Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
130 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.1% | — | Libiec Iccp MOD Project Libiec Iccp MOD | 31/8/2021 | 17/6/2026 | A heap buffer-overflow in the client_example1.c component of libiec_iccp_mod v1.5 leads to a denial of service (DOS). | |
| Modificada | Alta (7.5) | 1.1% | — | Iec104 Project Iec104 | 31/8/2021 | 17/6/2026 | IEC104 v1.0 contains a stack-buffer overflow in the parameter Iec10x_Sta_Addr. | |
| Modificada | Alta (7.5) | 1.4% | — | Iec104 Project Iec104 | 23/8/2021 | 17/6/2026 | A segmentation violation in the Iec104_Deal_FirmUpdate function of IEC104 v1.0 allows attackers to cause a denial of service (DOS). | |
| Modificada | Alta (7.5) | 1.4% | — | Iec104 Project Iec104 | 23/8/2021 | 17/6/2026 | A segmentation violation in the Iec104_Deal_I function of IEC104 v1.0 allows attackers to cause a denial of service (DOS). | |
| Modificada | Crítica (9.8) | 6.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Improper Handling of Length Parameter Inconsistency vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all… | |
| Modificada | Crítica (9.8) | 3.9% | — | Mitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data Transfer+37 | 19/2/2021 | 17/6/2026 | Heap-based buffer overflow vulnerability in Mitsubishi Electric FA Engineering Software (CPU Module Logging Configuration Tool versions 1.112R and prior, CW Configurator versions 1.011M and prior, Data Transfer versions 3.44W and prior, EZSocket versions 5.4 and prior, FR Configurator all versions, FR Configurator SW3… | |
| Modificada | Alta (7.5) | 1.3% | — | Freyrscada Iec-60879-5-104 Server Simulator | 11/1/2021 | 17/6/2026 | A denial-of-service vulnerability exists in the traffic-logging functionality of FreyrSCADA IEC-60879-5-104 Server Simulator 21.04.028. A specially crafted packet can lead to denial of service. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.0% | — | Mz-automation Libiec61850 | 26/8/2020 | 17/6/2026 | In libIEC61850 before version 1.4.3, when a message with COTP message length field with value < 4 is received an integer underflow will happen leading to heap buffer overflow. This can cause an application crash or on some platforms even the execution of remote code. If your application is used in open networks or… | |
| Modificada | Media (5.4) | 0.68% | — | Grafana Piechart-panel | 24/5/2020 | 17/6/2026 | legend.ts in the piechart-panel (aka Pie Chart Panel) plugin before 1.5.0 for Grafana allows XSS via the Values Header (aka legend header) option. | |
| Modificada | Alta (8.8) | 1.1% | — | Mz-automation Libiec61850 | 14/1/2020 | 17/6/2026 | MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c in libIEC61850 through 1.4.0 has a heap-based buffer overflow when parsing the MMS_BIT_STRING data type. | |
| Modificada | Alta (7.5) | 1.3% | — | Aveva Iec870ip Firmware | 14/1/2020 | 17/6/2026 | The IEC870IP driver for AVEVA’s Vijeo Citect and Citect SCADA and Schneider Electric’s Power SCADA Operation has a buffer overflow vulnerability that could result in a server-side crash. | |
| Modificada | Media (6.5) | 0.94% | — | Mz-automation Libiec61850 | 24/12/2019 | 17/6/2026 | In libIEC61850 1.4.0, StringUtils_createStringFromBuffer in common/string_utilities.c has an integer signedness issue that could lead to an attempted excessive memory allocation and denial of service. | |
| Modificada | Media (6.5) | 0.94% | — | Mz-automation Libiec61850 | 24/12/2019 | 17/6/2026 | In libIEC61850 1.4.0, getNumberOfElements in mms/iso_mms/server/mms_access_result.c has an out-of-bounds read vulnerability, related to bufPos and elementLength. | |
| Modificada | Media (6.5) | 0.94% | — | Mz-automation Libiec61850 | 23/12/2019 | 17/6/2026 | In libIEC61850 1.4.0, BerDecoder_decodeUint32 in mms/asn1/ber_decode.c has an out-of-bounds read, related to intLen and bufPos. | |
