Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.43% | — | Busbaer Eisbaer Scada | 25/10/2023 | 17/6/2026 | EisBaer Scada - CWE-321: Use of Hard-coded Cryptographic Key | |
| Modificada | Crítica (9.8) | 0.64% | — | Busbaer Eisbaer Scada | 25/10/2023 | 17/6/2026 | EisBaer Scada - CWE-285: Improper Authorization | |
| Modificada | Alta (7.5) | 0.62% | — | Busbaer Eisbaer Scada | 25/10/2023 | 17/6/2026 | EisBaer Scada - CWE-200: Exposure of Sensitive Information to an Unauthorized Actor | |
| Modificada | Crítica (9.8) | 0.66% | — | Busbaer Eisbaer Scada | 25/10/2023 | 17/6/2026 | EisBaer Scada - CWE-732: Incorrect Permission Assignment for Critical Resource | |
| Modificada | Alta (7.5) | 0.75% | — | Busbaer Eisbaer Scada | 25/10/2023 | 17/6/2026 | EisBaer Scada - CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') | |
| Analizada | Alta (7.5) | 100% | ⚠ Explotación activa💥 Exploit | Siemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP FirmwareSiemens Sinec INSSiemens Sinec NMSSiemens ST7 Scadaconnect+161 | 10/10/2023 | 11/8/2026 | The HTTP/2 protocol allows a denial of service (server resource consumption) because request cancellation can reset many streams quickly, as exploited in the wild in August through October 2023. | |
| Modificada | Crítica (9.8) | 0.92% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports | 4/10/2023 | 17/6/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | |
| Modificada | Baja (2.5) | 0.20% | — | Supcon Inplant Scada | 15/9/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901. Affected by this vulnerability is an unknown functionality of the file Project.xml. The manipulation leads to password hash with insufficient computational effort. Local access is required to approach this attack. The… | |
| Modificada | Alta (7.8) | 0.38% | — | Supcon Inplant Scada | 15/9/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml. The manipulation leads to improper authentication. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Alta (7.8) | 0.18% | — | Schneider-electric Interactive Graphical Scada System | 14/9/2023 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists in the IGSS Update Service that could allow a local attacker to change update source, potentially leading to remote code execution when the attacker force an update containing malicious content. | |
| Modificada | Crítica (9.8) | 0.73% | — | Ardereg Sistemas Scada | 6/9/2023 | 17/6/2026 | ARDEREG Sistema SCADA Central versions 2.203 and prior login page are vulnerable to an unauthenticated blind SQL injection attack. An attacker could manipulate the application's SQL query logic to extract sensitive information or perform unauthorized actions within the database. In this case, the vulnerability could… | |
| Modificada | Alta (7.5) | 1.0% | — | Tel-ster Telwin Scada Webinterface | 3/8/2023 | 17/6/2026 | External input could be used on TEL-STER TelWin SCADA WebInterface to construct paths to files and directories without properly neutralizing special elements within the pathname, which could allow an unauthenticated attacker to read files on the system. | |
| Modificada | Media (6.5) | 1.0% | — | Spidercontrol Scadawebserver | 2/8/2023 | 17/6/2026 | SpiderControl SCADA Webserver versions 2.08 and prior are vulnerable to path traversal. An attacker with administrative privileges could overwrite files on the webserver using the HMI's upload file feature. This could create size zero files anywhere on the webserver, potentially overwriting system files and creating a… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advantech Webaccess/scada | 2/8/2023 | 17/6/2026 | All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite… | |
| Modificada | Media (5.3) | 0.59% | — | Trianglemicroworks Scada Data Gateway | 7/6/2023 | 17/6/2026 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send broadcast events to any user via the WebMonitor.An unauthenticated user can use this vulnerability to forcefully log out of any currently logged-in user by sending a "password change event". Furthermore, an attacker… | |
| Modificada | Crítica (9.8) | 0.71% | — | Trianglemicroworks Scada Data Gateway | 7/6/2023 | 17/6/2026 | On Triangle MicroWorks' SCADA Data Gateway version <= v5.01.03, an unauthenticated attacker can send a specially crafted broadcast message including format string characters to the SCADA Data Gateway to perform unrestricted memory reads.An unauthenticated user can use this format string vulnerability to repeatedly… | |
| Modificada | Crítica (9.8) | 0.71% | — | Advantech Webaccess/scada | 6/6/2023 | 17/6/2026 | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution. | |
| Modificada | Crítica (9.8) | 0.90% | — | Advantech Webaccess/scada | 6/6/2023 | 17/6/2026 | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution. | |
| Modificada | Alta (7.2) | 0.83% | — | Advantech Webaccess/scada | 6/6/2023 | 17/6/2026 | In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution. | |
| Modificada | Alta (7.5) | 8.1% | 💥 Exploit | SDG Pnpscada | 12/5/2023 | 17/6/2026 | The PnPSCADA system, a product of SDG Technologies CC, is afflicted by a critical unauthenticated error-based PostgreSQL Injection vulnerability. Present within the hitlogcsv.jsp endpoint, this security flaw permits unauthenticated attackers to engage with the underlying database seamlessly and passively.… | |
| Modificada | Alta (8.8) | 0.75% | — | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Alta (8.8) | 0.75% | — | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Alta (8.8) | 4.5% | — | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Alta (8.8) | 25% | — | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. | |
| Modificada | Alta (8.8) | 45% | 💥 Exploit | Myscada Mypro | 27/4/2023 | 17/6/2026 | mySCADA myPRO versions 8.26.0 and prior has parameters which an authenticated user could exploit to inject arbitrary operating system commands. |