Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
69 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 2.1% | 💥 PoC | Eaton UPS Companion | 23/3/2020 | 17/6/2026 | UPS companion software v1.05 & Prior is affected by ‘Eval Injection’ vulnerability. The software does not neutralize or incorrectly neutralizes code syntax before using the input in a dynamic evaluation call e.g.”eval” in “Update Manager” class when software attempts to see if there are updates available. This results… | |
| Modificada | Media (4.8) | 0.65% | — | Eaton 5P 850 Firmware | 22/1/2020 | 17/6/2026 | An issue was discovered on Eaton 5P 850 devices. The Ubicacion SAI field allows XSS attacks by an administrator. | |
| Modificada | Alta (7.1) | 0.41% | — | Eaton Halo Home | 22/5/2019 | 17/6/2026 | The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored… | |
| Modificada | Alta (8.8) | 0.43% | — | Eaton 9PX UPS Firmware | 24/10/2018 | 17/6/2026 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The administration panel is vulnerable to a CSRF attack on the change-password functionality. This vulnerability could be used to force a logged-in administrator to perform a silent password update. The affected forms are also vulnerable to Reflected Cross-Site… | |
| Modificada | Media (4.9) | 1.0% | — | Eaton 9PX UPS Firmware | 24/10/2018 | 17/6/2026 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the SNMP version 3 user's password. The web page displayed by the appliance contains the password in cleartext. Passwords of the read and write users could be retrieved by browsing the source code of the webpage. | |
| Modificada | Media (4.9) | 1.0% | — | Eaton 9PX UPS Firmware | 24/10/2018 | 17/6/2026 | An issue was discovered on Eaton UPS 9PX 8000 SP devices. The appliance discloses the user's password. The web page displayed by the appliance contains the password in cleartext. Passwords could be retrieved by browsing the source code of the webpage. | |
| Modificada | Crítica (9.8) | 35% | — | Eaton Power Xpert Meter 4000 FirmwareEaton Power Xpert Meter 6000 FirmwareEaton Power Xpert Meter 8000 Firmware | 30/8/2018 | 17/6/2026 | Eaton Power Xpert Meter 4000, 6000, and 8000 devices before 13.4.0.10 have a single SSH private key across different customers' installations and do not properly restrict access to this key, which makes it easier for remote attackers to perform SSH logins (to uid 0) via the PubkeyAuthentication option. | |
| Modificada | Crítica (9.8) | 6.8% | — | Eaton 9000x Firmware | 13/7/2018 | 17/6/2026 | Eaton 9000X DriveA versions 2.0.29 and prior has a stack-based buffer overflow vulnerability, which may allow remote code execution. | |
| Modificada | Crítica (9.8) | 20% | 💥 Exploit | Eaton Intelligent Power Manager | 7/6/2018 | 17/6/2026 | Local file inclusion in Eaton Intelligent Power Manager v1.6 allows an attacker to include a file via server/node_upgrade_srv.js directory traversal with the firmware parameter in a downloadFirmware action. | |
| Modificada | Media (5.3) | 2.0% | — | Eaton Elcsoft | 20/3/2018 | 17/6/2026 | In Eaton ELCSoft versions 2.04.02 and prior, there are multiple cases where specially crafted files could cause a buffer overflow which, in turn, may allow remote execution of arbitrary code. | |
| Modificada | Alta (7.5) | 1.3% | — | Eaton Xcomfort Ethernet Communication Interface | 14/3/2017 | 17/6/2026 | An issue was discovered in Eaton xComfort Ethernet Communication Interface (ECI) Versions 1.07 and prior. By accessing a specific uniform resource locator (URL) on the webserver, a malicious user may be able to access files without authenticating. | |
| Modificada | Media (5.3) | 1.9% | — | Eaton Eamxxx Series Epdu FirmwareEaton Emaxxx Series Epdu FirmwareEaton Eamaxx Series Epdu FirmwareEaton Emaaxx Series Epdu Firmware+1 | 13/2/2017 | 17/6/2026 | An issue was discovered in certain legacy Eaton ePDUs -- the affected products are past end-of-life (EoL) and no longer supported: EAMxxx prior to June 30, 2015, EMAxxx prior to January 31, 2014, EAMAxx prior to January 31, 2014, EMAAxx prior to January 31, 2014, and ESWAxx prior to January 31, 2014. An… | |
| Modificada | Alta (7.3) | 3.6% | — | Eaton Elcsoft | 3/7/2016 | 17/6/2026 | Stack-based buffer overflow in ELCSimulator in Eaton ELCSoft 2.4.01 and earlier allows remote attackers to execute arbitrary code via a long packet. | |
| Modificada | Media (6) | 2.0% | — | Eaton Elcsoft | 3/7/2016 | 17/6/2026 | Heap-based buffer overflow in elcsoft.exe in Eaton ELCSoft 2.4.01 and earlier allows remote authenticated users to execute arbitrary code via a crafted file. | |
| Modificada | Alta (7.5) | 1.2% | — | Eaton Lighting Systems EG2 WEB Control | 6/4/2016 | 17/6/2026 | Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to have an unspecified impact via a modified cookie. | |
| Modificada | Alta (7.5) | 1.5% | — | Eaton Lighting Systems EG2 WEB Control | 6/4/2016 | 17/6/2026 | Eaton Lighting EG2 Web Control 4.04P and earlier allows remote attackers to read the configuration file, and consequently discover credentials, via a direct request. | |
| Modificada | Media (5.3) | 1.1% | — | Eaton Proview | 23/12/2015 | 17/6/2026 | Eaton Cooper Power Systems ProView 4.x and 5.x before 5.1 on Form 6 controls and Idea and IdeaPLUS relays does not properly initialize padding fields in Ethernet packets, which allows remote attackers to obtain sensitive information by reading packet data. | |
| Modificada | Alta (9.3) | 2.3% | — | Eaton Proview | 20/7/2015 | 17/6/2026 | Eaton Cooper Power Systems ProView 4.0 and 5.0 before 5.0 11 on Form 6 controls and Idea and IdeaPLUS relays generates TCP initial sequence number (ISN) values linearly, which makes it easier for remote attackers to spoof TCP sessions by predicting an ISN value. | |
| Modificada | Alta (10) | 4.5% | — | Eaton Network Shutdown Module | 28/5/2009 | 16/6/2026 | Eaton MGEOPS Network Shutdown Module before 3.10 Build 13 allows remote attackers to execute arbitrary code by adding a custom action to the MGE frontend via pane_actionbutton.php, and then executing this action via exec_action.php. |