Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
–

107 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.4%—Siemens En100 Ethernet Module IEC 104 FirmwareSiemens En100 Ethernet Module Dnp3 FirmwareSiemens En100 Ethernet Module Modbus TCP FirmwareSiemens En100 Ethernet Module Profinet IO Firmware+18/3/201817/6/2026
A vulnerability has been identified in EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module DNP3 variant (All versions < V1.04), EN100 Ethernet module PROFINET IO variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module IEC 104 variant (All…
ModificadaCrítica (9.8)5.2%—Schneider-electric Modbus Firmware30/6/201717/6/2026
An authentication bypass by capture-replay issue was discovered in Schneider Electric Modicon Modbus Protocol. Sensitive information is transmitted in cleartext in the Modicon Modbus protocol, which may allow an attacker to replay the following commands: run, stop, upload, and download.
ModificadaMedia (5.3)1.7%—Schneider-electric Modbus Firmware30/6/201717/6/2026
A Violation of Secure Design Principles issue was discovered in Schneider Electric Modicon Modbus Protocol. The Modicon Modbus protocol has a session-related weakness making it susceptible to brute-force attacks.
ModificadaBaja (1.9)0.27%—Freedesktop DbusOpensuse13/2/201517/6/2026
D-Bus 1.4.x through 1.6.x before 1.6.30, 1.8.x before 1.8.16, and 1.9.x before 1.9.10 does not validate the source of ActivationFailure signals, which allows local users to cause a denial of service (activation failure error returned) by leveraging a race condition involving sending an ActivationFailure signal before…
ModificadaBaja (2.1)0.59%—Freedesktop DbusDebian LinuxMageia Project MageiaCanonical Ubuntu Linux18/11/201417/6/2026
D-Bus 1.3.0 through 1.6.x before 1.6.26, 1.8.x before 1.8.10, and 1.9.x before 1.9.2 allows local users to cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors. NOTE: this vulnerability exists because of an incomplete fix for CVE-2014-3636.1.
ModificadaBaja (1.9)0.51%—D-bus Project D-busFreedesktop DbusOpensuse25/10/201417/6/2026
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 allows local users to (1) cause a denial of service (prevention of new connections and connection drop) by queuing the maximum number of file descriptors or (2) cause a denial of service (disconnect) via multiple messages that combine to have more than the…
ModificadaBaja (2.1)0.40%—OpensuseD-bus Project D-busFreedesktop Dbus22/9/201417/6/2026
The dbus-daemon in D-Bus before 1.6.24 and 1.8.x before 1.8.8 does not properly close old connections, which allows local users to cause a denial of service (incomplete connection consumption and prevention of new connections) via a large number of incomplete connections.
ModificadaBaja (2.1)0.39%—D-bus Project D-busFreedesktop DbusOpensuse22/9/201417/6/2026
The bus_connections_check_reply function in config-parser.c in D-Bus before 1.6.24 and 1.8.x before 1.8.8 allows local users to cause a denial of service (CPU consumption) via a large number of method calls.
ModificadaBaja (2.1)0.45%—Freedesktop DbusOpensuse22/9/201417/6/2026
D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8 does not properly close connections for processes that have terminated, which allows local users to cause a denial of service via a D-bus message containing a D-Bus connection file descriptor.
ModificadaMedia (4.4)0.49%—D-bus Project D-busFreedesktop DbusOpensuse22/9/201417/6/2026
Off-by-one error in D-Bus 1.3.0 through 1.6.x before 1.6.24 and 1.8.x before 1.8.8, when running on a 64-bit system and the max_message_unix_fds limit is set to an odd number, allows local users to cause a denial of service (dbus-daemon crash) or possibly execute arbitrary code by sending one more file descriptor than…
ModificadaBaja (2.1)0.42%—Debian LinuxFreedesktop DbusMageia Project MageiaOpensuse19/7/201417/6/2026
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6 allows local users to cause a denial of service (disconnect) via a certain sequence of crafted messages that cause the dbus-daemon to forward a message containing an invalid file descriptor.
ModificadaBaja (2.1)0.45%—Freedesktop DbusOpensuseDebian LinuxMageia+119/7/201417/6/2026
dbus 1.3.0 before 1.6.22 and 1.8.x before 1.8.6, when running on Linux 2.6.37-rc4 or later, allows local users to cause a denial of service (system-bus disconnect of other services or applications) by sending a message containing a file descriptor, then exceeding the maximum recursion depth before the initial message…
ModificadaMedia (4)0.44%—D-bus Project D-busFreedesktop Dbus1/7/201417/6/2026
The dbus-daemon in D-Bus 1.2.x through 1.4.x, 1.6.x before 1.6.20, and 1.8.x before 1.8.4, sends an AccessDenied error to the service instead of a client when the client is prohibited from accessing the service, which allows local users to cause a denial of service (initialization failure and exit) or possibly conduct…
ModificadaAlta (9.3)22%💥 ExploitSchneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+91/4/201416/6/2026
Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header.
