Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

72 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.23%—Siemens Simatic PCS 7 FirmwareSiemens Simatic PDM FirmwareSiemens Simatic Step 7 FirmwareSiemens Sinamics Starter Firmware13/7/202117/6/2026
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.X (All versions < V9.1 SP2), SIMATIC PDM (All versions < V9.2 SP2), SIMATIC STEP 7 V5.X (All versions < V5.7), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 SP2 HF1). A directory containing…
ModificadaAlta (7.8)0.56%—Siemens Simatic PCS FirmwareSiemens Simatic PDM FirmwareSiemens Simatic Step 7 FirmwareSiemens Sinamics Starter Firmware13/7/202117/6/2026
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). The affected software…
ModificadaAlta (7.8)0.34%—Epson Album PrintEpson Color Calibration UtilityEpson ColorbaseEpson Colorio Easy Print+2924/11/202017/6/2026
Untrusted search path vulnerability in the installers of multiple SEIKO EPSON products allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaAlta (7.8)1.6%—Chocolatey Boxstarter20/10/202017/6/2026
The Boxstarter installer before version 2.13.0 configures C:\ProgramData\Boxstarter to be in the system-wide PATH environment variable. However, this directory is writable by normal, unprivileged users. To exploit the vulnerability, place a DLL in this directory that a privileged service is looking for. For example,…
ModificadaMedia (5.3)2.2%—Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+914/7/202017/6/2026
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS…
ModificadaAlta (8.2)2.5%—Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+914/7/202017/6/2026
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC IT LMS…
ModificadaMedia (6.7)0.38%—Siemens Opcenter Execution DiscreteSiemens Opcenter Execution FoundationSiemens Opcenter Execution ProcessSiemens Opcenter Intelligence+714/7/202017/6/2026
A vulnerability has been identified in Opcenter Execution Discrete (All versions < V3.2), Opcenter Execution Foundation (All versions < V3.2), Opcenter Execution Process (All versions < V3.2), Opcenter Intelligence (All versions < V3.3), Opcenter Quality (All versions < V11.3), Opcenter RD&L (V8.0), SIMATIC Notifier…
ModificadaAlta (7.8)0.42%—Siemens Simatic PCS 7Siemens Simatic Process Device ManagerSiemens Simatic Step 7Siemens Sinamics Starter10/6/202017/6/2026
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A buffer overflow…
ModificadaAlta (7.8)0.45%—Siemens Simatic PCS 7Siemens Simatic Process Device ManagerSiemens Simatic Step 7Siemens Sinamics Starter10/6/202017/6/2026
A vulnerability has been identified in SIMATIC PCS 7 V8.2 and earlier (All versions), SIMATIC PCS 7 V9.0 (All versions < V9.0 SP3), SIMATIC PDM (All versions < V9.2), SIMATIC STEP 7 V5.X (All versions < V5.6 SP2 HF3), SINAMICS STARTER (containing STEP 7 OEM version) (All versions < V5.4 HF2). A DLL Hijacking…
ModificadaMedia (6.7)0.46%—Siemens Simatic Automatic ToolSiemens Simatic NET PCSiemens Simatic PCS 7Siemens Simatic PCS NEO+1310/6/202017/6/2026
A vulnerability has been identified in SIMATIC Automation Tool (All versions < V4 SP2), SIMATIC NET PC Software V14 (All versions < V14 SP1 Update 14), SIMATIC NET PC Software V15 (All versions), SIMATIC NET PC Software V16 (All versions < V16 Upd3), SIMATIC PCS neo (All versions < V3.0 SP1), SIMATIC ProSave (All…
ModificadaMedia (6.8)0.40%—Phoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 2152 Starterkit Firmware18/6/201917/6/2026
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD card manipulation may lead to an authentication bypass opportunity.
ModificadaMedia (5.9)1.0%—Phoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 2152 Starterkit Firmware17/6/201917/6/2026
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually…
ModificadaAlta (8.7)3.3%—Siemens Simatic S7-200 FirmwareSiemens Simatic S7-400pn V6 FirmwareSiemens Simatic S7-400h V6 FirmwareSiemens Simatic S7-400pn/dp V7 Firmware+3426/12/201717/6/2026
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
ModificadaCrítica (9.8)3.0%💥 ExploitKickstarter Clone Script Project Kickstarter Clone Script13/12/201717/6/2026
Kickstarter Clone Script 2.0 has SQL Injection via the investcalc.php projid parameter.
ModificadaAlta (7.1)0.91%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+7511/5/201717/6/2026
Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected.
ModificadaAlta (7.1)1.1%—Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+8911/5/201717/6/2026
Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected.
ModificadaAlta (8.6)4.7%—Rockwellautomation Rslogix 500 Professional EditionRockwellautomation Rslogix 500 Standard EditionRockwellautomation Rslogix 500 Starter EditionRockwellautomation Rslogix Micro Developer+119/9/201617/6/2026
Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition, and RSLogix 500 Professional Edition allows remote attackers to execute arbitrary code via a crafted RSS project file.
ModificadaMedia (6.9)0.40%—Siemens StarterSiemens Simatic ProsaveSiemens Simotion ScoutSiemens Simatic CFC+17/3/201517/6/2026
Untrusted search path vulnerability in Siemens SIMATIC ProSave before 13 SP1; SIMATIC CFC before 8.0 SP4 Upd9 and 8.1 before Upd1; SIMATIC STEP 7 before 5.5 SP1 HF2, 5.5 SP2 before HF7, 5.5 SP3, and 5.5 SP4 before HF4; SIMOTION Scout before 4.4; and STARTER before 4.4 HF3 allows local users to gain privileges via a…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitGNU BashArista EOSOracle LinuxQnap QTS+7025/9/201417/6/2026
GNU Bash through 4.3 bash43-025 processes trailing strings after certain malformed function definitions in the values of environment variables, which allows remote attackers to write to files or possibly have unknown other impact via a crafted environment, as demonstrated by vectors involving the ForceCommand feature…
AnalizadaCrítica (9.8)100%⚠ Explotación activa💥 ExploitGNU BashArista EOSOracle LinuxQnap QTS+7024/9/201417/6/2026
GNU Bash through 4.3 processes trailing strings after function definitions in the values of environment variables, which allows remote attackers to execute arbitrary code via a crafted environment, as demonstrated by vectors involving the ForceCommand feature in OpenSSH sshd, the mod_cgi and mod_cgid modules in the…
ModificadaAlta (10)4.9%—Hitachi Cm2-network Node ManagerHitachi Cm2-network Node Manager 250Hitachi Jp1-cm2-network Node ManagerHitachi Jp1-cm2-network Node Manager 250+226/2/200716/6/2026
Multiple unspecified vulnerabilities in JP1/Cm2/Network Node Manager (NNM) before 07-10-05, and before 08-00-02 in the 08-x series, allow remote attackers to execute arbitrary code, cause a denial of service, or trigger invalid Web utility behavior.
ModificadaMedia (5)8.1%💥 ExploitAstaware SearchdiscSunone Starter KIT2/4/200316/6/2026
Directory traversal vulnerability in ASTAware SearchDisk engine for Sun ONE Starter Kit 2.0 allows remote attackers to read arbitrary files via a .. (dot dot) attack on port (1) 6015 or (2) 6016, or (3) an absolute pathname to port 6017.