Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)298▼ 212 respecto a la semana anterior
–

435 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.3)0.58%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway certificate Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw…
AnalizadaMedia (5.3)1.0%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway get_config Missing Authentication Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.…
AnalizadaAlta (7.5)0.76%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Cryptograhic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability.…
AnalizadaAlta (7.2)2.0%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway GTWWebMonitorService Unquoted Search Path Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the…
AnalizadaAlta (7.2)1.2%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Trusted Certification Unrestricted Upload of File Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this…
AnalizadaMedia (6.5)1.5%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Workspace Unrestricted Upload Vulnerability. This vulnerability allows remote attackers to upload arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the existing authentication…
AnalizadaMedia (4.4)1.3%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Event Log Improper Output Neutralization For Logs Arbitrary File Write Vulnerability. This vulnerability allows remote attackers to write arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this…
AnalizadaAlta (7.2)3.4%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Event Log Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. Although authentication is required to exploit this vulnerability, the…
AnalizadaAlta (7.8)0.96%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Directory Traversal Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Triangle MicroWorks SCADA Data Gateway. User interaction is required to exploit this vulnerability in that the target must…
AnalizadaMedia (5.3)0.24%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Use of Hard-coded Credentials Authentication Bypass Vulnerability. This vulnerability allows network-adjacent attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The…
AnalizadaCrítica (9.8)2.0%—Trianglemicroworks Scada Data Gateway3/5/202417/6/2026
Triangle MicroWorks SCADA Data Gateway Missing Authentication Vulnerability. This vulnerability allows remote attackers to bypass authentication on affected installations of Triangle MicroWorks SCADA Data Gateway. Authentication is not required to exploit this vulnerability. The specific flaw exists due to the lack of…
AnalizadaMedia (6.8)0.18%—Measuresoft Scadapro Server30/4/202417/6/2026
The entire parent directory - C:\ScadaPro and its sub-directories and files are configured by default to allow user, including unprivileged users, to write or overwrite files.
AplazadaMedia (6.4)0.30%—Advantech Webaccess ScadaAI21/3/202417/6/2026
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.
ModificadaMedia (6.5)0.59%—Rapidscada Rapid Scada2/2/202417/6/2026
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can append path traversal characters to the filename when using a specific command, allowing them to read arbitrary files from the system.
ModificadaAlta (7.8)0.16%—Rapidscada Rapid Scada2/2/202417/6/2026
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an authorized user can write directly to the Scada directory. This may allow privilege escalation.
ModificadaMedia (5.5)0.16%—Rapidscada Rapid Scada2/2/202417/6/2026
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product stores plaintext credentials in various places. This may allow an attacker with local access to see them.
ModificadaMedia (5.3)0.41%—Rapidscada Rapid Scada2/2/202417/6/2026
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the affected product responds back with an error message containing sensitive data if it receives a specific malformed request.
ModificadaMedia (5.4)0.32%—Rapidscada Rapid Scada2/2/202417/6/2026
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can redirect users to malicious pages through the login page.
ModificadaCrítica (9.8)0.62%—Rapidscada Rapid Scada2/2/202417/6/2026
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, the product uses hard-coded credentials, which may allow an attacker to connect to a specific port.
ModificadaAlta (8.8)1.2%—Rapidscada Rapid Scada1/2/202417/6/2026
In Rapid Software LLC's Rapid SCADA versions prior to Version 5.8.4, an attacker can supply a malicious configuration file by utilizing a Zip Slip vulnerability in the unpacking routine to achieve remote code execution.
ModificadaAlta (8.8)1.3%—Scada-lts13/1/202417/6/2026
An issue was discovered in Scada-LTS v2.7.5.2 build 4551883606 and before, allows remote attackers with low-level authentication to escalate privileges, execute arbitrary code, and obtain sensitive information via Event Handlers function.
ModificadaAlta (7.1)0.22%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service.
ModificadaAlta (7.8)0.24%—Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+915/11/202317/6/2026
This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine.
ModificadaCrítica (9.8)0.71%—Busbaer Eisbaer Scada25/10/202317/6/2026
EisBaer Scada - CWE-749: Exposed Dangerous Method or Function
ModificadaCrítica (9.8)0.43%—Busbaer Eisbaer Scada25/10/202317/6/2026
EisBaer Scada - CWE-256: Plaintext Storage of a Password