Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

229 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.57%—Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+29/8/202317/6/2026
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem through a configuration dialog within the embedded Qt browser .
ModificadaMedia (4.3)0.57%—Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+29/8/202317/6/2026
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges is able to gain limited read-access to the device-filesystem within the embedded Qt browser.
ModificadaAlta (8.8)1.2%—Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+28/8/202317/6/2026
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a command injection in a HTTP POST request releated to font configuration operations to gain full access to the device.
ModificadaCrítica (9.9)1.0%—Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+28/8/202317/6/2026
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote, unauthenticated attacker may use an attribute of a specific HTTP POST request releated to date/time operations to gain full access to the device.
ModificadaAlta (8.8)0.59%—Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+28/8/202317/6/2026
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP POST releated to certificate operations to gain full access to the device.
ModificadaAlta (8.8)0.93%—Phoenixcontact WP 6070-wvps FirmwarePhoenixcontact WP 6101-wxps FirmwarePhoenixcontact WP 6121-wxps FirmwarePhoenixcontact WP 6156-whps Firmware+28/8/202317/6/2026
In PHOENIX CONTACTs WP 6xxx series web panels in versions prior to 4.0.10 a remote attacker with low privileges may use a specific HTTP DELETE request to gain full access to the device.
ModificadaMedia (4.9)1.4%—Phoenixcontact Cloud Client 1101t-tx FirmwarePhoenixcontact TC Cloud Client 1002-4g ATT FirmwarePhoenixcontact TC Cloud Client 1002-4g FirmwarePhoenixcontact TC Cloud Client 1002-4g VZW Firmware+38/8/202317/6/2026
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an authenticated remote attacker with admin privileges could upload a crafted XML file which causes a denial-of-service.
ModificadaCrítica (9.6)1.8%—Phoenixcontact Cloud Client 1101t-tx FirmwarePhoenixcontact TC Cloud Client 1002-4g ATT FirmwarePhoenixcontact TC Cloud Client 1002-4g FirmwarePhoenixcontact TC Cloud Client 1002-4g VZW Firmware+38/8/202317/6/2026
In PHOENIX CONTACTs TC ROUTER and TC CLOUD CLIENT in versions prior to 2.07.2 as well as CLOUD CLIENT 1101T-TX/TX prior to 2.06.10 an unauthenticated remote attacker could use a reflective XSS within the license viewer page of the devices in order to execute code in the context of the user's browser.
ModificadaMedia (5.3)0.62%—Phoenixcontact FL Mguard 2102 FirmwarePhoenixcontact FL Mguard 4102 PCI FirmwarePhoenixcontact FL Mguard 4102 Pcie FirmwarePhoenixcontact FL Mguard 4302 Firmware+2213/6/202317/6/2026
Improper Input Validation vulnerability in PHOENIX CONTACT FL/TC MGUARD Family in multiple versions may allow UDP packets to bypass the filter rules and access the solely connected device behind the MGUARD which can be used for flooding attacks.
ModificadaAlta (8.8)0.76%—Phoenixcontact Energy AXC PUPhoenixcontact Infobox FirmwarePhoenixcontact Smartrtu AXC SG FirmwarePhoenixcontact Smartrtu AXC IG Firmware17/4/202317/6/2026
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
ModificadaCrítica (9.8)0.66%—Phoenixcf Project Phoenixcf18/1/202316/6/2026
A vulnerability was found in iamdroppy phoenixcf. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file content/2-Community/articles.cfm. The manipulation leads to sql injection. The patch is named d156faf8bc36cd49c3b10d3697ef14167ad451d8. It is recommended to apply a…
ModificadaMedia (6.1)0.41%—Phoenixframework Phoenix Html10/1/202317/6/2026
tag.ex in Phoenix Phoenix.HTML (aka phoenix_html) before 3.0.4 allows XSS in HEEx class attributes.
