Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
2405 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 18% | — | Rockwellautomation Thinmanager | 22/3/2023 | 17/6/2026 | In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation. | |
| Modificada | Alta (7.5) | 77% | — | Rockwellautomation Thinmanager | 22/3/2023 | 17/6/2026 | In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed. | |
| Modificada | Crítica (9.8) | 13% | — | Rockwellautomation Thinmanager | 22/3/2023 | 17/6/2026 | In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could… | |
| Modificada | Media (5.5) | 4.1% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 1.8% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 1.8% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (4.3) | 0.85% | — | Rockwellautomation Modbus TCP Server ADD ON Instructions | 17/3/2023 | 17/6/2026 | Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP… | |
| Modificada | Baja (3.2) | 0.22% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 15/3/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710. | |
| Modificada | Media (6.5) | 0.60% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 15/3/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032. | |
| Modificada | Media (6.5) | 0.50% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 15/3/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951. | |
| Modificada | Crítica (9.8) | 0.71% | — | Alpatateknoloji Licensed Warehousing Automation System | 10/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in reads past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Media (5.4) | 0.36% | — | Yordam Library Automation System | 2/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS. This issue affects Library Automation System: before 19.2. | |
| Modificada | Media (6.5) | 0.59% | — | Yordam Library Automation System | 2/3/2023 | 17/6/2026 | Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2. | |
| Modificada | Media (6.5) | 0.59% | — | Yordam Library Automation System | 2/3/2023 | 17/6/2026 | Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2. | |
| Modificada | Crítica (9.8) | 0.67% | — | Uzaybaskul Weighbridge Automation Software | 1/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1. | |
| Modificada | Alta (7.1) | 0.15% | — | Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+1 | 28/2/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,… | |
| Modificada | Media (5.4) | 0.39% | — | IBM Cloud PAK FOR Business Automation | 27/2/2023 | 17/6/2026 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Modificada | Media (5.5) | 0.24% | — | Mz-automation Lib60870 | 24/2/2023 | 17/6/2026 | Se descubrió un problema en lib60870 v2.3.2. Hay una pérdida de memoria en lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c. | |
| Modificada | Crítica (9.8) | 12% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. |