Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
229 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.8) | 0.41% | — | Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware | 12/3/2024 | 17/6/2026 | An unauthenticated local attacker can perform a privilege escalation due to improper input validation in the OCPP agent service. | |
| Modificada | Alta (7.3) | 1.5% | — | Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware | 12/3/2024 | 17/6/2026 | An unauthenticated remote attacker can perform a command injection in the OCPP Service with limited privileges due to improper input validation. | |
| Analizada | Media (5.3) | 0.69% | — | Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware | 12/3/2024 | 17/6/2026 | An unauthenticated remote attacker can perform a log injection due to improper input validation. Only a certain log file is affected. | |
| Analizada | Crítica (9.8) | 0.39% | — | Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware | 12/3/2024 | 17/6/2026 | An unauthenticated remote attacker can perform a remote code execution due to an origin validation error. The access is limited to the service user. | |
| Modificada | Crítica (9.8) | 1.4% | — | Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware | 12/3/2024 | 17/6/2026 | An unauthenticated remote attacker can modify configurations to perform a remote code execution, gain root rights or perform an DoS due to improper input validation. | |
| Modificada | Media (5.3) | 0.73% | — | Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware | 12/3/2024 | 17/6/2026 | An unauthenticated remote attacker can upload a arbitrary script file due to improper input validation. The upload destination is fixed and is write only. | |
| Aplazada | Media (4.8) | 0.81% | 💥 PoC | Oscommerce CE PhoenixAI | 12/3/2024 | 17/6/2026 | HTML Injection vulnerability in CE Phoenix v1.0.8.20 and before allows a remote attacker to execute arbitrary code, escalate privileges, and obtain sensitive information via a crafted payload to the english.php component. | |
| Analizada | Alta (7.2) | 27% | — | Phoenixcart CE Phoenix Cart | 16/2/2024 | 17/6/2026 | A remote code execution (RCE) vulnerability in /admin/define_language.php of CE Phoenix v1.0.8.20 allows attackers to execute arbitrary PHP code via injecting a crafted payload into the file english.php. | |
| Modificada | Alta (7.5) | 0.33% | — | Phoenixcontact MultiprogPhoenixcontact Proconos Eclr | 14/12/2023 | 17/6/2026 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to download and execute applications without integrity checks on the device which may result in a complete loss of integrity. | |
| Modificada | Media (6.5) | 0.31% | — | Phoenixcontact AXC F 1152 FirmwarePhoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 3152 FirmwarePhoenixcontact BPC 9102s Firmware+5 | 14/12/2023 | 17/6/2026 | A download of code without integrity check vulnerability in PLCnext products allows an remote attacker with low privileges to compromise integrity on the affected engineering station and the connected devices. | |
| Modificada | Alta (7.5) | 0.33% | — | Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+14 | 14/12/2023 | 17/6/2026 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. | |
| Modificada | Alta (8.8) | 0.74% | — | Phoenixcontact AXC F 1152 FirmwarePhoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 3152 FirmwarePhoenixcontact BPC 9102s Firmware+5 | 14/12/2023 | 17/6/2026 | A incorrect permission assignment for critical resource vulnerability in PLCnext products allows an remote attacker with low privileges to gain full access on the affected devices. | |
| Modificada | Crítica (9.8) | 0.88% | — | Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+14 | 14/12/2023 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device. | |
| Modificada | Crítica (9.8) | 0.88% | — | Phoenixcontact MultiprogPhoenixcontact Proconos Eclr | 14/12/2023 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in PHOENIX CONTACT MULTIPROG, PHOENIX CONTACT ProConOS eCLR (SDK) allows an unauthenticated remote attacker to upload arbitrary malicious code and gain full access on the affected device. | |
| Analizada | Alta (7.8) | 0.27% | — | Phoenixtech Securecore Technology | 7/12/2023 | 17/6/2026 | Improper Input Validation in the processing of user-supplied splash screen during system boot in Phoenix SecureCore™ Technology™ 4 potentially allows denial-of-service attacks or arbitrary code execution. | |
| Analizada | Alta (7.1) | 0.19% | — | Phoenixtech Securecore Technology | 15/11/2023 | 17/6/2026 | Improper Access Control in SMI handler vulnerability in Phoenix SecureCore™ Technology™ 4 allows SPI flash modification. This issue affects SecureCore™ Technology™ 4: from from from 4.5.0.0 before 4.5.0.138 | |
| Modificada | Crítica (9.8) | 2.0% | — | Wibu Codemeter RuntimeTrumpf OseonTrumpf ProgrammingtubeTrumpf Teczonebend+20 | 13/9/2023 | 17/6/2026 | A heap buffer overflow vulnerability in Wibu CodeMeter Runtime network service up to version 7.60b allows an unauthenticated, remote attacker to achieve RCE and gain full access of the host system. | |
| Modificada | Alta (7.2) | 0.42% | — | Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+2 | 9/8/2023 | 17/6/2026 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device. | |
| Modificada | Alta (7.2) | 0.93% | — | Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+2 | 9/8/2023 | 17/6/2026 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with SNMPv2 write privileges may use an a special SNMP request to gain full access to the device. | |
| Modificada | Alta (8.2) | 0.50% | — | Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+2 | 9/8/2023 | 17/6/2026 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an unauthenticated remote attacker can access upload-functions of the HTTP API. This might cause certificate errors for SSL-connections and might result in a partial denial-of-service. | |
| Modificada | Alta (8.8) | 0.88% | — | Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+2 | 9/8/2023 | 17/6/2026 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated remote attacker can execute code with root permissions with a specially crafted HTTP POST when uploading a certificate to the device. | |
| Modificada | Alta (7.5) | 0.80% | — | Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+2 | 9/8/2023 | 17/6/2026 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote unauthenticated attacker can obtain the r/w community string of the SNMPv2 daemon. | |
| Modificada | Alta (7.2) | 0.86% | — | Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+2 | 9/8/2023 | 17/6/2026 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 the SNMP daemon is running with root privileges allowing a remote attacker with knowledge of the SNMPv2 r/w community string to execute system commands as root. | |
| Modificada | Media (4.9) | 0.45% | — | Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+2 | 9/8/2023 | 17/6/2026 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing to decrypt an encrypted web application login password. | |
| Modificada | Alta (7.2) | 0.58% | — | Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+2 | 9/8/2023 | 17/6/2026 | In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 an authenticated, remote attacker with admin privileges is able to read hardcoded cryptographic keys allowing the attacker to create valid session cookies. These session-cookies created by the attacker are not sufficient to obtain a valid… |