Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2761▲ 61 respecto a la semana anterior
Críticas / altas1285▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)233▲ 215 respecto a la semana anterior
3560 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in reads past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Media (6.1) | 0.36% | — | Ubit Student Information Management System | 7/3/2023 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management System: before 20211126. | |
| Modificada | Media (6.1) | 0.36% | — | Ubit Student Information Management System | 7/3/2023 | 17/6/2026 | Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability in UBIT Information Technologies Student Information Management System. This issue affects Student Information Management System: before 20211126. | |
| Modificada | Media (5.4) | 0.36% | — | Yordam Library Automation System | 2/3/2023 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation vulnerability in Yordam Information Technologies Library Automation System allows Stored XSS. This issue affects Library Automation System: before 19.2. | |
| Modificada | Media (6.5) | 0.59% | — | Yordam Library Automation System | 2/3/2023 | 17/6/2026 | Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2. | |
| Modificada | Media (6.5) | 0.59% | — | Yordam Library Automation System | 2/3/2023 | 17/6/2026 | Improper Handling of Parameters vulnerability in Bordam Information Technologies Library Automation System allows Collect Data as Provided by Users. This issue affects Library Automation System: before 19.2. | |
| Modificada | Crítica (9.8) | 0.67% | — | Uzaybaskul Weighbridge Automation Software | 1/3/2023 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Uzay Baskul Weighbridge Automation Software allows SQL Injection. This issue affects Weighbridge Automation Software: before 1.1. | |
| Modificada | Alta (7.1) | 0.15% | — | Hitachi Automation DirectorHitachi Infrastructure Analytics AdvisorHitachi OPS Center AnalyzerHitachi OPS Center Automator+1 | 28/2/2023 | 17/6/2026 | Incorrect Default Permissions vulnerability in Hitachi Automation Director on Linux, Hitachi Infrastructure Analytics Advisor on Linux (Hitachi Infrastructure Analytics Advisor, Analytics probe server components), Hitachi Ops Center Automator on Linux, Hitachi Ops Center Analyzer on Linux (Hitachi Ops Center Analyzer,… | |
| Modificada | Media (5.4) | 0.39% | — | IBM Cloud PAK FOR Business Automation | 27/2/2023 | 17/6/2026 | IBM Cloud Pak for Business Automation 18.0.0, 18.0.1, 18.0.2, 19.0.1, 19.0.2, 19.0.3, 20.0.1, 20.0.2, 20.0.3, 21.0.1, 21.0.2, 21.0.3, 22.0.1, and 22.0.2 is vulnerable to stored cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended… | |
| Modificada | Media (5.5) | 0.24% | — | Mz-automation Lib60870 | 24/2/2023 | 17/6/2026 | Se descubrió un problema en lib60870 v2.3.2. Hay una pérdida de memoria en lib60870/lib60870-C/examples/multi_client_server/multi_client_server.c. | |
| Modificada | Crítica (9.8) | 12% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code. | |
| Modificada | Crítica (9.8) | 2.9% | — | GE Digital Industrial Gateway ServerPTC Kepware ServerPTC Kepware ServerexPTC Thingworx .net-sdk+5 | 23/2/2023 | 17/6/2026 | The affected products are vulnerable to an integer overflow or wraparound, which could allow an attacker to crash the server and remotely execute arbitrary code. | |
| Modificada | Alta (8.8) | 1.3% | — | Vmware Vrealize AutomationVmware Vrealize Orchestrator | 22/2/2023 | 17/6/2026 | VMware vRealize Orchestrator contiene una vulnerabilidad de entidad externa XML (XXE). Un actor malintencionado, con acceso no administrativo a vRealize Orchestrator, puede utilizar entradas especialmente manipuladas para evitar las restricciones de análisis XML que conducen al acceso a información confidencial o a… | |
| Modificada | Media (5.4) | 0.38% | — | IBM Infosphere Information Server | 21/2/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 247646. | |
| Modificada | Media (5.5) | 0.26% | — | Redhat ResteasyNetapp Active IQ Unified ManagerNetapp Oncommand Workflow Automation | 17/2/2023 | 17/6/2026 | In RESTEasy the insecure File.createTempFile() is used in the DataSourceProvider, FileProvider and Mime4JWorkaround classes which creates temp files with insecure permissions that could be read by a local user. | |
| Modificada | Alta (7.5) | 1.4% | — | IBM Infosphere Information Server | 17/2/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a remote attacker to traverse directories on the system. An attacker could send a specially crafted URL request containing "dot dot" sequences (/../) to view arbitrary files on the system. IBM X-Force ID: 246333 | |
| Modificada | Alta (7.5) | 0.39% | — | IBM Qradar Security Information AND Event Manager | 17/2/2023 | 17/6/2026 | IBM QRadar SIEM 7.4 and 7.5 is vulnerable to information exposure allowing a non-tenant user with a specific domain security profile assigned to see some data from other domains. IBM X-Force ID: 230402. | |
| Modificada | Media (5.5) | 0.13% | — | IBM Infosphere Information Server | 17/2/2023 | 17/6/2026 | IBM InfoSphere Information Server 11.7 could allow a local user to obtain sensitive information from a log files. IBM X-Force ID: 246463. | |
| Modificada | Media (6.1) | 0.56% | — | Br-automation Automation Runtime | 14/2/2023 | 17/6/2026 | A reflected cross-site scripting (XSS) vulnerability exists in System Diagnostics Manager of B&R Automation Runtime versions >=3.00 and <=C4.93 that enables a remote attacker to execute arbitrary JavaScript in the context of the users browser session. | |
| Modificada | Media (4.6) | 0.35% | — | IBM Infosphere Information Server | 8/2/2023 | 17/6/2026 | IBM Infosphere Information Server 11.7 is vulnerable to cross-site scripting. This vulnerability allows users to embed arbitrary JavaScript code in the Web UI thus altering the intended functionality potentially leading to credentials disclosure within a trusted session. IBM X-Force ID: 245423. | |
| Modificada | Alta (7.5) | 0.62% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service. | |
| Modificada | Crítica (9.8) | 0.78% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code. | |
| Modificada | Alta (7.5) | 0.62% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07. |