Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2632▼ 455 respecto a la semana anterior
Críticas / altas1285▼ 65 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 275 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.7) | 0.81% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'GetProjects' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.81% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UnlockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.81% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'LockProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.81% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'DeleteProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.81% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.81% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateOpcSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.81% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateGateways' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateProject' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateBufferingSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateSmtpSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateTcmSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateDatabaseSettings' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateUsers' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'ImportDatabase' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateProjectConnections' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to… | |
| Analizada | Alta (8.7) | 0.86% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'UpdateConnectionVariables' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write… | |
| Analizada | Alta (8.7) | 0.89% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'RestoreFromBackup' method. This could allow an authenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Crítica (9.3) | 1.0% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'Authenticate' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Crítica (9.3) | 1.0% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'VerifyUser' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Crítica (9.3) | 1.0% | — | Siemens Telecontrol Server Basic | 16/4/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.2). The affected application is vulnerable to SQL injection through the internally used 'CreateTrace' method. This could allow an unauthenticated remote attacker to bypass authorization controls, to read from and write to the… | |
| Analizada | Crítica (10) | 1.00% | — | Siemens Telecontrol Server Basic | 12/11/2024 | 17/6/2026 | A vulnerability has been identified in PP TeleControl Server Basic 1000 to 5000 V3.1 (6NH9910-0AA31-0AE1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 256 to 1000 V3.1 (6NH9910-0AA31-0AD1) (All versions < V3.1.2.1 with redundancy configured), PP TeleControl Server Basic 32 to 64… | |
| Modificada | Media (6.5) | 1.4% | — | Opcfoundation Ua-nodesetSiemens Simatic NET PCSiemens Sitop ManagerSiemens Telecontrol Server Basic | 21/3/2022 | 17/6/2026 | The OPC autogenerated ANSI C stack stubs (in the NodeSets) do not handle all error cases. This can lead to a NULL pointer dereference. | |
| Modificada | Alta (7.5) | 2.6% | — | Opcfoundation Local Discover ServerSiemens Simatic Process Historian OPC UA Server FirmwareSiemens Simatic NET PCSiemens Simatic Wincc+3 | 27/8/2021 | 17/6/2026 | In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer. | |
| Modificada | Alta (7.5) | 1.6% | — | Siemens Simatic Cp443-1 OPC UA FirmwareSiemens Simatic ET 200 Open Controller CPU 1515sp PC2 FirmwareSiemens Simatic IPC Diagmonitor FirmwareSiemens Simatic NET PC Software Firmware+23 | 17/4/2019 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 443-1 OPC UA (All versions), SIMATIC ET 200SP Open Controller CPU 1515SP PC2 (incl. SIPLUS variants) (All versions < V2.7), SIMATIC HMI Comfort Outdoor Panels 7" & 15" (incl. SIPLUS variants) (All versions < V15.1 Upd 4), SIMATIC HMI Comfort Panels 4" - 22" (incl.… | |
| Modificada | Alta (7.5) | 2.7% | — | Siemens Telecontrol Server Basic | 25/1/2018 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic < V3.1. An attacker with access to the TeleControl Server Basic's webserver (port 80/tcp or 443/tcp) could cause a Denial-of-Service condition on the web server. The remaining functionality of the TeleControl Server Basic is not affected by the… |