Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3029▼ 65 respecto a la semana anterior
Críticas / altas1425▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

435 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.22%—Hitachienergy Microscada X Sys60024/6/202517/6/2026
A vulnerability exists in the IEC 61850 of the MicroSCADA X SYS600 product. An IEC 61850-8 crafted message content from IED or remote system can cause a denial of service resulting in disconnection loop.
AnalizadaAlta (8.3)0.23%—Hitachienergy Microscada X Sys60024/6/202517/6/2026
A vulnerability exists in in the Monitor Pro interface of the MicroSCADA X SYS600 product. An authenticated user with low privileges can see and overwrite files causing information leak and data corruption.
AnalizadaMedia (6.9)0.13%—Hitachienergy Microscada X Sys60024/6/202517/6/2026
A vulnerability exists in MicroSCADA X SYS600 product. If exploited this could allow a local unauthenticated attacker to tamper a system file, making denial of Notify service.
AplazadaMedia (6.4)0.21%—Diot ScadaAI14/6/202517/6/2026
The DIOT SCADA with MQTT plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the plugin's 'diot' shortcode in all versions up to, and including, 1.0.5.1 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers, with…
AnalizadaCrítica (9.3)1.7%—Myscada Mypro13/2/202517/6/2026
mySCADA myPRO Manager is vulnerable to an OS command injection which could allow a remote attacker to execute arbitrary OS commands.
AnalizadaCrítica (10)7.2%—Myscada Mypro13/2/202517/6/2026
The administrative web interface of mySCADA myPRO Manager can be accessed without authentication which could allow an unauthorized attacker to retrieve sensitive information and upload files without the associated password.
AnalizadaMedia (5.1)0.60%—Myscada Mypro13/2/202517/6/2026
mySCADA myPRO Manager is vulnerable to cross-site request forgery (CSRF), which could allow an attacker to obtain sensitive information. An attacker would need to trick the victim in to visiting an attacker-controlled website.
AnalizadaCrítica (9.2)3.6%—Myscada Mypro13/2/202517/6/2026
mySCADA myPRO Manager stores credentials in cleartext, which could allow an attacker to obtain sensitive information.
AplazadaCrítica (9.3)1.3%—Myscada MyproAI29/1/202517/6/2026
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with email information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
AplazadaCrítica (9.3)1.3%—Myscada MyproAI29/1/202517/6/2026
mySCADA myPRO does not properly neutralize POST requests sent to a specific port with version information. This vulnerability could be exploited by an attacker to execute arbitrary commands on the affected system.
AplazadaAlta (8.6)0.50%—Ininet Solutions Spidercontrol Scada PC HMI EditorAI24/10/202417/6/2026
iniNet Solutions SpiderControl SCADA PC HMI Editor has a path traversal vulnerability. When the software loads a malicious ‘ems' project template file constructed by an attacker, it can write files to arbitrary directories. This can lead to overwriting system files, causing system paralysis, or writing to startup…
AplazadaAlta (7)0.65%—Laquis ScadaAI17/10/202417/6/2026
In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions.
ModificadaAlta (7.5)0.35%—Rapidscada Rapid Scada22/9/202417/6/2026
CheckUser in ScadaServerEngine/MainLogic.cs in Rapid SCADA through 5.8.4 allows an empty password.
AplazadaAlta (8.7)13%—Spidercontrol Scada WEB ServerAI10/9/202417/6/2026
SpiderControl SCADA Web Server has a vulnerability that could allow an attacker to upload specially crafted malicious files without authentication.
AnalizadaMedia (4.3)0.34%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
An HTTP parameter may contain a URL value and could cause the web application to redirect the request to the specified URL. By modifying the URL value to a malicious site, an attacker may successfully launch a phishing scam and steal user credentials.
AnalizadaCrítica (9.8)0.58%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
The product exposes a service that is intended for local only to all network interfaces without any authentication.
AnalizadaAlta (8.8)0.50%—Hitachienergy Microscada PRO Sys600Hitachienergy Microscada X Sys60027/8/202417/6/2026
A vulnerability exists in the query validation of the MicroSCADA Pro/X SYS600 product. If exploited this could allow an authenticated attacker to inject code towards persistent data. Note that to successfully exploit this vulnerability an attacker must have a valid credential.
AnalizadaAlta (8.2)0.22%—Hitachienergy Microscada X Sys60027/8/202417/6/2026
An attacker with local access to machine where MicroSCADA X SYS600 is installed, could enable the session logging supporting the product and try to exploit a session hijacking of an already established session. By default, the session logging level is not enabled and only users with administrator rights can enable it.
AnalizadaAlta (8.8)0.61%—Hitachienergy Microscada PRO Sys600Hitachienergy Microscada X Sys60027/8/202417/6/2026
The MicroSCADA Pro/X SYS600 product allows an authenticated user input to control or influence paths or file names that are used in filesystem operations. If exploited the vulnerability allows the attacker to access or modify system files or other files that are critical to the application.
AnalizadaMedia (5.3)0.36%—Scada-lts17/8/202417/6/2026
A vulnerability has been found in Scada-LTS 2.7.8 and classified as problematic. Affected by this vulnerability is an unknown functionality of the file /Scada-LTS/app.shtm#/alarms/Scada of the component Message Handler. The manipulation leads to cross site scripting. The attack can be launched remotely. The exploit…
ModificadaCrítica (9.3)1.00%—Myscada Mypro2/7/202417/6/2026
mySCADA myPRO uses a hard-coded password which could allow an attacker to remotely execute code on the affected device.
AplazadaCrítica (9.3)0.66%—SDG Technologies PnpscadaAI27/6/202417/6/2026
SDG Technologies PnPSCADA allows a remote attacker to attach various entities without requiring system authentication. This breach could potentially lead to unauthorized control, data manipulation, and access to sensitive information within the SCADA system.
AplazadaAlta (8.5)0.41%—Lcds Laquis ScadaAI21/5/202417/6/2026
There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory.
AnalizadaAlta (8.8)2.3%—Trianglemicroworks Scada Data Gateway7/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Restore Workspace Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability,…
AnalizadaAlta (7.2)1.9%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway DbasSectorFileToExecuteOnReset Exposed Dangerous Function Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is required to exploit this…