Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
–

3560 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaAlta (7.8)0.23%—Hornerautomation Cscape Envision RV9/3/202317/6/2026
Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in reads past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute…
ModificadaMedia (6.1)0.36%—Ubit Student Information Management System7/3/202317/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management System: before 20211126.
ModificadaMedia (6.1)0.36%—Ubit Student Information Management System7/3/202317/6/2026
Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management System: before 20211126.
ModificadaMedia (5.4)0.36%—Yordam Library Automation System2/3/202317/6/2026
Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS. This issue affects Library Automation System: before 19.2.
ModificadaMedia (6.5)0.59%—Yordam Library Automation System2/3/202317/6/2026
Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2.
ModificadaMedia (6.5)0.59%—Yordam Library Automation System2/3/202317/6/2026
Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2.
ModificadaCrítica (9.8)0.67%—Uzaybaskul Weighbridge Automation Software1/3/202317/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1.
ModificadaAlta (7.1)0.15%—Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+128/2/202317/6/2026
Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,…
ModificadaMedia (5.4)0.39%—IBM Cloud PAK FOR Business Automation27/2/202317/6/2026
IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended…
ModificadaMedia (5.5)0.24%—Mz-automation Lib6087024/2/202317/6/2026
Se descubrió un problema en lib60870 v2.3.2. Hay una pérdida de memoria en lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c.
ModificadaCrítica (9.8)12%—GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+523/2/202317/6/2026
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
ModificadaCrítica (9.8)2.9%—GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+523/2/202317/6/2026
The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code.
ModificadaAlta (8.8)1.3%—Vmware Vrealize AutomationVmware Vrealize Orchestrator22/2/202317/6/2026
VMware vRealize Orchestrator contiene una vulnerabilidad de entidad externa XML (XXE). Un actor malintencionado, con acceso no administrativo a vRealize Orchestrator, puede utilizar entradas especialmente manipuladas para evitar las restricciones de análisis XML que conducen al acceso a información confidencial o a…
ModificadaMedia (5.4)0.38%—IBM Infosphere Information Server21/2/202317/6/2026
IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247646.
ModificadaMedia (5.5)0.26%—Redhat ResteasyNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation17/2/202317/6/2026
In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user.
ModificadaAlta (7.5)1.4%—IBM Infosphere Information Server17/2/202317/6/2026
IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 246333
ModificadaAlta (7.5)0.39%—IBM Qradar Security Information AND Event Manager17/2/202317/6/2026
IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402.
ModificadaMedia (5.5)0.13%—IBM Infosphere Information Server17/2/202317/6/2026
IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463.
ModificadaMedia (6.1)0.56%—Br-automation Automation Runtime14/2/202317/6/2026
A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session.
ModificadaMedia (4.6)0.35%—IBM Infosphere Information Server8/2/202317/6/2026
IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245423.
ModificadaAlta (7.5)0.62%—Br-automation Industrial Automation Aprol8/2/202317/6/2026
B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service.
ModificadaCrítica (9.8)0.78%—Br-automation Industrial Automation Aprol8/2/202317/6/2026
Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code.
ModificadaAlta (7.5)0.62%—Br-automation Industrial Automation Aprol8/2/202317/6/2026
Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07.