ModificadaAlta (7.5)0.89%—Phoenixcoin Project Phoenixcoin30/12/202217/6/2026
A vulnerability was found in ghostlander Phoenixcoin. It has been classified as problematic. Affected is the function CTxMemPool::accept of the file src/main.cpp. The manipulation leads to denial of service. Upgrading to version 0.6.6.1-pxc is able to address this issue. The name of the patch is…
ModificadaAlta (7.8)0.21%—Phoenixcontact Automationworx Software Suite15/11/202217/6/2026
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 memory can be read beyond the intended scope due to insufficient validation of input data. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
ModificadaAlta (7.5)0.91%—Phoenixcontact FL Mguard Centerport FirmwarePhoenixcontact FL Mguard Centerport Vpn-1000 FirmwarePhoenixcontact FL Mguard Core TX FirmwarePhoenixcontact FL Mguard Core TX VPN Firmware+2715/11/202217/6/2026
A remote, unauthenticated attacker could cause a denial-of-service of PHOENIX CONTACT FL MGUARD and TC MGUARD devices below version 8.9.0 by sending a larger number of unauthenticated HTTPS connections originating from different source IP’s. Configuring firewall limits for incoming connections cannot prevent the issue.
ModificadaAlta (7.8)0.21%—Phoenixcontact Automationworx Software Suite15/11/202217/6/2026
In PHOENIX CONTACT Automationworx Software Suite up to version 1.89 manipulated PC Worx or Config+ files could lead to a heap buffer overflow and a read access violation. Availability, integrity, or confidentiality of an application programming workstation might be compromised by attacks using these vulnerabilities.
ModificadaAlta (7.5)0.61%—Phoenixcontact FL Mguard DM9/11/202217/6/2026
In Phoenix Contact: FL MGUARD DM version 1.12.0 and 1.13.0 access to the Apache web server being installed as part of the FL MGUARD DM on Microsoft Windows does not require login credentials even if configured during installation.Attackers with network access to the Apache web server can download and therefore read…
ModificadaAlta (7.5)0.57%—Phoenixframework Phoenix17/10/202217/6/2026
socket/transport.ex in Phoenix before 1.6.14 mishandles check_origin wildcarding. NOTE: LiveView applications are unaffected by default because of the presence of a LiveView CSRF token.
ModificadaCrítica (9.8)1.1%—Phoenixcontact MultiprogPhoenixcontact ProconosPhoenixcontact-software Proconos Eclr21/6/202217/6/2026
An unauthenticated, remote attacker could upload malicious logic to the devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
ModificadaCrítica (9.8)1.6%—Phoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 FirmwarePhoenixcontact FC 350 PCI ETH Firmware+1321/6/202217/6/2026
An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device.
ModificadaCrítica (9.1)0.65%—Phoenixcontact Rad-ism-900-en-bd FirmwarePhoenixcontact Rad-ism-900-en-bd/b FirmwarePhoenixcontact Rad-ism-900-en-bd-bus Firmware11/5/202217/6/2026
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the configuration file uploader in the WebUI to execute arbitrary code with root privileges on the OS due to an improper validation of an integrity check value in all versions of the firmware.
ModificadaCrítica (9.1)1.4%—Phoenixcontact Rad-ism-900-en-bd FirmwarePhoenixcontact Rad-ism-900-en-bd/b FirmwarePhoenixcontact Rad-ism-900-en-bd-bus Firmware11/5/202217/6/2026
On various RAD-ISM-900-EN-* devices by PHOENIX CONTACT an admin user could use the traceroute utility integrated in the WebUI to execute arbitrary code with root privileges on the OS due to an improper input validation in all versions of the firmware.
ModificadaAlta (8.8)0.99%—Phoenixcontact FL Switch 2005 FirmwarePhoenixcontact FL Switch 2008 FirmwarePhoenixcontact FL Switch 2008f FirmwarePhoenixcontact FL Switch 2016 Firmware+612/2/202217/6/2026
In Phoenix Contact FL SWITCH Series 2xxx in version 3.00 an incorrect privilege assignment allows an low privileged user to enable full access to the device configuration.
ModificadaAlta (7.5)0.93%—Phoenixcontact FL Mguard 1102 FirmwarePhoenixcontact FL Mguard 1105 Firmware10/11/202117/6/2026
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 the remote logging functionality is impaired by the lack of memory release for data structures from syslog-ng when remote logging is active
ModificadaMedia (4.8)0.29%—Phoenixcontact FL Mguard 1102 FirmwarePhoenixcontact FL Mguard 1105 Firmware10/11/202117/6/2026
In Phoenix Contact FL MGUARD 1102 and 1105 in Versions 1.4.0, 1.4.1 and 1.5.0 a user with high privileges can inject HTML code (XSS) through web-based management or the REST API with a manipulated certificate file.
Orbitaley — Vulnerabilidades