Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
180 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 1.4% | — | Wago Pfc200 Firmware | 12/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to… | |
| Modificada | Alta (7.8) | 1.4% | — | Wago Pfc200 Firmware | 12/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to… | |
| Modificada | Media (5.5) | 0.53% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable stack buffer overflow vulnerability vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file.The destination buffer sp+0x440 is overflowed with the call… | |
| Modificada | Alta (7.8) | 1.4% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to… | |
| Modificada | Alta (7.8) | 1.4% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to trigger the… | |
| Modificada | Alta (7.8) | 1.4% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can be used to inject OS commands. An attacker can send a specially crafted packet to… | |
| Modificada | Alta (7.8) | 1.3% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 Firmware version 03.02.02(14). An attacker can send a specially crafted packet to trigger the parsing of this cache file. At 0x1e840 the extracted ntp value from the xml file is used as an argument to… | |
| Modificada | Alta (7.8) | 1.3% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). An attacker can send a specially crafted XML cache file At 0x1e8a8 the extracted domainname value from the xml file is used as an argument to /etc/config-tools/edit_dns_server… | |
| Modificada | Alta (7.8) | 1.2% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the iocheckd service ‘I/O-Check’ function of the WAGO PFC 200 version 03.02.02(14). At 0x1e3f0 the extracted dns value from the xml file is used as an argument to /etc/config-tools/edit_dns_server %s dns-server-nr=%d dns-server-name=<contents of dns node> using… | |
| Modificada | Alta (7.8) | 0.82% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable stack buffer overflow vulnerability exists in the iocheckd service ‘I/O-Check’ functionality of WAGO PFC 200 version 03.02.02(14). A specially crafted XML cache file written to a specific location on the device can cause a stack buffer overflow, resulting in code execution. An attacker can send a… | |
| Modificada | Crítica (9.1) | 2.5% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable remote code execution vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted XML file will direct the Cloud Connectivity service to download and execute a shell script with root privileges. | |
| Modificada | Crítica (9.1) | 2.7% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable improper host validation vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). A specially crafted HTTPS POST request can cause the software to connect to an unauthorized host, resulting in unauthorized access to… | |
| Modificada | Alta (7.2) | 4.2% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the Cloud Connectivity functionality of WAGO PFC200 Firmware versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject OS commands into the TimeoutUnconfirmed parameter value contained in the Firmware Update command. | |
| Modificada | Alta (7.2) | 4.2% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the cloud connectivity functionality of WAGO PFC200 versions 03.02.02(14), 03.01.07(13), and 03.00.39(12). An attacker can inject operating system commands into the TimeoutPrepared parameter value contained in the firmware update command. | |
| Modificada | Alta (7.2) | 4.6% | — | Wago Pfc200 Firmware | 11/3/2020 | 17/6/2026 | An exploitable command injection vulnerability exists in the cloud connectivity feature of WAGO PFC200. An attacker can inject operating system commands into any of the parameter values contained in the firmware update command. This affects WAGO PFC200 Firmware version 03.02.02(14), version 03.01.07(13), and version… | |
| Modificada | Alta (7.5) | 1.8% | — | Wago Pfc200 FirmwareWago Pfc100 Firmware | 11/3/2020 | 17/6/2026 | The WBM web application on firmwares prior to 03.02.02 and 03.01.07 on the WAGO PFC100 and PFC2000, respectively, runs on a lighttpd web server and makes use of the FastCGI module, which is intended to provide high performance for all Internet applications without the penalties of Web server APIs. However, the default… | |
| Modificada | Media (5.3) | 1.0% | — | Wago Pfc200 FirmwareWago Pfc100 Firmware | 11/3/2020 | 17/6/2026 | An exploitable timing discrepancy vulnerability exists in the authentication functionality of the Web-Based Management (WBM) web application on WAGO PFC100/200 controllers. The WBM application makes use of the PHP crypt() function which can be exploited to disclose hashed user credentials. This affects WAGO PFC200… | |
| Modificada | Alta (7.5) | 2.3% | — | Wago Pfc200 FirmwareWago Pfc100 Firmware | 11/3/2020 | 17/6/2026 | An exploitable regular expression without anchors vulnerability exists in the Web-Based Management (WBM) authentication functionality of WAGO PFC200 versions 03.00.39(12) and 03.01.07(13), and WAGO PFC100 version 03.00.39(12). A specially crafted authentication request can bypass regular expression filters, resulting… | |
| Modificada | Media (6.5) | 1.9% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+11 | 24/1/2020 | 17/6/2026 | CODESYS Control V3, Gateway V3, and HMI V3 before 3.5.15.30 allow uncontrolled memory allocation which can result in a remote denial of service condition. | |
| Modificada | Alta (7.1) | 0.71% | — | Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus ReadystartSiemens Nucleus Safetycert+22 | 16/1/2020 | 17/6/2026 | A vulnerability has been identified in APOGEE MEC/MBC/PXC (P2) (All versions < V2.8.2), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8.2 < V2.8.19), APOGEE PXC Modular (BACnet) (All versions < V3.5.3), APOGEE PXC Modular (P2 Ethernet) (All versions >= V2.8.2… | |
| Modificada | Crítica (9.8) | 3.3% | — | Wago Pfc200 FirmwareWago Pfc100 Firmware | 8/1/2020 | 17/6/2026 | An exploitable heap buffer overflow vulnerability exists in the iocheckd service I/O-Check functionality of WAGO PFC200 Firmware version 03.01.07(13), WAGO PFC200 Firmware version 03.00.39(12), and WAGO PFC100 Firmware version 03.00.39(12). A specially crafted set of packets can cause a heap buffer overflow,… | |
| Modificada | Media (5.3) | 1.7% | — | Siemens Pxc00-e.d FirmwareSiemens Pxc50-e.d FirmwareSiemens Pxc100-e.d FirmwareSiemens Pxc200-e.d Firmware+12 | 12/12/2019 | 17/6/2026 | A vulnerability has been identified in Desigo PX automation controllers PXC00-E.D, PXC50-E.D, PXC100-E.D, PXC200-E.D with Desigo PX Web modules PXA40-W0, PXA40-W1, PXA40-W2 (All firmware versions < V6.00.320), Desigo PX automation controllers PXC00-U, PXC64-U, PXC128-U with Desigo PX Web modules PXA30-W0, PXA30-W1,… | |
| Modificada | Crítica (9.8) | 1.9% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+10 | 20/11/2019 | 17/6/2026 | CODESYS 3 web server before 3.5.15.20, as distributed with CODESYS Control runtime systems, has a Buffer Overflow. | |
| Modificada | Media (5.9) | 1.0% | — | Technicolor C2000t FirmwareTechnicolor C2100t Firmware | 6/11/2019 | 17/6/2026 | Technicolor C2000T and C2100T uses hard-coded cryptographic keys. | |
| Modificada | Media (6.5) | 1.4% | — | Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+6 | 17/9/2019 | 17/6/2026 | 3S-Smart Software Solutions GmbH CODESYS V3 OPC UA Server, all versions 3.5.11.0 to 3.5.15.0, allows an attacker to send crafted requests from a trusted OPC UA client that cause a NULL pointer dereference, which may trigger a denial-of-service condition. |