% | — | ABB Smu615 FirmwareABB Rec615 FirmwareABB Rer615 FirmwareABB Evd4 Firmware+15 | 28/2/2023 | 17/6/2026 | Improper Initialization vulnerability in ABB Relion protection relays - 611 series, ABB Relion protection relays - 615 series IEC 4.0 FP1, ABB Relion protection relays - 615 series CN 4.0 FP1, ABB Relion protection relays - 615 series IEC 5.0, ABB Relion protection relays - 615 series IEC 5.0 FP1, ABB Relion… | |
| Modificada | Alta (8.8) | 0.21% | — | ABB Infinity DC Power PlantABB Ne843 S | 24/2/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in ABB Pulsar Plus System Controller NE843_S, ABB Infinity DC Power Plant allows Cross Site Request Forgery.This issue affects Pulsar Plus System Controller NE843_S : comcode 150042936; Infinity DC Power Plant: H5692448 G104 G842 G224L G630-4 G451C(2) G461(2) – comcode… | |
| Modificada | Media (6.5) | 0.72% | — | Jenkins Rabbitmq Consumer | 26/1/2023 | 17/6/2026 | A missing permission check in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers with Overall/Read permission to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password. | |
| Modificada | Alta (8.8) | 0.52% | — | Jenkins Rabbitmq Consumer | 26/1/2023 | 17/6/2026 | A cross-site request forgery (CSRF) vulnerability in Jenkins RabbitMQ Consumer Plugin 2.8 and earlier allows attackers to connect to an attacker-specified AMQP(S) URL using attacker-specified username and password. | |
| Modificada | Media (5.4) | 0.59% | — | GitlabABB Drive Composer | 12/1/2023 | 17/6/2026 | An issue has been discovered in GitLab CE/EE affecting all versions starting from 15.4 before 15.5.7, all versions starting from 15.6 before 15.6.4, all versions starting from 15.7 before 15.7.2. Due to the improper filtering of query parameters in the wiki changes page, an attacker can execute arbitrary JavaScript on… | |
| Modificada | Media (5.9) | 48% | — | Zabbix WEB Service Report GenerationZabbix-agent2 | 15/12/2022 | 17/6/2026 | Arbitrary file read vulnerability exists in Zabbix Web Service Report Generation, which listens on the port 10053. The service does not have proper validation for URL parameters before reading the files. | |
| Modificada | Crítica (9.8) | 0.95% | — | Microsoft Windows FirewallZabbix | 5/12/2022 | 17/6/2026 | A Firewall Rule which allows all incoming TCP connections to all programs from any source and to all ports is created in Windows Firewall after Zabbix agent installation (MSI) | |
| Modificada | Crítica (9.8) | 1.2% | — | Zabbix Frontend | 5/12/2022 | 17/6/2026 | Zabbix Frontend provides a feature that allows admins to maintain the installation and ensure that only certain IP addresses can access it. In this way, any user will not be able to access the Zabbix Frontend while it is being maintained and possible sensitive data will be prevented from being disclosed. An attacker… | |
| Modificada | Alta (7.5) | 0.40% | — | Broadcom Rabbitmq ServerVmware Rabbitmq | 6/10/2022 | 17/6/2026 | RabbitMQ is a multi-protocol messaging and streaming broker. In affected versions the shovel and federation plugins perform URI obfuscation in their worker (link) state. The encryption key used to encrypt the URI was seeded with a predictable secret. This means that in case of certain exceptions related to Shovel and… | |
| Modificada | Media (6.1) | 0.80% | — | ZabbixFedoraproject Fedora | 14/9/2022 | 17/6/2026 | An unauthenticated user can create a link with reflected Javascript code inside the backurl parameter and send it to other authenticated users in order to create a fake account with predefined login, password and role in Zabbix Frontend. | |
| Modificada | Alta (8.4) | 0.15% | — | ABB Zenon | 24/8/2022 | 17/6/2026 | Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add or alter data points and corresponding attributes. Once such engineering data is used the data visualization will be altered for the end user. | |
| Modificada | Media (6.1) | 0.15% | — | ABB Zenon | 24/8/2022 | 17/6/2026 | Storing Passwords in a Recoverable Format vulnerability in ABB Zenon 8.20 allows an attacker who successfully exploit the vulnerability may add more network clients that may monitor various activities of the Zenon. | |
| Modificada | Alta (8.2) | 0.62% | — | ABB Zenon | 24/8/2022 | 17/6/2026 | Relative Path Traversal vulnerability in ABB Zenon 8.20 allows the user to access files on the Zenon system and user also can add own log messages and e.g., flood the log entries. An attacker who successfully exploit the vulnerability could access the Zenon runtime activities such as the start and stop of various… | |
| Modificada | Crítica (9.8) | 17% | — | ABB Rmc-100 FirmwareABB Rmc-100-lite FirmwareABB XIO FirmwareABB Xfcg5 Firmware+3 | 21/7/2022 | 17/6/2026 | Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal'), Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in flow computer and remote controller products of ABB ( RMC-100 (Standard), RMC-100-LITE, XIO, XFCG5 , XRCG5 , uFLOG5 , UDC) allows an… | |
| Modificada | Media (5.4) | 0.79% | — | Zabbix | 6/7/2022 | 17/6/2026 | An authenticated user can create a link with reflected Javascript code inside it for the graphs page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. | |
| Modificada | Media (5.4) | 0.81% | — | Zabbix | 6/7/2022 | 17/6/2026 | An authenticated user can create a link with reflected Javascript code inside it for the discovery page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. | |
| Modificada | Media (6.5) | 0.65% | — | ABB Rex640 Pcl1 FirmwareABB Rex640 Pcl2 FirmwareABB Rex640 Pcl3 Firmware | 21/6/2022 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in ABB REX640 PCL1, REX640 PCL2, REX640 PCL3 allows an authenticated attacker to launch an attack against the user database file and try to take control of an affected system node. | |
| Modificada | Alta (7.8) | 0.30% | — | ABB Automation BuilderABB Drive ComposerABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product. | |
| Modificada | Alta (7.8) | 0.32% | — | ABB Automation BuilderABB Drive ComposerABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product. | |
| Modificada | Alta (7.8) | 0.32% | — | ABB Automation BuilderABB Drive ComposerABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product. | |
| Modificada | Alta (7.8) | 0.32% | — | ABB Automation BuilderABB Drive ComposerABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Drive Composer allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Drive Composer installer file allows a low-privileged user to run a "repair" operation on the product. |