Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.47%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
An improper verification of the cryptographic signature of firmware updates of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to generate valid firmware updates with arbitrary content that can be used to tamper with devices.
ModificadaAlta (7.5)0.62%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to recover user credentials of the administrative interface.
ModificadaAlta (7.5)1.9%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A XPath injection vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows unauthenticated remote attackers to access sensitive information and escalate privileges.
ModificadaMedia (6.3)0.21%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
Improper access controls in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 enables attackers to extract and tamper with the devices network configuration.
ModificadaMedia (6.1)0.85%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A reflected cross-site scripting (XSS) vulnerability in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to inject arbitrary web script or HTML into various locations.
ModificadaAlta (7.2)1.2%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
Active debug code in the B. Braun Melsungen AG SpaceCom Version L8/U61, and the Data module compactplus Versions A10 and A11 and earlier enables attackers in possession of cryptographic material to access the device as root.
ModificadaMedia (6.1)0.66%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
An open redirect vulnerability in the administrative interface of the B. Braun Melsungen AG SpaceCom device Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers to redirect users to malicious websites.
ModificadaAlta (8.1)1.3%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A session fixation vulnerability in the B. Braun Melsungen AG SpaceCom administrative interface Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows remote attackers to hijack web sessions and escalate privileges.
ModificadaAlta (8.8)1.5%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A relative path traversal attack in the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with service user privileges to upload arbitrary files. By uploading a specially crafted tar file an attacker can execute arbitrary commands.
ModificadaMedia (6.7)0.25%—Bbraun Datamodule CompactplusBbraun Spacecom14/4/202217/6/2026
A vulnerability in the configuration import mechanism of the B. Braun Melsungen AG SpaceCom Version L81/U61 and earlier, and the Data module compactplus Versions A10 and A11 allows attackers with command line access to the underlying Linux system to escalate privileges to the root user.
ModificadaCrítica (9.8)5.2%—Rockwellautomation Compactlogix 1768-l43 FirmwareRockwellautomation Compactlogix 1768-l45 FirmwareRockwellautomation Compactlogix 1769-l31 FirmwareRockwellautomation Compactlogix 1769-l32c Firmware+2011/4/202217/6/2026
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the…
ModificadaAlta (7.2)3.5%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compactlogix 5480 Firmware+11/4/202217/6/2026
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.
ModificadaAlta (7.5)0.95%—ABB 800xaABB Base SoftwareABB Compact Product SuiteABB Control Builder Safe1/4/202217/6/2026
Improper Input Validation vulnerability in ABB 800xA, Control Software for AC 800M, Control Builder Safe, Compact Product Suite - Control and I/O, ABB Base Software for SoftControl allows an attacker to cause the denial of service.
ModificadaMedia (5.1)0.14%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+2109/2/202217/6/2026
Select Dell Client Commercial and Consumer platforms are vulnerable to an insufficient verification of data authenticity vulnerability. An authenticated malicious user may exploit this vulnerability in order to install modified BIOS firmware.
ModificadaAlta (7.2)0.26%—Dell Alienware Area 51M R1 FirmwareDell Alienware Area 51M R2 FirmwareDell Alienware M15 R3 FirmwareDell Alienware M15 R4 Firmware+2109/2/202217/6/2026
Select Dell Client Commercial and Consumer platforms contain a pre-boot direct memory access (DMA) vulnerability. An authenticated attacker with physical access to the system may potentially exploit this vulnerability in order to execute arbitrary code on the device.
ModificadaAlta (7.4)1.2%—Fanuc R-30ia FirmwareFanuc R-30ia Mate FirmwareFanuc R-30ib Mate FirmwareFanuc R-30ib Compact Firmware+510/1/202217/6/2026
The FANUC R-30iA and R-30iB series controllers are vulnerable to an out-of-bounds write, which may allow an attacker to remotely execute arbitrary code. INIT START/restore from backup required.
ModificadaAlta (7.5)1.1%—Fanuc R-30ia FirmwareFanuc R-30ia Mate FirmwareFanuc R-30ib Mate FirmwareFanuc R-30ib Compact Firmware+510/1/202217/6/2026
The FANUC R-30iA and R-30iB series controllers are vulnerable to integer coercion errors, which cause the device to crash. A restart is required.
ModificadaMedia (4.9)2.5%—Auerswald Compact 5500r IP FirmwareAuerswald Compact 5200r IP FirmwareAuerswald Compact 5000r IP FirmwareAuerswald Compact 4000 IP Firmware+613/12/202117/6/2026
Auerswald COMpact 5500R devices before 8.2B allow Arbitrary File Disclosure. A sub-admin can read the cleartext Admin password via the fileName=../../etc/passwd substring.
ModificadaAlta (8.8)2.1%—Auerswald Compact 5500r IP FirmwareAuerswald Compact 5200r IP FirmwareAuerswald Compact 5000r IP FirmwareAuerswald Compact 4000 IP Firmware+613/12/202117/6/2026
Auerswald COMpact 5500R devices before 8.2B allow Privilege Escalation via the passwd=1 substring.
ModificadaCrítica (9.8)72%💥 ExploitAuerswald Compact 5500r Firmware7/12/202117/6/2026
Backdoors were discovered in Auerswald COMpact 5500R 7.8A and 8.0B devices, that allow attackers with access to the web based management application full administrative access to the device.
ModificadaCrítica (9.8)2.5%—Circutor Compact Dc-s Basic Firmware2/12/202117/6/2026
Buffer overflow vulnerability in function SetFirewall in index.cgi in CIRCUTOR COMPACT DC-S BASIC smart metering concentrator Firwmare version CIR_CDC_v1.2.17, allows attackers to execute arbitrary code.
ModificadaCrítica (9.1)2.2%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+79/11/202117/6/2026
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). The total length of an TCP payload…
ModificadaCrítica (9.1)2.2%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+69/11/202117/6/2026
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0). Malformed TCP packets with a corrupted SACK option leads to Information Leaks and…
ModificadaAlta (8.8)2.4%—Siemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source CodeSiemens Apogee Modular Building Controller Firmware+189/11/202117/6/2026
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions <…
ModificadaAlta (8.8)2.4%—Siemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source CodeSiemens Apogee Modular Building Controller Firmware+189/11/202117/6/2026
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions <…