Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2849▼ 221 respecto a la semana anterior
Críticas / altas1332▼ 165 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)222▼ 99 respecto a la semana anterior
–

2405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e374b. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer.
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.24%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e3c04. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaAlta (7.8)0.23%—Hornerautomation CscapeHornerautomation Cscape Envisionrv6/6/202317/6/2026
The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process.
ModificadaCrítica (9.8)0.86%—Sprecher-automation Sprecon-e-p Dq6-1 FirmwareSprecher-automation Sprecon-e-p Dl6-1 FirmwareSprecher-automation Sprecon-e-p Ds6-0 FirmwareSprecher-automation Sprecon-e-c Firmware+51/6/202317/6/2026
Hardcoded Credentials in multiple SPRECON-E CPU variants of Sprecher Automation allows an remote attacker to take over the device. These accounts should be deactivated according to Sprecher's hardening guidelines.
ModificadaMedia (6.8)0.34%—Sprecher-automation Sprecon-e-p Dq6-1 FirmwareSprecher-automation Sprecon-e-p Dl6-1 FirmwareSprecher-automation Sprecon-e-p Ds6-0 FirmwareSprecher-automation Sprecon-e-c Firmware+21/6/202317/6/2026
In Sprecher Automation SPRECON-E-C/P/T3 CPU in variant PU244x a vulnerable firmware verification has been identified. Through physical access and hardware manipulation, an attacker might be able to bypass hardware-based code verification and thus inject and execute arbitrary code and gain full access of the device.
ModificadaAlta (8.8)0.38%—Rockwellautomation Factorytalk Vantagepoint11/5/202317/6/2026
A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could…
ModificadaAlta (7.5)0.67%—Rockwellautomation Thinmanager11/5/202317/6/2026
Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API.
ModificadaCrítica (9.1)1.3%—Rockwellautomation Kinetix 5500 Firmware11/5/202317/6/2026
Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attackers unauthorized access to the device through the open ports.
ModificadaAlta (7.1)0.49%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.
ModificadaAlta (7.1)0.49%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…
ModificadaMedia (6.5)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discovered that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is…
ModificadaMedia (6.1)0.49%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability.
ModificadaMedia (5.9)0.62%—Rockwellautomation Armorstart ST 284ee FirmwareRockwellautomation Armorstart ST 281e Firmware11/5/202317/6/2026
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the…