Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
2356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.19% | — | Siemens Sinec NMS | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP2). The affected application permits improper modification of a configuration file by a low-privileged user. This could allow an attacker to load malicious DLLs, potentially leading to arbitrary code execution with administrative… | |
| Analizada | Alta (7.3) | 0.17% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected application is vulnerable to heap-based buffer overflow while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted NDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds read vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process. | |
| Analizada | Alta (7.3) | 0.17% | — | Siemens Simcenter FemapSiemens Simcenter Nastran | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512), Simcenter Nastran (All versions < V2512). The affected applications contains an out of bounds write vulnerability while parsing specially crafted XDB files. This could allow an attacker to execute code in the context of the current process. | |
| Modificada | Alta (7.3) | 0.14% | — | Siemens NX | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in NX (All versions < V2512), NX (Managed Mode) (All versions < V2512). The affected application contains a data validation vulnerability that could allow an attacker with local access to interfere with internal data during the PDF export process that could potentially lead to… | |
| Aplazada | Media (6.3) | 0.28% | — | Siemens Syngo.plazaAI | 10/2/2026 | 17/6/2026 | A vulnerability has been identified in syngo.plaza VB30E (All versions < VB30E_HF07). The affected application does not encrypt the passwords properly. This could allow an attacker to recover the original passwords and might gain unauthorized access. | |
| Analizada | Crítica (9.8) | 86% | ⚠ Explotación activa💥 PoC | Fortinet FortianalyzerFortinet FortimanagerFortinet Fortinac-fFortinet Fortiproxy+3 | 27/1/2026 | 17/6/2026 | An Authentication Bypass Using an Alternate Path or Channel vulnerability [CWE-288] vulnerability in Fortinet FortiAnalyzer 7.6.0 through 7.6.5, FortiAnalyzer 7.4.0 through 7.4.9, FortiAnalyzer 7.2.0 through 7.2.11, FortiAnalyzer 7.0.0 through 7.0.15, FortiManager 7.6.0 through 7.6.5, FortiManager 7.4.0 through 7.4.9,… | |
| Analizada | Crítica (9.8) | 3.9% | ⚠ Explotación activa | Fortinet FortiosFortinet FortiswitchmanagerFortinet FortisaseSiemens Ruggedcom Ape1808 Firmware | 13/1/2026 | 10/9/2026 | A heap-based buffer overflow vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiOS 6.4 all versions, FortiSwitchManager 7.2.0 through 7.2.6, FortiSwitchManager 7.0.0 through 7.0.5 allows attacker to execute unauthorized… | |
| Aplazada | Alta (8.7) | 0.44% | — | Siemens Simatic ET 200al IM 157-1 PNAISiemens Simatic ET 200mp IM 155-5 PN HFAISiemens Simatic ET 200sp IM 155-6 MF HFAISiemens Simatic ET 200sp IM 155-6 PN HAAI+8 | 13/1/2026 | 17/6/2026 | A vulnerability has been identified in SIMATIC ET 200AL IM 157-1 PN (6ES7157-1AB00-0AB0) (All versions), SIMATIC ET 200MP IM 155-5 PN HF (6ES7155-5AA00-0AC0) (All versions >= V4.2.0), SIMATIC ET 200SP IM 155-6 MF HF (6ES7155-6MU00-0CN0) (All versions), SIMATIC ET 200SP IM 155-6 PN HA (incl. SIPLUS variants) (All… | |
| Analizada | Alta (7.3) | 0.16% | — | Siemens Telecontrol Server Basic | 13/1/2026 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic (All versions < V3.1.2.4). Affected application contains a local privilege escalation vulnerability that could allow an attacker to run arbitrary code with elevated privileges. | |
| Analizada | Alta (7.3) | 0.20% | — | Siemens Simcenter Femap | 12/12/2025 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap (All versions < V2512). The affected applications contains an uninitialized memory vulnerability while parsing specially crafted SLDPRT files. This could allow an attacker to execute code in the context of the current process. (ZDI-CAN-27146) | |
| Analizada | Crítica (9.8) | 68% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosSiemens Ruggedcom Ape1808 Firmware | 9/12/2025 | 17/6/2026 | A improper verification of cryptographic signature vulnerability in Fortinet FortiOS 7.6.0 through 7.6.3, FortiOS 7.4.0 through 7.4.8, FortiOS 7.2.0 through 7.2.11, FortiOS 7.0.0 through 7.0.17, FortiProxy 7.6.0 through 7.6.3, FortiProxy 7.4.0 through 7.4.10, FortiProxy 7.2.0 through 7.2.14, FortiProxy 7.0.0 through… | |
| Analizada | Media (5.3) | 0.28% | — | Siemens Simatic CN 4100 Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected devices exposes server information in its responses. This could allow an attacker with network access to gain useful information, increasing the likelihood of targeted attacks. | |
| Analizada | Media (6.9) | 0.37% | — | Siemens Simatic CN 4100 Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application exhibits inconsistent SNMP behavior, such as unexpected service availability and unreliable configuration handling across protocol versions. This could allow an attacker to access sensitive data, potentially… | |
| Analizada | Media (5.1) | 0.21% | — | Siemens Simatic CN 4100 Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device contains a USB port which allows unauthenticated connections. This could allow an attacker with physical access to the device to trigger reboot that could cause denial of service condition. | |
| Analizada | Crítica (9.2) | 0.38% | — | Siemens Simatic CN 4100 Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected device stores sensitive information in the firmware. This could allow an attacker to access and misuse this information, potentially impacting the device’s confidentiality, integrity, and availability. | |
| Analizada | Alta (8.7) | 0.59% | — | Siemens Simatic CN 4100 Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC CN 4100 (All versions < V4.0.1). The affected application do not properly validate input parameters in its REST API, resulting in improper handling of unexpected arguments. This could allow an authenticated attacker to execute arbitrary code with limited privileges. | |
| Analizada | Alta (7.1) | 0.39% | — | Siemens Sinec Security Monitor | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application lacks input validation of date parameter in report generation functionality. This could allow an authenticated, lowly privileged attacker to cause denial of service condition of the report functionality. | |
| Analizada | Alta (8.4) | 0.16% | — | Siemens Sinec Security Monitor | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Security Monitor (All versions < V4.10.0). The affected application does not have proper authorization checks for the file_transfer feature in ssmctl-client command. This could allow an authenticated, lowly privileged local attacker to read or write to any file on server or… | |
| Analizada | Media (4.3) | 0.25% | — | Siemens Sinema Remote Connect Server | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications do not properly validate license restrictions against the database, allowing direct modification of the system_ticketinfo table to bypass license limitations without proper enforcement checks. This… | |
| Analizada | Baja (3.3) | 0.10% | — | Siemens Sinema Remote Connect Server | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in SINEMA Remote Connect Server (All versions < V3.2 SP4). Affected applications contain private SSL/TLS keys on the server that are not properly protected allowing any user with server access to read these keys. This could allow an authenticated attacker to impersonate the server… | |
| Analizada | Media (5.3) | 0.30% | — | Siemens Gridscale X Prepay | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to capture-replay of authentication tokens. This could allow an authenticated but already locked-out user to establish still valid user sessions. |