Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
152 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.33% | — | Schneider-electric Ecostruxure Control Expert | 19/11/2020 | 17/6/2026 | A CWE-863: Incorrect Authorization vulnerability exists in PLC Simulator on EcoStruxureª Control Expert (now Unity Pro) (all versions) that could cause bypass of authentication when overwriting memory using a debugger. | |
| Modificada | Media (6.1) | 0.81% | — | Schneider-electric Ecostruxure Building Operation | 19/11/2020 | 17/6/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability exists in EcoStruxure Building Operation WebStation V2.0 - V3.1 that could cause an attacker to inject HTML and JavaScript code into the user's browser. | |
| Modificada | Crítica (9.8) | 2.3% | — | Schneider-electric Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause arbitrary application execution when the computer starts. | |
| Modificada | Alta (7.8) | 0.86% | — | SE Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-88: Argument Injection or Modification vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD)which could cause unauthorized write access when opening the project file. | |
| Modificada | Media (5.5) | 0.88% | — | Schneider-electric Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability during zip file extraction exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause unauthorized write access outside of expected path folder when… | |
| Modificada | Alta (7.8) | 1.3% | — | Schneider-electric Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file. | |
| Modificada | Alta (7.8) | 1.1% | — | Schneider-electric Ecostruxure Operator Terminal Expert | 16/6/2020 | 17/6/2026 | A CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability exists in EcoStruxure Operator Terminal Expert 3.1 Service Pack 1 and prior (formerly known as Vijeo XD) which could cause malicious code execution when opening the project file. | |
| Modificada | Alta (7.8) | 0.50% | — | Fazecast JserialcommSchneider-electric Ecostruxure IT Gateway | 14/5/2020 | 17/6/2026 | In Fazecast jSerialComm, Version 2.2.2 and prior, an uncontrolled search path element vulnerability could allow a malicious DLL file with the same name of any resident DLLs inside the software installation to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 1.6% | — | Schneider-electric Ecostruxure Machine ExpertSchneider-electric Somachine BasicSchneider-electric Modicon M100 FirmwareSchneider-electric Modicon M200 Firmware+1 | 22/4/2020 | 17/6/2026 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection') vulnerability exists on EcoStruxure Machine Expert – Basic or SoMachine Basic programming software (versions in security notification). The result of this vulnerability, DLL substitution, could allow the… | |
| Modificada | Alta (7.5) | 0.88% | — | Schneider-electric Ecostruxure Machine ExpertSchneider-electric SomachineSchneider-electric Somachine MotionSchneider-electric Modicon M218 Firmware+3 | 22/4/2020 | 17/6/2026 | A CWE-319: Cleartext Transmission of Sensitive Information vulnerability exists which could leak sensitive information transmitted between the software and the Modicon M218, M241, M251, and M258 controllers. | |
| Modificada | Crítica (9.8) | 0.69% | — | Schneider-electric Ecostruxure Machine ExpertSchneider-electric SomachineSchneider-electric Somachine MotionSchneider-electric Modicon M218 Firmware+3 | 22/4/2020 | 17/6/2026 | A CWE-345: Insufficient Verification of Data Authenticity vulnerability exists which could allow the attacker to execute malicious code on the Modicon M218, M241, M251, and M258 controllers. | |
| Modificada | Crítica (9.8) | 1.6% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PROSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon M580 Firmware | 23/3/2020 | 17/6/2026 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior… | |
| Modificada | Alta (7.3) | 0.95% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PROSchneider-electric Modicon M580 Bmep584040 FirmwareSchneider-electric Modicon M580 Bmeh584040 Firmware+19 | 6/1/2020 | 17/6/2026 | Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control… | |
| Modificada | Media (6.1) | 0.76% | — | Schneider-electric Ecostruxure Energy ExpertSchneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Scada Operation | 17/12/2018 | 17/6/2026 | A URL redirection vulnerability exists in Power Monitoring Expert, Energy Expert (formerly Power Manager) - EcoStruxure Power Monitoring Expert (PME) v8.2 (all editions), EcoStruxure Energy Expert 1.3 (formerly Power Manager), EcoStruxure Power SCADA Operation (PSO) 8.2 Advanced Reports and Dashboards Module,… | |
