Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 8.8% | 💥 Exploit | Modbustools Modbus Slave | 16/11/2018 | 17/6/2026 | Modbus Slave 7.0.0 in modbus tools has a Buffer Overflow. | |
| Modificada | Alta (7.5) | 2.4% | — | Siemens Dnp3 TCP FirmwareSiemens IEC 61850 FirmwareSiemens Iec104 FirmwareSiemens Modbus TCP Firmware+4 | 23/7/2018 | 17/6/2026 | A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All… | |
| Modificada | Alta (7.5) | 2.4% | — | Siemens Dnp3 TCP FirmwareSiemens IEC 61850 FirmwareSiemens Iec104 FirmwareSiemens Modbus TCP Firmware+4 | 23/7/2018 | 17/6/2026 | A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.33), Firmware variant PROFINET IO for EN100 Ethernet module (All versions), Firmware variant Modbus TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All… | |
| Modificada | Media (5.5) | 5.8% | 💥 Exploit | Modbuspal Project Modbuspal | 11/5/2018 | 17/6/2026 | ModbusPal 1.6b is vulnerable to an XML External Entity (XXE) attack. Projects are saved as .xmpp files and automations can be exported as .xmpa files, both XML-based, which are vulnerable to XXE injection. Sending a crafted .xmpp or .xmpa file to a user, when opened/imported in ModbusPal, will return the contents of… | |
| Modificada | Alta (7.5) | 1.8% | — | Siemens Siprotec Compact 7sj80 FirmwareSiemens Siprotec Compact 7sk80 FirmwareSiemens Siprotec 4 7sj66 FirmwareSiemens Digsi 4+5 | 8/3/2018 | 17/6/2026 | A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100… | |
| Modificada | Media (5.3) | 0.58% | — | Siemens Siprotec Compact 7sj80 FirmwareSiemens Siprotec Compact 7sk80 FirmwareSiemens Siprotec 4 7sj66 FirmwareSiemens Digsi 4+5 | 8/3/2018 | 17/6/2026 | A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100… | |
| Modificada | Alta (7.5) | 1.4% | — | Siemens En100 Ethernet Module IEC 104 FirmwareSiemens En100 Ethernet Module Dnp3 FirmwareSiemens En100 Ethernet Module Modbus TCP FirmwareSiemens En100 Ethernet Module Profinet IO Firmware+1 | 8/3/2018 | 17/6/2026 | A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module IEC 104 variant (All… | |
| Modificada | Crítica (9.8) | 5.2% | — | Schneider-electric Modbus Firmware | 30/6/2017 | 17/6/2026 | An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download. | |
| Modificada | Media (5.3) | 1.7% | — | Schneider-electric Modbus Firmware | 30/6/2017 | 17/6/2026 | A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-force attacks. | |
| Modificada | Alta (9.3) | 22% | 💥 Exploit | Schneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+9 | 1/4/2014 | 16/6/2026 | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header. | |
| Modificada | Media (6.8) | 27% | 💥 Exploit | Craig Peterson Turbopower AbbreviaScadatec ModbustagserverScadatec Scadaphone | 3/4/2012 | 16/6/2026 | Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file. | |
| Modificada | Alta (10) | 3.8% | — | Advantech Adam OPC ServerAdvantech Modbus RTU OPC ServerAdvantech Modbus TCP OPC Server | 21/2/2012 | 16/6/2026 | Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM OPC Server before 3.01.012, Modbus RTU OPC Server before 3.01.010, and Modbus TCP OPC Server before 3.01.010 allows remote attackers to execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 2.3% | — | Intellicom Netbiter Easyconnect Ec150Intellicom Netbiter Modbus Rtu-tcp Gateway Mb100Intellicom Netbiter Serial Ethernet Server Ss100Intellicom Netbiter Webscada Ws100+3 | 15/2/2011 | 16/6/2026 | WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms have a default username and password, which makes it easier for remote attackers to obtain superadmin access via the web interface, a different… | |
| Modificada | Alta (9) | 4.5% | — | Intellicom Netbiter Easyconnect Ec150Intellicom Netbiter Modbus Rtu-tcp Gateway Mb100Intellicom Netbiter Serial Ethernet Server Ss100Intellicom Netbiter Webscada Ws100+3 | 15/2/2011 | 16/6/2026 | cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's… | |
| Modificada | Media (6.8) | 1.6% | — | Intellicom Netbiter Easyconnect Ec150Intellicom Netbiter Modbus Rtu-tcp Gateway Mb100Intellicom Netbiter Serial Ethernet Server Ss100Intellicom Netbiter Webscada Ws100+3 | 15/2/2011 | 16/6/2026 | Absolute path traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to read arbitrary files via a full pathname in the… | |
| Modificada | Media (6.8) | 1.9% | — | Intellicom Netbiter Easyconnect Ec150Intellicom Netbiter Modbus Rtu-tcp Gateway Mb100Intellicom Netbiter Serial Ethernet Server Ss100Intellicom Netbiter Webscada Ws100+3 | 15/2/2011 | 16/6/2026 | Directory traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the page… | |
| Modificada | Alta (7.6) | 16% | 💥 Exploit | Automatedsolutions Modbus/tcp Master OPC Server | 28/1/2011 | 16/6/2026 | Heap-based buffer overflow in Automated Solutions Modbus/TCP Master OPC Server before 3.0.2 allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via a MODBUS response packet with a crafted length field. | |
| Modificada | Alta (7.5) | 4.7% | — | Automated Solutions Modbus Slave Activex Control | 19/9/2007 | 16/6/2026 | Unspecified vulnerability in the Modbus/TCP Diagnostic function in MiniHMI.exe for the Automated Solutions Modbus Slave ActiveX Control before 1.5 allows remote attackers to corrupt the heap and possibly execute arbitrary code via malformed Modbus requests to TCP port 502. |