Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2827▼ 257 respecto a la semana anterior
Críticas / altas1324▼ 180 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)214▼ 107 respecto a la semana anterior
–

2405 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)18%—Rockwellautomation Thinmanager22/3/202317/6/2026
In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation.
ModificadaAlta (7.5)77%—Rockwellautomation Thinmanager22/3/202317/6/2026
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed.
ModificadaCrítica (9.8)13%—Rockwellautomation Thinmanager22/3/202317/6/2026
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could…
ModificadaMedia (5.5)4.1%—Visam Vbase Automation Base21/3/202317/6/2026
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
ModificadaMedia (5.5)1.8%—Visam Vbase Automation Base21/3/202317/6/2026
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
ModificadaMedia (5.5)1.8%—Visam Vbase Automation Base21/3/202317/6/2026
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
ModificadaMedia (5.5)0.26%—Visam Vbase Automation Base21/3/202317/6/2026
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
ModificadaMedia (5.5)0.26%—Visam Vbase Automation Base21/3/202317/6/2026
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
ModificadaMedia (5.5)0.26%—Visam Vbase Automation Base21/3/202317/6/2026
Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file.
ModificadaMedia (4.3)0.85%—Rockwellautomation Modbus TCP Server ADD ON Instructions17/3/202317/6/2026
Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP…
ModificadaBaja (3.2)0.22%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service15/3/202317/6/2026
IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710.
ModificadaMedia (6.5)0.60%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK15/3/202317/6/2026
IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032.
ModificadaMedia (6.5)0.50%—IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK15/3/202317/6/2026
IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951.
ModificadaCrítica (9.8)0.71%—Alpatateknoloji Licensed Warehousing Automation System10/3/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01.
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in reads past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaMedia (5.4)0.36%—Yordam Library Automation System2/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS. This issue affects Library Automation System: before 19.2.
ModificadaMedia (6.5)0.59%—Yordam Library Automation System2/3/202317/6/2026
Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2.
ModificadaMedia (6.5)0.59%—Yordam Library Automation System2/3/202317/6/2026
Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2.
ModificadaCrítica (9.8)0.67%—Uzaybaskul Weighbridge Automation Software1/3/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1.
ModificadaAlta (7.1)0.15%—Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+128/2/202317/6/2026
Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,…
ModificadaMedia (5.4)0.39%—IBM Cloud PAK FOR Business Automation27/2/202317/6/2026
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…
ModificadaMedia (5.5)0.24%—Mz-automation Lib6087024/2/202317/6/2026
Se descubrió un problema en lib60870 v2.3.2. Hay una pérdida de memoria en lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.
ModificadaCrítica (9.8)12%—GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+523/2/202317/6/2026
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.