Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.72% | — | Br-automation VC4 | 14/4/2023 | 17/6/2026 | Improper Authentication vulnerability in B&R Industrial Automation B&R VC4 (VNC-Server modules). This vulnerability may allow an unauthenticated network-based attacker to bypass the authentication mechanism of the VC4 visualization on affected devices. The impact of this vulnerability depends on the functionality… | |
| Modificada | Alta (7.5) | 0.91% | — | Mz-automation Libiec61850 | 13/4/2023 | 17/6/2026 | libiec61850 v1.5.1 was discovered to contain a segmentation violation via the function ControlObjectClient_setOrigin() at /client/client_control.c. | |
| Modificada | Media (5.5) | 0.23% | — | Mlit National Land Numerical Information Data Conversion Tool | 11/4/2023 | 17/6/2026 | National land numerical information data conversion tool all versions improperly restricts XML external entity references (XXE). By processing a specially crafted XML file, arbitrary files on the PC may be accessed by an attacker. | |
| Modificada | Media (5.4) | 0.34% | — | Prolizyazilim Student Affairs Information System | 7/4/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Proliz OBS allows Stored XSS for an authenticated user. This issue affects OBS: before 23.04.01. | |
| Modificada | Alta (8.8) | 2.9% | — | Apache Unstructured Information Management Architecture | 30/3/2023 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Apache Software Foundation Apache UIMA DUCC. When using the "Distributed UIMA Cluster Computing" (DUCC) module of Apache UIMA, an authenticated user that has the permissions to modify… | |
| Modificada | Alta (7.5) | 1.2% | — | Unified-automation OPC UA C++ Demo Server | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537 [with vendor rollup]. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of certificates. A crafted… | |
| Modificada | Alta (7.5) | 1.8% | — | Unified-automation OPC UA C++ Demo Server | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Unified Automation OPC UA C++ Demo Server 1.7.6-537. Authentication is not required to exploit this vulnerability. The specific flaw exists within the OpcUa_SecureListener_ProcessSessionCallRequest method. A… | |
| Modificada | Crítica (9.1) | 3.4% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation… | |
| Modificada | Crítica (9.8) | 3.4% | — | GE Industrial Gateway ServerPTC Kepware KepserverexPTC Opc-aggregatorPTC Thingworx Industrial Connectivity+4 | 29/3/2023 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation… | |
| Modificada | Alta (7.2) | 0.74% | — | IBM Qradar Security Information AND Event Manager | 22/3/2023 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 is vulnerable to privilege escalation, allowing a user with some admin capabilities to gain additional admin capabilities. IBM X-Force ID: 239425. | |
| Modificada | Alta (7.5) | 18% | — | Rockwellautomation Thinmanager | 22/3/2023 | 17/6/2026 | In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation. | |
| Modificada | Alta (7.5) | 77% | — | Rockwellautomation Thinmanager | 22/3/2023 | 17/6/2026 | In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed. | |
| Modificada | Crítica (9.8) | 13% | — | Rockwellautomation Thinmanager | 22/3/2023 | 17/6/2026 | In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could… | |
| Modificada | Media (5.5) | 4.1% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 1.8% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 1.8% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.5) | 0.26% | — | Visam Vbase Automation Base | 21/3/2023 | 17/6/2026 | Versions of VISAM VBASE Automation Base prior to 11.7.5 may disclose information if a valid user opens a specially crafted file. | |
| Modificada | Media (5.4) | 0.34% | — | University Information Management System Project University Information Management System | 20/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Izmir Katip Celebi University UBYS allows Stored XSS. This issue affects UBYS: before 23.03.16. | |
| Modificada | Media (4.3) | 0.85% | — | Rockwellautomation Modbus TCP Server ADD ON Instructions | 17/3/2023 | 17/6/2026 | Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP… | |
| Modificada | Baja (3.2) | 0.22% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A Service | 15/3/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 through 21.0.7 and 23.0.0 through 23.0.1 could allow a user with physical access to the system due to session tokens for not being invalidated after a password reset. IBM X-Force ID: 243710. | |
| Modificada | Media (6.5) | 0.60% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 15/3/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.1 through 21.0.5 is vulnerable to insufficiently protecting credentials. Queue Provider credentials are not obfuscated while editing queue provider details. IBM X-Force ID: 247032. | |
| Modificada | Media (6.5) | 0.50% | — | IBM Robotic Process AutomationIBM Robotic Process Automation AS A ServiceIBM Robotic Process Automation FOR Cloud PAK | 15/3/2023 | 17/6/2026 | IBM Robotic Process Automation 21.0.0 - 21.0.7 and 23.0.0 is vulnerable to client-side validation bypass for credential pools. Invalid credential pools may be created as a result. IBM X-Force ID: 242951. | |
| Modificada | Crítica (9.8) | 0.71% | — | Alpatateknoloji Licensed Warehousing Automation System | 10/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Alpata Licensed Warehousing Automation System allows Command Line Execution through SQL Injection. This issue affects Licensed Warehousing Automation System: through 2023.1.01. |