Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
66 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.6) | 0.39% | — | Schneider-electric Wonderware Historian Client | 19/5/2017 | 17/6/2026 | An Improper XML Parser Configuration issue was discovered in Schneider Electric Wonderware Historian Client 2014 R2 SP1 and prior. An improperly restricted XML parser (with improper restriction of XML external entity reference, or XXE) may allow an attacker to enter malicious input through the application which could… | |
| Modificada | Alta (7.3) | 1.7% | — | Schneider-electric Wonderware Historian | 13/2/2017 | 17/6/2026 | An issue was discovered in Schneider Electric Wonderware Historian 2014 R2 SP1 P01 and earlier. Wonderware Historian creates logins with default passwords, which can allow a malicious entity to compromise Historian databases. In some installation scenarios, resources beyond those created by Wonderware Historian may be… | |
| Modificada | Media (6.7) | 0.37% | — | GE CimplicityGE HistorianGE Ifix | 13/2/2017 | 17/6/2026 | An issue was discovered in General Electric (GE) Proficy HMI/SCADA iFIX Version 5.8 SIM 13 and prior versions, Proficy HMI/SCADA CIMPLICITY Version 9.0 and prior versions, and Proficy Historian Version 6.0 and prior versions. An attacker may be able to retrieve user passwords if he or she has access to an… | |
| Modificada | Alta (9.4) | 3.0% | — | Matrikonopc A&E Historian | 1/5/2013 | 16/6/2026 | Directory traversal vulnerability in the web interface in the Health Monitor service in MatrikonOPC A&E Historian 1.0.0.0 allows remote attackers to read and delete arbitrary files via a crafted URL. | |
| Modificada | Media (6.9) | 0.45% | — | Invensys Foxboro Control SoftwareInvensys Infusion Ce/fe/scadaInvensys IntouchInvensys Intouch/wonderware Application Server+3 | 26/7/2012 | 16/6/2026 | Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified… | |
| Modificada | Alta (10) | 4.6% | — | Wellintech Kinghistorian | 5/7/2012 | 16/6/2026 | WellinTech KingHistorian 3.0 allows remote attackers to execute arbitrary code or cause a denial of service (invalid pointer write) via a crafted packet to TCP port 5678. | |
| Modificada | Alta (9.3) | 40% | 💥 Exploit | Intelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy HistorianIntelligent Platforms Proficy Hmi/scada IfixIntelligent Platforms Proficy Pulse+1 | 5/7/2012 | 16/6/2026 | An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows… | |
| Modificada | Alta (9.3) | 28% | 💥 Exploit | EMC Captiva Quickscan PROEMC Documentum Applicationxtender DesktopIntelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy Historian+3 | 5/7/2012 | 16/6/2026 | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5;… | |
| Modificada | Alta (10) | 5.0% | — | Intelligent Platforms Proficy Historian | 15/3/2012 | 16/6/2026 | The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted session on TCP port 14000 to (1) ihDataArchiver.exe or (2) ihDataArchiver_x64.exe. | |
| Modificada | Media (5) | 1.7% | — | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Directory traversal vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Media (4.3) | 2.0% | — | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 13% | 💥 Exploit | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to execute arbitrary code or cause a denial of service via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Schneider-electric Vijeo HistorianSchneider-electric CitecthistorianSchneider-electric Citectscada Reports | 2/12/2011 | 16/6/2026 | Buffer overflow in the Steema TeeChart ActiveX control, as used in Schneider Electric Vijeo Historian 4.30 and earlier, CitectHistorian 4.30 and earlier, and CitectSCADAReports 4.10 and earlier, allows remote attackers to cause a denial of service via unspecified vectors. | |
| Modificada | Media (4.3) | 0.91% | — | Intelligent Platforms Proficy Historian | 2/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Administrator component in GE Intelligent Platforms Proficy Historian 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Alta (10) | 4.6% | — | Intelligent Platforms Proficy Historian | 2/11/2011 | 16/6/2026 | Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic to (1) PRProficyMgr.exe in Proficy Server Manager,… | |
| Modificada | Alta (10) | 6.3% | — | Intelligent Platforms Proficy Historian | 2/11/2011 | 16/6/2026 | Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic. |