Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

180 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+1017/9/201917/6/2026
An issue was discovered in 3S-Smart CODESYS before 3.5.15.0 . Crafted network packets cause the Control Runtime to crash.
ModificadaAlta (8.8)1.9%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Pfc100+617/9/201917/6/2026
An issue was discovered in 3S-Smart CODESYS V3 through 3.5.12.30. A user with low privileges can take full control over the runtime.
ModificadaCrítica (9.8)5.8%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+913/9/201917/6/2026
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which could cause a stack overflow and create a denial-of-service condition or allow remote code execution.
ModificadaAlta (7.5)3.2%—Codesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000Codesys Control FOR Linux+913/9/201917/6/2026
CODESYS V3 web server, all versions prior to 3.5.14.10, allows an attacker to send specially crafted http or https requests which may allow access to files outside the restricted working directory of the controller.
ModificadaAlta (7.5)1.8%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+615/8/201917/6/2026
An issue was discovered in 3S-Smart CODESYS V3 products. A crafted communication request may cause uncontrolled memory allocations in the affected CODESYS products and may result in a denial-of-service condition. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the…
ModificadaCrítica (9.8)1.9%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+615/8/201917/6/2026
An issue was discovered in 3S-Smart CODESYS V3 products. The CODESYS Gateway does not correctly verify the ownership of a communication channel. All variants of the following CODESYS V3 products in all versions prior to v3.5.14.20 that contain the CmpGateway component are affected, regardless of the CPU type or…
ModificadaAlta (8.8)0.28%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+815/8/201917/6/2026
An issue was discovered in 3S-Smart CODESYS V3 products. The application may utilize non-TLS based encryption, which results in user credentials being insufficiently protected during transport. All variants of the following CODESYS V3 products in all versions containing the CmpUserMgr component are affected regardless…
ModificadaAlta (7.5)3.0%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1419/2/201917/6/2026
Improper Communication Address Filtering exists in CODESYS V3 products versions prior V3.5.14.0.
ModificadaAlta (7.5)2.6%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+1119/2/201917/6/2026
Use of Insufficiently Random Values exists in CODESYS V3 products versions prior V3.5.14.0.
ModificadaCrítica (9.8)1.3%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+829/1/201917/6/2026
In 3S-Smart Software Solutions GmbH CODESYS Control V3 products prior to version 3.5.14.0, user access management and communication encryption is not enabled by default, which could allow an attacker access to the device and sensitive information, including user credentials.
ModificadaMedia (6.1)1.0%—Ricoh MP C2003sp Firmware26/9/201817/6/2026
On the RICOH MP C2003 printer, HTML Injection and Stored XSS vulnerabilities have been discovered in the area of adding addresses via the entryNameIn parameter to /web/entry/en/address/adrsSetUserWizard.cgi.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in the httpd process in multiple models of Axis IP Cameras. There is Memory Corruption.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Incorrect Size Calculation.
ModificadaCrítica (9.8)80%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is an Exposed Insecure Interface.
ModificadaCrítica (9.8)87%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is a bypass of access control.
ModificadaCrítica (9.8)82%💥 ExploitAxis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
An issue was discovered in multiple models of Axis IP Cameras. There is Shell Command Injection.
ModificadaAlta (7.5)1.8%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which allows remote attackers to cause a denial of service (crash) by sending a crafted command which will result in a code path that calls the UND undefined ARM instruction.
ModificadaAlta (7.5)1.5%—Axis A1001 FirmwareAxis A8004-v FirmwareAxis A8105-e FirmwareAxis A9161 Firmware+38626/6/201817/6/2026
There was a Memory Corruption issue discovered in multiple models of Axis IP Cameras which causes a denial of service (crash). The crash arises from code inside libdbus-send.so shared object or similar.
ModificadaCrítica (9.8)2.7%—Wago Pfc200 Firmware13/2/201817/6/2026
An Improper Authentication issue was discovered in WAGO PFC200 Series 3S CoDeSys Runtime versions 2.3.X and 2.4.X. An attacker can execute different unauthenticated remote operations because of the CoDeSys Runtime application, which is available via network by default on Port 2455. An attacker could execute some…
ModificadaCrítica (9.8)1.7%—Basystems Bas920 FirmwareBasystems Isc2000 Firmware29/12/201717/6/2026
BA SYSTEMS BAS Web on BAS920 devices (with Firmware 01.01.00*, HTTPserv 00002, and Script 02.*) and ISC2000 devices allows remote attackers to obtain sensitive information via a request for isc/get_sid_js.aspx or isc/get_sid.aspx, as demonstrated by obtaining administrative access by subsequently using the credential…
AnalizadaAlta (8.1)99%⚠ Explotación activa💥 ExploitMicrosoft Server Message BlockSiemens Acuson P300 FirmwareSiemens Acuson P500 FirmwareSiemens Acuson Sc2000 Firmware+517/3/201717/6/2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote…
AnalizadaAlta (7.5)100%⚠ Explotación activa💥 ExploitMicrosoft Windows 10 1507Microsoft Windows 10 1511Microsoft Windows 10 1607Microsoft Windows 7+1417/3/201717/6/2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to obtain sensitive information from process memory via a crafted…
AnalizadaAlta (8.8)90%⚠ Explotación activa💥 ExploitMicrosoft Server Message BlockSiemens Acuson P300 FirmwareSiemens Acuson P500 FirmwareSiemens Acuson Sc2000 Firmware+517/3/201717/6/2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote…
AnalizadaAlta (8.8)90%⚠ Explotación activa💥 ExploitMicrosoft Server Message BlockSiemens Acuson P300 FirmwareSiemens Acuson P500 FirmwareSiemens Acuson Sc2000 Firmware+517/3/201714/8/2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote…
AnalizadaAlta (8.8)99%⚠ Explotación activa💥 ExploitMicrosoft Server Message BlockSiemens Acuson P300 FirmwareSiemens Acuson P500 FirmwareSiemens Acuson Sc2000 Firmware+517/3/201714/8/2026
The SMBv1 server in Microsoft Windows Vista SP2; Windows Server 2008 SP2 and R2 SP1; Windows 7 SP1; Windows 8.1; Windows Server 2012 Gold and R2; Windows RT 8.1; and Windows 10 Gold, 1511, and 1607; and Windows Server 2016 allows remote attackers to execute arbitrary code via crafted packets, aka "Windows SMB Remote…
Orbitaley — Vulnerabilidades