Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
2356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 0.30% | — | Siemens Simatic CN 4100 Firmware | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V5.0). The affected application does not properly restrict unauthenticated connections and is susceptible to resource exhaustion conditions. This could allow an attacker to disrupt normal operations or perform unauthorized actions, potentially… | |
| Analizada | Alta (8.9) | 0.67% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Mx5000re FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+7 | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions <… | |
| Analizada | Media (6.1) | 0.40% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Mx5000re FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+7 | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions <… | |
| Analizada | Alta (7.7) | 0.54% | — | Siemens Ruggedcom ROX Mx5000 FirmwareSiemens Ruggedcom ROX Mx5000re FirmwareSiemens Ruggedcom ROX Rx1400 FirmwareSiemens Ruggedcom ROX Rx1500 Firmware+7 | 12/5/2026 | 29/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.1), RUGGEDCOM ROX MX5000RE (All versions < V2.17.1), RUGGEDCOM ROX RX1400 (All versions < V2.17.1), RUGGEDCOM ROX RX1500 (All versions < V2.17.1), RUGGEDCOM ROX RX1501 (All versions < V2.17.1), RUGGEDCOM ROX RX1510 (All versions <… | |
| Pendiente de análisis | Media (6.9) | 0.31% | — | Siemens Siprotec 5AI | 12/5/2026 | 17/6/2026 | A vulnerability has been identified in SIPROTEC 5 6MD84 (CP300) (All versions < V11.0), SIPROTEC 5 6MD85 (CP200) (All versions), SIPROTEC 5 6MD85 (CP300) (All versions >= V7.80 < V11.0), SIPROTEC 5 6MD86 (CP200) (All versions), SIPROTEC 5 6MD86 (CP300) (All versions >= V7.80 < V11.0), SIPROTEC 5 6MD89 (CP300) (All… | |
| Analizada | Crítica (9.3) | 32% | ⚠ Explotación activa💥 PoC | Paloaltonetworks Pan-osSiemens Ruggedcom Ape1808 Firmware | 6/5/2026 | 17/6/2026 | A buffer overflow vulnerability in the User-ID™ Authentication Portal (aka Captive Portal) service of Palo Alto Networks PAN-OS software allows an unauthenticated attacker to execute arbitrary code with root privileges on the PA-Series and VM-Series firewalls by sending specially crafted packets. The risk of this… | |
| Analizada | Alta (7.8) | 3.4% | ⚠ Explotación activa💥 Exploit | Linux KernelRedhat Openshift Container PlatformRedhat Enterprise LinuxRedhat Enterprise Linux AUS+44 | 22/4/2026 | 8/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: algif_aead - Revert to operating out-of-place This mostly reverts commit 72548b093ee3 except for the copying of the associated data. There is no benefit in operating in-place in algif_aead since the source and destination come from different… | |
| Pendiente de análisis | Media (5.1) | 0.36% | — | Siemens Industrial Edge Management PROAISiemens Industrial Edge Management VirtualAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in Industrial Edge Management Pro V1 (All versions >= V1.7.6 < V1.15.17), Industrial Edge Management Pro V2 (All versions >= V2.0.0 < V2.1.1), Industrial Edge Management Virtual (All versions >= V2.2.0 < V2.8.0). Affected management systems do not properly enforce user… | |
| Pendiente de análisis | Alta (8.7) | 0.42% | — | Siemens Ruggedcom Crossbow Secure Access Manager PrimaryAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM CROSSBOW Secure Access Manager Primary (SAM-P) (All versions < V5.8). User Administrators are allowed to administer groups they belong to. This could allow an authenticated User Administrator to escalate their own privileges and grant themselves access to any device… | |
| Pendiente de análisis | Alta (8.7) | 0.53% | — | Siemens Sinec NMSAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3). Affected products do not properly validate user authorization when processing password reset requests. This could allow an authenticated remote attacker to bypass authorization checks, leading to the ability to reset the password of any… | |
| Pendiente de análisis | Media (6.9) | 0.25% | — | Siemens Sinec NMSAI | 14/4/2026 | 17/6/2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3 with UMC). The affected application contains an authentication weakness due to insufficient validation of user identity in the UMC component. This could allow an unauthenticated remote attacker to bypass authentication and gain unauthorized… | |
