Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
2424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.8) | 5.0% | ⚠ Explotación activa | Google ChromeSiemens Cadra | 17/11/2025 | 14/7/2026 | Type Confusion in V8 in Google Chrome prior to 142.0.7444.175 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Alta (7.3) | 0.20% | — | Siemens PS Iges Parasolid Translator ComponentAISiemens Simcenter FemapAISiemens Solid EdgeAI | 17/11/2025 | 17/6/2026 | A vulnerability has been identified in PS/IGES Parasolid Translator Component (All versions < V29.0.258), Simcenter Femap (All versions < V2512.0003), Solid Edge (All versions < V226.00 Update 03). The affected applications contains an out of bounds read vulnerability while parsing specially crafted IGS files. This… | |
| Aplazada | Alta (8.5) | 0.16% | — | Siemens Software CenterAISiemens Solid Edge Se2025AI | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in Siemens Software Center (All versions < V3.5), Solid Edge SE2025 (All versions < V225.0 Update 10). The affected application is vulnerable to DLL hijacking. This could allow an attacker to execute arbitrary code via placing a crafted DLL file on the system. | |
| Aplazada | Alta (7.1) | 0.22% | — | Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+12 | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo… | |
| Aplazada | Alta (7.2) | 0.20% | — | Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+12 | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo… | |
| Aplazada | Alta (8.6) | 0.35% | — | Siemens Logo 12 24rceAISiemens Logo 12 24rceoAISiemens Logo 230rceAISiemens Logo 230rceoAI+12 | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in LOGO! 12/24RCE (6ED1052-1MD08-0BA2) (All versions), LOGO! 12/24RCEo (6ED1052-2MD08-0BA2) (All versions), LOGO! 230RCE (6ED1052-1FB08-0BA2) (All versions), LOGO! 230RCEo (6ED1052-2FB08-0BA2) (All versions), LOGO! 24CE (6ED1052-1CC08-0BA2) (All versions), LOGO! 24CEo… | |
| Aplazada | Alta (8.7) | 0.21% | — | Siemens Solid Edge Se2025AI | 11/11/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2025 (All versions < V225.0 Update 11). Affected applications do not properly validate client certificates to connect to License Service endpoint. This could allow an unauthenticated remote attacker to perform man in the middle attacks. | |
| Analizada | Media (4.8) | 0.27% | — | Fortinet Fortisiem | 14/10/2025 | 17/6/2026 | An improper neutralization of input during web page generation vulnerability [CWE-79] in FortiSIEM 7.2.0 through 7.2.2, 7.1 all versions, 7.0 all versions, 6.7 all versions, 6.6 all versions, 6.5 all versions, 6.4 all versions, 6.3 all versions, 6.2 all versions may allow an authenticated attacker to perform a stored… | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Solid Edge Se2024Siemens Solid Edge Se2025 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or… | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Solid Edge Se2024Siemens Solid Edge Se2025 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds read vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or… | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Solid Edge Se2024Siemens Solid Edge Se2025 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or… | |
| Analizada | Alta (7.3) | 0.14% | — | Siemens Solid Edge Se2024Siemens Solid Edge Se2025 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in Solid Edge SE2024 (All versions < V224.0 Update 14), Solid Edge SE2025 (All versions < V225.0 Update 6). The affected applications contains an out of bounds write vulnerability while parsing specially crafted PRT files. This could allow an attacker to crash the application or… | |
| Analizada | Media (6.7) | 0.14% | — | Siemens Sipass Integrated | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications store user passwords encrypted in its database. Decryption keys are accessible to users with administrative privileges, allowing them to recover passwords. Successful exploitation of this vulnerability allows… | |
| Analizada | Media (5.1) | 0.20% | — | Siemens Sipass Integrated | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications contains a broken access control vulnerability. The authorization mechanism lacks sufficient server-side checks, allowing an attacker to execute a specific API request. Successful exploitation allows an… | |