ModificadaBaja (1.9)0.38%—Freedesktop DbusOpensuse3/7/201316/6/2026
The _dbus_printf_string_upper_bound function in dbus/dbus-sysdeps-unix.c in D-Bus (aka DBus) 1.4.x before 1.4.26, 1.6.x before 1.6.12, and 1.7.x before 1.7.4 allows local users to cause a denial of service (service crash) via a crafted message.
ModificadaAlta (7.2)1.1%💥 ExploitFreedesktop Dbus-glib5/3/201316/6/2026
The dbus_g_proxy_manager_filter function in dbus-gproxy in Dbus-glib before 0.100.1 does not properly verify the sender of NameOwnerChanged signals, which allows local users to gain privileges via a spoofed signal.
ModificadaMedia (6.9)4.5%💥 ExploitFreedesktop Libdbus18/9/201216/6/2026
libdbus 1.5.x and earlier, when used in setuid or other privileged programs in X.org and possibly other products, allows local users to gain privileges and execute arbitrary code via the DBUS_SYSTEM_BUS_ADDRESS environment variable. NOTE: libdbus maintainers state that this is a vulnerability in the applications that…
ModificadaMedia (6.8)27%💥 ExploitCraig Peterson Turbopower AbbreviaScadatec ModbustagserverScadatec Scadaphone3/4/201216/6/2026
Buffer overflow in TurboPower Abbrevia before 4.0, as used in ScadaTEC ScadaPhone 5.3.11.1230 and earlier, ScadaTEC ModbusTagServer 4.1.1.81 and earlier, and other products, allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a crafted ZIP file.
ModificadaAlta (10)3.8%—Advantech Adam OPC ServerAdvantech Modbus RTU OPC ServerAdvantech Modbus TCP OPC Server21/2/201216/6/2026
Buffer overflow in the Advantech ADAM OLE for Process Control (OPC) Server ActiveX control in ADAM OPC Server before 3.01.012, Modbus RTU OPC Server before 3.01.010, and Modbus TCP OPC Server before 3.01.010 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaBaja (3.3)0.29%—Freedesktop Dbus22/6/201116/6/2026
The configure script in D-Bus (aka DBus) 1.2.x before 1.2.28 allows local users to overwrite arbitrary files via a symlink attack on an unspecified file in /tmp/.
ModificadaMedia (4.6)0.39%—Freedesktop DbusD-bus Project D-bus22/6/201116/6/2026
The _dbus_header_byteswap function in dbus-marshal-header.c in D-Bus (aka DBus) 1.2.x before 1.2.28, 1.4.x before 1.4.12, and 1.5.x before 1.5.4 does not properly handle a non-native byte order, which allows local users to cause a denial of service (connection loss), obtain potentially sensitive information, or…
ModificadaAlta (10)2.3%—Intellicom Netbiter Easyconnect Ec150Intellicom Netbiter Modbus Rtu-tcp Gateway Mb100Intellicom Netbiter Serial Ethernet Server Ss100Intellicom Netbiter Webscada Ws100+315/2/201116/6/2026
WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms have a default username and password, which makes it easier for remote attackers to obtain superadmin access via the web interface, a different…
ModificadaAlta (9)4.5%—Intellicom Netbiter Easyconnect Ec150Intellicom Netbiter Modbus Rtu-tcp Gateway Mb100Intellicom Netbiter Serial Ethernet Server Ss100Intellicom Netbiter Webscada Ws100+315/2/201116/6/2026
cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to execute arbitrary code by using a config.html 2.conf action to replace the logo page's…
ModificadaMedia (6.8)1.6%—Intellicom Netbiter Easyconnect Ec150Intellicom Netbiter Modbus Rtu-tcp Gateway Mb100Intellicom Netbiter Serial Ethernet Server Ss100Intellicom Netbiter Webscada Ws100+315/2/201116/6/2026
Absolute path traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to read arbitrary files via a full pathname in the…
ModificadaMedia (6.8)1.9%—Intellicom Netbiter Easyconnect Ec150Intellicom Netbiter Modbus Rtu-tcp Gateway Mb100Intellicom Netbiter Serial Ethernet Server Ss100Intellicom Netbiter Webscada Ws100+315/2/201116/6/2026
Directory traversal vulnerability in cgi-bin/read.cgi in WebSCADA WS100 and WS200, Easy Connect EC150, Modbus RTU - TCP Gateway MB100, and Serial Ethernet Server SS100 on the IntelliCom NetBiter NB100 and NB200 platforms allows remote authenticated administrators to read arbitrary files via a .. (dot dot) in the page…
Orbitaley — Vulnerabilidades