Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.6%—Codesys18/8/202117/6/2026
An unsafe deserialization vulnerability exists in the ObjectManager.plugin Project.get_MissingTypes() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.8)1.6%—Codesys18/8/202117/6/2026
An unsafe deserialization vulnerability exists in the ObjectManager.plugin ObjectStream.ProfileByteArray functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.8)1.2%—Codesys Development System5/8/202117/6/2026
A unsafe deserialization vulnerability exists in the ComponentModel Profile.FromFile() functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.5)0.99%—Codesys Ethernetip4/8/202117/6/2026
In CODESYS EtherNetIP before 4.1.0.0, specific EtherNet/IP requests may cause a null pointer dereference in the downloaded vulnerable EtherNet/IP stack that is executed by the CODESYS Control runtime system.
ModificadaAlta (7.5)0.99%—Codesys Gateway4/8/202117/6/2026
In CODESYS Gateway V3 before 3.5.17.10, there is a NULL Pointer Dereference. Crafted communication requests may cause a Null pointer dereference in the affected CODESYS products and may result in a denial-of-service condition.
ModificadaAlta (7.5)1.0%—Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+33/8/202117/6/2026
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
ModificadaAlta (7.5)0.96%—Codesys Runtime Toolkit3/8/202117/6/2026
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.
ModificadaCrítica (9.8)1.1%—Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+33/8/202117/6/2026
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
ModificadaAlta (7.8)1.7%—Codesys Development System2/8/202117/6/2026
A unsafe deserialization vulnerability exists in the ObjectManager.plugin ProfileInformation.ProfileData functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.8)1.3%—Codesys Development System2/8/202117/6/2026
A unsafe deserialization vulnerability exists in the PackageManagement.plugin ExtensionMethods.Clone() functionality of CODESYS GmbH CODESYS Development System 3.5.16. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this vulnerability.
ModificadaAlta (7.8)1.7%—Codesys Development System2/8/202117/6/2026
A unsafe deserialization vulnerability exists in the ComponentModel ComponentManager.StartupCultureSettings functionality of CODESYS GmbH CODESYS Development System 3.5.16 and 3.5.17. A specially crafted file can lead to arbitrary command execution. An attacker can provide a malicious file to trigger this…
AnalizadaAlta (7.5)7.2%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2525/5/202117/6/2026
CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation.
AnalizadaCrítica (9.1)1.2%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Read.
AnalizadaCrítica (9.8)1.2%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 Web-Server before 1.1.9.20 has an Out-of-bounds Write.
AnalizadaCrítica (9.8)1.2%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 Web-Server before 1.1.9.20 has an Improperly Implemented Security Check.
AnalizadaAlta (7.5)1.0%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 Web-Server before 1.1.9.20 has a a Buffer Copy without Checking the Size of the Input.
AnalizadaCrítica (9.8)1.4%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 Web-Server before 1.1.9.20 has Improper Access Control.
AnalizadaCrítica (9.8)1.3%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 Web-Server before 1.1.9.20 has a Stack-based Buffer Overflow.
AnalizadaCrítica (9.8)1.3%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow.
AnalizadaAlta (7.5)7.4%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2525/5/202117/6/2026
CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow.
AnalizadaMedia (5.3)0.27%—Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+2425/5/202117/6/2026
CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command.
ModificadaAlta (7.8)0.94%—Codesys Development System4/5/202117/6/2026
The Package Manager of CODESYS Development System 3 before 3.5.17.0 does not check the validity of packages before installation and may be used to install CODESYS packages with malicious content.
ModificadaAlta (7.3)1.1%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+183/5/202117/6/2026
CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages.
ModificadaAlta (7.5)1.4%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+73/5/202117/6/2026
CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS).
ModificadaAlta (7.8)0.18%—Codesys Development System3/5/202117/6/2026
CODESYS Development System 3 before 3.5.17.0 displays or executes malicious documents or files embedded in libraries without first checking their validity.