Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
2356 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.9) | 0.46% | — | Siemens Gridscale X Prepay | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in Gridscale X Prepay (All versions < V4.2.1). The affected application is vulnerable to user enumeration due to distinguishable responses. This could allow an unauthenticated remote attacker to determine if a user is valid or not, enabling a brute force attack with valid users. | |
| Modificada | Alta (7.5) | 0.64% | — | Siemens Ruggedcom ROX II Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions <… | |
| Modificada | Alta (8.6) | 0.64% | — | Siemens Ruggedcom ROX II Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions <… | |
| Modificada | Alta (8.6) | 0.39% | — | Siemens Ruggedcom ROX II Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions <… | |
| Modificada | Alta (8.6) | 0.52% | — | Siemens Ruggedcom ROX II Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions <… | |
| Modificada | Alta (7.7) | 0.43% | — | Siemens Ruggedcom ROX II Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions <… | |
| Modificada | Alta (8.7) | 0.51% | — | Siemens Ruggedcom ROX II Firmware | 9/12/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions < V2.17.0), RUGGEDCOM ROX MX5000RE (All versions < V2.17.0), RUGGEDCOM ROX RX1400 (All versions < V2.17.0), RUGGEDCOM ROX RX1500 (All versions < V2.17.0), RUGGEDCOM ROX RX1501 (All versions < V2.17.0), RUGGEDCOM ROX RX1510 (All versions <… | |
| Aplazada | Media (5.3) | 0.25% | — | Siemens Ruggedcom Rmc8388AISiemens Ruggedcom Rs416pv2AISiemens Ruggedcom Rs416v2AISiemens Ruggedcom Rs900AI+17 | 9/12/2025 | 7/10/2026 | A vulnerability has been identified in RUGGEDCOM RMC8388 V5.X (All versions < V5.10.1), RUGGEDCOM RS416Pv2 V5.X (All versions < V5.10.1), RUGGEDCOM RS416v2 V5.X (All versions < V5.10.1), RUGGEDCOM RS900 (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RS900G (32M) V5.X (All versions < V5.10.1), RUGGEDCOM RSG2100 (32M)… | |
| Aplazada | Crítica (9.2) | 0.26% | — | Siemens ComosAISiemens JT Bi-directional Translator FOR StepAISiemens NXAISiemens Simcenter 3DAI+5 | 9/12/2025 | 7/10/2026 | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), JT Bi-Directional Translator for STEP (All versions), NX V2412 (All versions < V2412.8900 with Cloud Entitlement (bundled as NX X)), NX V2506 (All versions < V2506.6000 with Cloud Entitlement (bundled as… | |
| Aplazada | Crítica (9.1) | 0.21% | — | Siemens ComosAISiemens NXAISiemens Simcenter 3DAISiemens Simcenter FemapAI+1 | 9/12/2025 | 7/10/2026 | A vulnerability has been identified in COMOS V10.6 (All versions < V10.6.1), COMOS V10.6 (All versions < V10.6.1), NX V2412 (All versions < V2412.8700), NX V2506 (All versions < V2506.6000), Simcenter 3D (All versions < V2506.6000), Simcenter Femap (All versions < V2506.0002), Solid Edge SE2025 (All versions < V225.0… | |
| Analizada | Alta (8.8) | 5.0% | ⚠ Explotación activa | Google ChromeSiemens Cadra | 17/11/2025 | 14/7/2026 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Alta (7.3) | 0.20% | — | Siemens PS Iges Parasolid Translator ComponentAISiemens Simcenter FemapAISiemens Solid EdgeAI | 17/11/2025 | 17/6/2026 | A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This… | |
| Aplazada | Alta (8.5) | 0.16% | — | Siemens Software CenterAISiemens Solid Edge Se2025AI | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2025 (All versions < V225.0 Update 10). The affected application is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system. | |
| Aplazada | Alta (7.1) | 0.22% | — | Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+12 | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo… | |
| Aplazada | Alta (7.2) | 0.20% | — | Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+12 | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo… | |
| Aplazada | Alta (8.6) | 0.35% | — | Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+12 | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo… | |
| Aplazada | Alta (8.7) | 0.21% | — | Siemens Solid Edge Se2025AI | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate client certificates to connect to License Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks. | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Solid Edge Se2024Siemens Solid Edge Se2025 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or… | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Solid Edge Se2024Siemens Solid Edge Se2025 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or… | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Solid Edge Se2024Siemens Solid Edge Se2025 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or… | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Solid Edge Se2024Siemens Solid Edge Se2025 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or… | |
| Analizada | Media (6.7) | 0.14% | — | Siemens Sipass Integrated | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing them to recover passwords. Successful exploitation of this vulnerability allows… | |
| Analizada | Media (5.1) | 0.20% | — | Siemens Sipass Integrated | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request. Successful exploitation allows an… | |
| Analizada | Alta (7) | 0.32% | — | Siemens Sipass Integrated | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page. Successful exploitation allows an… | |
| Aplazada | Crítica (9.3) | 0.53% | — | Siemens Simatic CP 1542sp-1AISiemens Simatic CP 1542sp-1 IRCAISiemens Simatic CP 1543sp-1AISiemens Siplus ET 200sp CP 1542sp-1 IRC TX RailAI+2 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions… |