| Modificada | Alta (8.8) | 1.3% | — | Mz-automation Libiec61850 | 23/12/2019 | 17/6/2026 | In libIEC61850 1.4.0, MmsValue_decodeMmsData in mms/iso_mms/server/mms_access_result.c has a heap-based buffer overflow. | |
| Modificada | Media (6.5) | 1.1% | — | Mz-automation Libiec61850 | 23/12/2019 | 17/6/2026 | In libIEC61850 1.4.0, MmsValue_newOctetString in mms/iso_mms/common/mms_value.c has an integer signedness error that can lead to an attempted excessive memory allocation. | |
| Modificada | Media (5.3) | 1.6% | — | Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+1 | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All… | |
| Modificada | Media (6.1) | 0.89% | — | Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+1 | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All… | |
| Modificada | Alta (7.5) | 1.9% | — | Siemens En100 Ethernet Module With Firmware Variant Dnp3 TCPSiemens En100 Ethernet Module With Firmware Variant IEC 61850Siemens En100 Ethernet Module With Firmware Variant Iec104Siemens En100 Ethernet Module With Firmware Variant Modbus TCP+1 | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in EN100 Ethernet module DNP3 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.37), EN100 Ethernet module IEC104 variant (All versions), EN100 Ethernet module Modbus TCP variant (All versions), EN100 Ethernet module PROFINET IO variant (All… | |
| Modificada | Alta (7.5) | 1.4% | — | Mz-automation Libiec61850 | 19/9/2019 | 17/6/2026 | libIEC61850 through 1.3.3 has a use-after-free in MmsServer_waitReady in mms/iso_mms/server/mms_server.c, as demonstrated by server_example_goose. | |
| Modificada | Alta (7.5) | 1.3% | — | Mz-automation Libiec61850 | 15/7/2019 | 17/6/2026 | mz-automation libiec61850 1.3.2 1.3.1 1.3.0 is affected by: Buffer Overflow. The impact is: Software crash. The component is: server_example_complex_array. The attack vector is: Send a specific MMS protocol packet. | |
| Modificada | Media (5.9) | 1.2% | — | Siemens Siprotec 5 With CPU Variant Cp100Siemens Siprotec 5 With CPU Variant Cp200Siemens Siprotec 5 With CPU Variant Cp300Siemens En100 Ethernet Module Firmware+5 | 21/3/2019 | 17/6/2026 | A vulnerability has been identified in Firmware variant IEC 61850 for EN100 Ethernet module (All versions < V4.35), Firmware variant MODBUS TCP for EN100 Ethernet module (All versions), Firmware variant DNP3 TCP for EN100 Ethernet module (All versions), Firmware variant IEC104 for EN100 Ethernet module (All versions),… | |
| Modificada | Alta (8.8) | 2.6% | — | Psigridconnect Telecontrol Gateway Xs-mu FirmwarePsigridconnect Telecontrol Gateway VM FirmwarePsigridconnect Telecontrol Gateway 3G FirmwarePsigridconnect Smart Telecontrol Unit TCG Firmware+1 | 5/3/2019 | 17/6/2026 | PSI GridConnect GmbH Telecontrol Gateway and Smart Telecontrol Unit family, IEC104 Security Proxy versions Telecontrol Gateway 3G Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway XS-MU Versions 4.2.21, 5.0.27, 5.1.19, 6.0.16 and prior, and Telecontrol Gateway VM Versions 4.2.21, 5.0.27,… | |
| Modificada | Media (6.1) | 1.3% | — | Grafana Piechart-panel | 6/2/2019 | 17/6/2026 | The Pie Chart Panel plugin through 2019-01-02 for Grafana is vulnerable to XSS via legend data or tooltip data. When a chart is included in a Grafana dashboard, this vulnerability could allow an attacker to gain remote unauthenticated access to the dashboard. | |
| Modificada | Alta (7.5) | 1.5% | — | Mz-automation Libiec61850 | 23/1/2019 | 17/6/2026 | An issue has been found in libIEC61850 v1.3.1. There is a use-after-free in the getState function in mms/iso_server/iso_server.c, as demonstrated by examples/server_example_goose/server_example_goose.c and examples/server_example_61400_25/server_example_61400_25.c. |