| Analizada | Alta (7) | 0.32% | — | Siemens Sipass Integrated | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in SiPass integrated (All versions < V3.0). Affected server applications are vulnerable to stored Cross-Site Scripting (XSS), allowing an attacker to inject malicious code that can be executed by other users when they visit the affected page. Successful exploitation allows an… | |
| Aplazada | Crítica (9.3) | 0.53% | — | Siemens Simatic CP 1542sp-1AISiemens Simatic CP 1542sp-1 IRCAISiemens Simatic CP 1543sp-1AISiemens Siplus ET 200sp CP 1542sp-1 IRC TX RailAI+2 | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1542SP-1 (6GK7542-6UX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1542SP-1 IRC (6GK7542-6VX00-0XE0) (All versions < V2.4.24), SIMATIC CP 1543SP-1 (6GK7543-6WX00-0XE0) (All versions < V2.4.24), SIPLUS ET 200SP CP 1542SP-1 IRC TX RAIL (6AG2542-6VX00-4XE0) (All versions… | |
| Analizada | Crítica (9.3) | 0.53% | — | Siemens Telecontrol Server Basic | 14/10/2025 | 17/6/2026 | A vulnerability has been identified in TeleControl Server Basic V3.1 (All versions >= V3.1.2.2 < V3.1.2.3). The affected application contains an information disclosure vulnerability. This could allow an unauthenticated remote attacker to obtain password hashes of users and to login to and perform authenticated… | |
| Aplazada | Alta (8.3) | 0.31% | — | Siemens Simatic S7-1200 CPU V1AISiemens Simatic S7-1200 CPU V2AI | 14/10/2025 | 16/6/2026 | A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.2), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.2). Affected controllers are vulnerable to capture-replay in the communication with the engineering software. This could allow… | |
| Aplazada | Alta (8.7) | 0.47% | — | Siemens Simatic S7-1200 CPU V1AISiemens Simatic S7-1200 CPU V2AI | 14/10/2025 | 16/6/2026 | A vulnerability has been identified in SIMATIC S7-1200 CPU V1 family (incl. SIPLUS variants) (All versions < V2.0.3), SIMATIC S7-1200 CPU V2 family (incl. SIPLUS variants) (All versions < V2.0.3). The web server interface of affected devices improperly processes incoming malformed HTTP traffic at high rate. This could… | |
| Analizada | Alta (8.7) | 0.37% | — | Siemens Sinec NMS | 14/10/2025 | 5/10/2026 | A vulnerability has been identified in SINEC NMS (All versions < V4.0 SP1). Affected applications are vulnerable to SQL injection through getTotalAndFilterCounts endpoint. An authenticated low privileged attacker could exploit to insert data and achieve privilege escalation. (ZDI-CAN-26570) | |
| Analizada | Media (5.5) | 1.3% | ⚠ Explotación activa💥 PoC | Linux KernelSiemens Simatic S7-1500 CPU 1518-4 Pn/dp MFP FirmwareSiemens Simatic S7-1500 CPU 1518f-4 Pn/dp MFP Firmware | 13/10/2025 | 19/9/2026 | In the Linux kernel, the following vulnerability has been resolved: crypto: af_alg - Disallow concurrent writes in af_alg_sendmsg Issuing two writes to the same af_alg socket is bogus as the data will be interleaved in an unpredictable fashion. Furthermore, concurrent writes may create inconsistencies in the internal… | |
| Aplazada | Crítica (9.6) | 0.56% | 💥 PoC | NPMAISiemens NXAI | 24/9/2025 | 17/6/2026 | Malicious code was inserted into the Nx (build system) package and several related plugins. The tampered package was published to the npm software registry, via a supply-chain attack. Affected versions contain code that scans the file system, collects credentials, and posts them to GitHub as a repo under user's… | |
| Analizada | Crítica (9.8) | 5.4% | ⚠ Explotación activa💥 PoC | Google ChromeSiemens Cadra | 24/9/2025 | 14/7/2026 | Type confusion in V8 in Google Chrome prior to 140.0.7339.185 allowed a remote attacker to potentially exploit heap corruption via a crafted HTML page. (Chromium security severity: High) | |
| Aplazada | Crítica (9.3) | 0.40% | — | Siemens Simatic Virtualization AS A ServiceAI | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC Virtualization as a Service (SIVaaS) (All versions). The affected application exposes a network share without any authentication. This could allow an attacker to access or alter sensitive data without proper authorization. | |
| Analizada | Baja (2.3) | 0.18% | — | Siemens Ruggedcom Rst2428p Firmware | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device exposes certain non-critical information from the device. This could allow an unauthenticated attacker to access sensitive data, potentially leading to a breach of confidentiality. |