Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2678▼ 660 respecto a la semana anterior
Críticas / altas1266▼ 293 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
933 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.21% | — | ABB Mint Workbench | 15/6/2022 | 17/6/2026 | Vulnerabilities in the Mint WorkBench allow a low privileged attacker to create and write to a file anywhere on the file system as SYSTEM with arbitrary content as long as the file does not already exist. The Mint WorkBench installer file allows a low-privileged user to run a "repair" operation on the product | |
| Modificada | Alta (7.8) | 0.32% | — | ABB E-design | 2/6/2022 | 17/6/2026 | Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine. | |
| Modificada | Media (5.5) | 0.27% | — | ABB E-design | 2/6/2022 | 17/6/2026 | Incorrect Default Permissions vulnerability in ABB e-Design allows attacker to install malicious software executing with SYSTEM permissions violating confidentiality, integrity, and availability of the target machine. | |
| Modificada | Crítica (9.8) | 0.88% | — | ABB Arg600a1220na FirmwareABB Arg600a1230na FirmwareABB Arg600a1240na FirmwareABB Arg600a1260na Firmware+20 | 10/5/2022 | 17/6/2026 | A vulnerability in ABB ARG600 Wireless Gateway series that could allow an attacker to exploit the vulnerability by remotely connecting to the serial port gateway, and/or protocol converter, depending on the configuration. | |
| Modificada | Alta (7.5) | 0.99% | — | ABB Rtu500 FirmwareHitachienergy Rtu500 Firmware | 2/5/2022 | 17/6/2026 | A vulnerability exists in the HCI Modbus TCP function included in the product versions listed above. If the HCI Modbus TCP is en-abled and configured, an attacker could exploit the vulnerability by sending a specially crafted message to the RTU500, causing the receiving RTU500 CMU to reboot. The vulnerability is… | |
| Modificada | Alta (7.5) | 0.95% | — | ABB 800xaABB Base SoftwareABB Compact Product SuiteABB Control Builder Safe | 1/4/2022 | 17/6/2026 | Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service. | |
| Modificada | Media (4.4) | 1.2% | — | Zabbix FrontendDebian LinuxFedoraproject Fedora | 9/3/2022 | 17/6/2026 | An authenticated user can create a link with reflected Javascript code inside it for graphs’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the… | |
| Modificada | Media (4.4) | 1.2% | — | Zabbix FrontendFedoraproject Fedora | 9/3/2022 | 17/6/2026 | An authenticated user can create a link with reflected Javascript code inside it for items’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as the… | |
| Modificada | Media (4.4) | 1.2% | — | Zabbix FrontendDebian LinuxFedoraproject Fedora | 9/3/2022 | 17/6/2026 | An authenticated user can create a link with reflected Javascript code inside it for services’ page and send it to other users. The payload can be executed only with a known CSRF token value of the victim, which is changed periodically and is difficult to predict. Malicious code has access to all the same objects as… | |
| Modificada | Media (4.4) | 1.2% | — | Zabbix FrontendDebian LinuxFedoraproject Fedora | 9/3/2022 | 17/6/2026 | An authenticated user can create a link with reflected XSS payload for actions’ pages, and send it to other users. Malicious code has access to all the same objects as the rest of the web page and can make arbitrary modifications to the contents of the page being displayed to a victim. This attack can be implemented… | |
| Modificada | Alta (7.5) | 1.1% | — | ABB Pni800 FirmwareABB Spiet800 Firmware | 4/2/2022 | 17/6/2026 | Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive. | |
| Modificada | Alta (7.5) | 1.1% | — | ABB Pni800 FirmwareABB Spiet800 Firmware | 4/2/2022 | 17/6/2026 | Improper Input Validation vulnerability in the ABB SPIET800 and PNI800 module allows an attacker to cause the denial of service or make the module unresponsive. | |
| Modificada | Alta (7.5) | 1.0% | — | ABB Pni800 FirmwareABB Spiet800 Firmware | 4/2/2022 | 17/6/2026 | Improper Handling of Exceptional Conditions, Improper Check for Unusual or Exceptional Conditions vulnerability in the ABB SPIET800 and PNI800 module that allows an attacker to cause the denial of service or make the module unresponsive. | |
| Modificada | Alta (8.8) | 0.83% | — | ABB OPC Server FOR AC 800m | 4/2/2022 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in OPC Server for AC 800M allows an attacker to execute arbitrary code in the node running the AC800M OPC Server. | |
| Modificada | Alta (7.2) | 3.9% | — | Zabbix | 27/1/2022 | 17/6/2026 | Zabbix 4.0 LTS, 4.2, 4.4, and 5.0 LTS is vulnerable to Remote Code Execution (RCE). Any user with the "Zabbix Admin" role is able to run custom shell script on the application server in the context of the application user. | |
| Analizada | Media (5.3) | 95% | ⚠ Explotación activa💥 Exploit | ZabbixFedoraproject FedoraDebian Linux | 13/1/2022 | 17/6/2026 | After the initial setup process, some steps of setup.php file are reachable not only by super-administrators, but by unauthenticated users as well. Malicious actor can pass step checks and potentially change the configuration of Zabbix Frontend. | |
| Modificada | Media (5.4) | 1.0% | — | ZabbixFedoraproject Fedora | 13/1/2022 | 17/6/2026 | An authenticated user can create a hosts group from the configuration with XSS payload, which will be available for other users. When XSS is stored by an authenticated malicious actor and other users try to search for groups during new host creation, the XSS payload will fire and the actor can steal session cookies… | |
| Modificada | Alta (7.3) | 0.80% | — | ZabbixFedoraproject Fedora | 13/1/2022 | 17/6/2026 | During Zabbix installation from RPM, DAC_OVERRIDE SELinux capability is in use to access PID files in [/var/run/zabbix] folder. In this case, Zabbix Proxy or Server processes can bypass file read, write and execute permissions check on the file system level | |
| Analizada | Crítica (9.8) | 96% | ⚠ Explotación activa💥 Exploit | Zabbix | 13/1/2022 | 17/6/2026 | In the case of instances where the SAML SSO authentication is enabled (non-default), session data can be modified by a malicious actor, because a user login stored in the session was not verified. Malicious unauthenticated actor may exploit this issue to escalate privileges and gain admin access to Zabbix Frontend. To… | |
| Modificada | Crítica (9.8) | 1.3% | — | Zabbix-agent2 | 6/1/2022 | 17/6/2026 | The zabbix-agent2 package before 5.4.9-r1 for Alpine Linux sometimes allows privilege escalation to root because the design incorrectly expected that systemd would (in effect) determine part of the configuration. | |
| Modificada | Crítica (9.8) | 1.5% | — | ABB Omnicore C30 Firmware | 13/12/2021 | 17/6/2026 | A Missing Authentication vulnerability in RobotWare for the OmniCore robot controller allows an attacker to read and modify files on the robot controller if the attacker has access to the Connected Services Gateway Ethernet port. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phpjabbers Fundraising Script | 5/11/2021 | 17/6/2026 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionSetAmount function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phpjabbers Fundraising Script | 5/11/2021 | 17/6/2026 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoadForm function. | |
| Modificada | Media (6.1) | 0.66% | — | Phpjabbers Fundraising Script | 5/11/2021 | 17/6/2026 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a cross-site scripting (XSS) vulnerability via the pjActionPreview function. | |
| Modificada | Crítica (9.8) | 1.1% | — | Phpjabbers Fundraising Script | 5/11/2021 | 17/6/2026 | Stivasoft (Phpjabbers) Fundraising Script v1.0 was discovered to contain a SQL injection vulnerability via the pjActionLoad function. |