| Analizada | Media (6.3) | 0.14% | — | Siemens Simcenter 3DSiemens Simcenter FemapSiemens Simcenter Star-ccm+ ViewerSiemens Software Center+3 | 14/4/2026 | 29/6/2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5.8.2), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Simcenter STAR-CCM+ (All versions < V2602), Solid Edge SE2025 (All versions < V225.0 Update 13), Solid Edge SE2026 (All versions < V226.0… | |
| Modificada | Alta (7.8) | 0.18% | — | Sudo Project SudoSiemens Sinec OS | 3/4/2026 | 1/9/2026 | In Sudo through 1.9.17p2 before 3e474c2, a failure of a setuid, setgid, or setgroups call, during a privilege drop before running the mailer, is not a fatal error and can lead to privilege escalation. | |
| Pendiente de análisis | Alta (8.7) | 0.51% | — | Siemens Cpci85AISiemens SicoreAI | 26/3/2026 | 17/6/2026 | A vulnerability has been identified in CPCI85 Central Processing/Communication (All versions < V26.10), SICORE Base system (All versions < V26.10.0). The affected application contains an out-of-bounds write vulnerability while parsing specially crafted XML inputs. This could allow an unauthenticated attacker to… | |
| Aplazada | Alta (8.2) | 0.13% | — | Siemens Software CenterAI | 18/3/2026 | 17/6/2026 | When a plugin is installed using the Arturia Software Center (MacOS), it also installs an uninstall.sh bash script in a root owned path. This script is written to disk with the file permissions 777, meaning it is writable by any user. When uninstalling a plugin via the Arturia Software Center the Privileged Helper… | |
| Aplazada | Alta (7.8) | 0.12% | — | Siemens Software CenterAI | 18/3/2026 | 17/6/2026 | The "Privileged Helper" component of the Arturia Software Center (MacOS) does not perform sufficient client code signature validation when a client connects. This leads to an attacker being able to connect to the helper and execute privileged actions leading to local privilege escalation. | |
| Analizada | Media (6.5) | 0.49% | — | OpensslSiemens Simatic CN 4100 Firmware | 13/3/2026 | 17/6/2026 | Issue summary: An OpenSSL TLS 1.3 server may fail to negotiate the expected preferred key exchange group when its key exchange group configuration includes the default by using the 'DEFAULT' keyword. Impact summary: A less preferred key exchange may be used even when a more preferred group is supported by both client… | |
| Analizada | Media (5.3) | 0.27% | — | Siemens Sinec Security Monitor | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.9.0). The affected application leaks confidential information in metadata, and files such as information on contributors and email address, on `SSM Server`. | |
| Analizada | Media (5.9) | 0.13% | — | Siemens Sicam Siapp SDK | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application performs file deletion without properly validating the file path or target. An attacker could delete files or sockets that the affected process has permission to remove, potentially resulting in denial of service… | |
| Analizada | Alta (8.6) | 0.50% | — | Siemens Sicam Siapp SDK | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The affected application builds shell commands with caller-provided strings and executes them. An attacker could influence the executed command, potentially resulting in command injection and full system compromise. | |
| Analizada | Media (5.9) | 0.12% | — | Siemens Sicam Siapp SDK | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK server component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially… | |
| Analizada | Media (5.9) | 0.12% | — | Siemens Sicam Siapp SDK | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK client component does not enforce maximum length checks on certain variables before use. This could allow an attacker to send an oversized input that could trigger a stack overflow crashing the process and potentially… | |
| Analizada | Alta (7.5) | 0.15% | — | Siemens Sicam Siapp SDK | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). The SICAM SIAPP SDK does not perform checks on input values potentially resulting in stack overflow. This could allow an attacker to perform code execution and denial of service. | |
| Analizada | Alta (7.5) | 0.15% | — | Siemens Sicam Siapp SDK | 10/3/2026 | 17/6/2026 | A vulnerability has been identified in SICAM SIAPP SDK (All versions < V2.1.7). An out-of-bounds write vulnerability exists in SICAM SIAPP SDK. This could allow an attacker to write data beyond the intended buffer, potentially leading to denial of service, or arbitrary code execution. | |
| Modificada | Alta (8.5) | 0.19% | — | Siemens Sinec NMSSiemens User Management Component | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP3), User Management Component (UMC) (All versions < V2.15.2.1). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to… |