| Modificada | Alta (8.8) | 1.3% | — | Schneider-electric Struxureware Data Center Expert | 30/11/2018 | 17/6/2026 | Data Center Expert, versions 7.5.0 and earlier, allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As such, it could allow for the arbitrary… | |
| Modificada | Alta (8.8) | 1.3% | — | Schneider-electric Struxureware Data Center Operation | 30/11/2018 | 17/6/2026 | Data Center Operation allows for the upload of a zip file from its user interface to the server. A carefully crafted, malicious file could be mistakenly uploaded by an authenticated user via this feature which could contain path traversal file names. As such, it could allow for the arbitrary upload of files contained… | |
| Modificada | Media (5.6) | 8.6% | — | Intel Atom CIntel Atom EIntel Atom X3Intel Atom Z+221 | 10/7/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and branch prediction may allow unauthorized disclosure of information to an attacker with local user access via a speculative buffer overflow and side-channel analysis. | |
| Modificada | Crítica (9.8) | 1.9% | — | Procps-ng Project Procps-ngCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+6 | 23/5/2018 | 17/6/2026 | procps-ng before version 3.3.15 is vulnerable to an incorrect integer size in proc/alloc.* leading to truncation/integer overflow issues. This flaw is related to CVE-2018-1124. | |
| Modificada | Alta (7.8) | 1.9% | 💥 Exploit | Procps-ng Project Procps-ngCanonical Ubuntu LinuxDebian LinuxRedhat Enterprise Linux+5 | 23/5/2018 | 17/6/2026 | procps-ng before version 3.3.15 is vulnerable to multiple integer overflows leading to a heap corruption in file2strvec function. This allows a privilege escalation for a local attacker who can create entries in procfs by starting processes, which could result in crashes or arbitrary code execution in proc utilities… | |
| Modificada | Media (5.5) | 61% | 💥 Exploit | Intel Atom CIntel Atom EIntel Atom X5-e3930Intel Atom X5-e3940+278 | 22/5/2018 | 17/6/2026 | Systems with microprocessors utilizing speculative execution and speculative execution of memory reads before the addresses of all prior memory writes are known may allow unauthorized disclosure of information to an attacker with local user access via a side-channel analysis, aka Speculative Store Bypass (SSB),… | |
| Modificada | Media (5.3) | 5.1% | — | Oracle JDKOracle JREOracle JrockitRedhat Enterprise Linux Desktop+9 | 19/4/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: Serialization). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network… | |
| Modificada | Alta (8.3) | 4.0% | — | Oracle JDKOracle JRERedhat Enterprise Linux DesktopRedhat Enterprise Linux Server+8 | 19/4/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded component of Oracle Java SE (subcomponent: Hotspot). Supported versions that are affected are Java SE: 6u181, 7u171, 8u162 and 10; Java SE Embedded: 8u161. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to… | |
| Modificada | Alta (7.7) | 0.49% | — | Oracle JDKOracle JRERedhat Enterprise Linux ServerRedhat Enterprise Linux Workstation+1 | 19/4/2018 | 17/6/2026 | Vulnerability in the Java SE component of Oracle Java SE (subcomponent: Install). Supported versions that are affected are Java SE: 8u162 and 10. Difficult to exploit vulnerability allows unauthenticated attacker with logon to the infrastructure where Java SE executes to compromise Java SE. Successful attacks require… | |
| Modificada | Media (4.2) | 5.2% | — | Oracle JDKOracle JREOracle JrockitRedhat Satellite+10 | 19/4/2018 | 17/6/2026 | Vulnerability in the Java SE, JRockit component of Oracle Java SE (subcomponent: RMI). Supported versions that are affected are Java SE: 6u181, 7u171 and 8u162; JRockit: R28.3.17. Difficult to exploit vulnerability allows unauthenticated attacker with network access via multiple protocols to compromise Java SE,… | |
| Modificada | Media (5.3) | 15% | — | Oracle JDKOracle JREOracle JrockitRedhat Satellite+11 | 19/4/2018 | 17/6/2026 | Vulnerability in the Java SE, Java SE Embedded, JRockit component of Oracle Java SE (subcomponent: JAXP). Supported versions that are affected are Java SE: 7u171, 8u162 and 10; Java SE Embedded: 8u161; JRockit: R28.3.17. Easily exploitable vulnerability allows unauthenticated attacker with network access via multiple… |