Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

435 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.43%—Busbaer Eisbaer Scada25/10/202317/6/2026
EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key
ModificadaCrítica (9.8)0.64%—Busbaer Eisbaer Scada25/10/202317/6/2026
EisBaer Scada - CWE-285: Improper Authorization
ModificadaAlta (7.5)0.62%—Busbaer Eisbaer Scada25/10/202317/6/2026
EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor
ModificadaCrítica (9.8)0.66%—Busbaer Eisbaer Scada25/10/202317/6/2026
EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource
ModificadaAlta (7.5)0.75%—Busbaer Eisbaer Scada25/10/202317/6/2026
EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+16110/10/202311/8/2026
The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023.
ModificadaCrítica (9.8)0.92%—Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports4/10/202317/6/2026
A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application.
ModificadaBaja (2.5)0.20%—Supcon Inplant Scada15/9/202317/6/2026
A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901. Affected by this vulnerability is an unknown functionality of the file Project.xml. The manipulation leads to password hash with insufficient computational effort. Local access is required to approach this attack. The…
ModificadaAlta (7.8)0.38%—Supcon Inplant Scada15/9/202317/6/2026
A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml. The manipulation leads to improper authentication. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier…
ModificadaAlta (7.8)0.18%—Schneider-electric Interactive Graphical Scada System14/9/202317/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content.
ModificadaCrítica (9.8)0.73%—Ardereg Sistemas Scada6/9/202317/6/2026
ARDEREG ​Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the database. In this case, the vulnerability could…
ModificadaAlta (7.5)1.0%—Tel-ster Telwin Scada Webinterface3/8/202317/6/2026
External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system.
ModificadaMedia (6.5)1.0%—Spidercontrol Scadawebserver2/8/202317/6/2026
SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a…
ModificadaCrítica (9.8)2.8%—Advantech Webaccess/scada2/8/202317/6/2026
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite…
ModificadaMedia (5.3)0.59%—Trianglemicroworks Scada Data Gateway7/6/202317/6/2026
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker…
ModificadaCrítica (9.8)0.71%—Trianglemicroworks Scada Data Gateway7/6/202317/6/2026
On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly…
ModificadaCrítica (9.8)0.71%—Advantech Webaccess/scada6/6/202317/6/2026
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.
ModificadaCrítica (9.8)0.90%—Advantech Webaccess/scada6/6/202317/6/2026
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
ModificadaAlta (7.2)0.83%—Advantech Webaccess/scada6/6/202317/6/2026
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.
ModificadaAlta (7.5)8.1%💥 ExploitSDG Pnpscada12/5/202317/6/2026
The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively.…
ModificadaAlta (8.8)0.75%—Myscada Mypro27/4/202317/6/2026
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
ModificadaAlta (8.8)0.75%—Myscada Mypro27/4/202317/6/2026
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
ModificadaAlta (8.8)4.5%—Myscada Mypro27/4/202317/6/2026
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
ModificadaAlta (8.8)25%—Myscada Mypro27/4/202317/6/2026
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.
ModificadaAlta (8.8)45%💥 ExploitMyscada Mypro27/4/202317/6/2026
mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands.