Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5) | 2.1% | — | 3s-smart Software Solutions Codesys Gateway Server | 25/10/2015 | 17/6/2026 | 3S-Smart CODESYS Gateway Server before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and daemon crash) via a crafted (1) GET or (2) POST request. | |
| Modificada | Media (5) | 2.1% | — | 3s-software Codesys Runtime System | 18/10/2015 | 17/6/2026 | Runtime Toolkit before 2.4.7.48 in 3S-Smart CODESYS before 2.3.9.48 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via a crafted request. | |
| Modificada | Alta (7.5) | 6.2% | — | 3s-smart Codesys Gateway Server | 18/9/2015 | 17/6/2026 | Multiple heap-based buffer overflows in 3S-Smart CODESYS Gateway Server before 2.3.9.34 allow remote attackers to execute arbitrary code via opcode (1) 0x3ef or (2) 0x3f0. | |
| Modificada | Alta (9.3) | 2.3% | — | Softmotion3d SoftmotionFesto Cecx-x-m1 Modular Controller3s-software Codesys Runtime SystemFesto Cecx-x-c1 Modular Master Controller | 25/4/2014 | 17/6/2026 | The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion do not require authentication for connections to certain TCP ports, which allows remote attackers to (1) modify the configuration via a request to the debug service on port 4000 or (2) delete log… | |
| Modificada | Alta (9.3) | 3.3% | — | 3s-software Codesys Runtime SystemFesto Cecx-x-c1 Modular Master ControllerSoftmotion3d SoftmotionFesto Cecx-x-m1 Modular Controller | 25/4/2014 | 17/6/2026 | The Festo CECX-X-C1 Modular Master Controller with CoDeSys and CECX-X-M1 Modular Controller with CoDeSys and SoftMotion provide an undocumented access method involving the FTP protocol, which could allow a remote attacker to execute arbitrary code or cause a denial of service (application crash) via unspecified… | |
| Modificada | Media (5) | 3.6% | — | 3s-software Codesys Runtime Toolkit | 31/1/2014 | 17/6/2026 | Smart Software Solutions (3S) CoDeSys Runtime Toolkit before 2.4.7.44 allows remote attackers to cause a denial of service (NULL pointer dereference and application crash) via unspecified vectors. | |
| Modificada | Alta (10) | 3.8% | — | 3s-software Codesys Gateway-server | 23/5/2013 | 16/6/2026 | Use-after-free vulnerability in the server application in 3S CODESYS Gateway 2.3.9.27 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (10) | 7.4% | — | 3s-software Codesys Gateway-server | 24/2/2013 | 16/6/2026 | Stack-based buffer overflow in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Alta (10) | 3.6% | — | 3s-software Codesys Gateway-server | 24/2/2013 | 16/6/2026 | 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors that trigger an out-of-bounds memory access. | |
| Modificada | Alta (7.8) | 1.6% | — | 3s-software Codesys Gateway-server | 24/2/2013 | 16/6/2026 | Integer signedness error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to cause a denial of service via a crafted packet that triggers a heap-based buffer overflow. | |
| Modificada | Alta (10) | 65% | 💥 Exploit | 3s-software Codesys Gateway-server | 24/2/2013 | 16/6/2026 | Directory traversal vulnerability in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via vectors involving a crafted pathname. | |
| Modificada | Alta (10) | 4.2% | — | 3s-software Codesys Gateway-server | 24/2/2013 | 16/6/2026 | Array index error in 3S CODESYS Gateway-Server before 2.3.9.27 allows remote attackers to execute arbitrary code via a crafted packet. | |
| Modificada | Crítica (10) | 2.6% | — | 3s-software Codesys Runtime System | 21/1/2013 | 16/6/2026 | The CoDeSys Runtime Toolkit’s file transfer functionality does not perform input validation, which allows an attacker to access files and directories outside the intended scope. This may allow an attacker to upload and download any file on the device. This could allow the attacker to affect the availability,… | |
| Modificada | Crítica (9.8) | 5.3% | — | 3s-software Codesys Runtime System | 21/1/2013 | 16/6/2026 | The Runtime Toolkit in CODESYS Runtime System 2.3.x and 2.4.x does not require authentication, which allows remote attackers to execute commands via the command-line interface in the TCP listener service or transfer files via requests to the TCP listener service. | |
| Modificada | Media (6.4) | 1.8% | — | 3ssoftware Codesys | 10/1/2012 | 16/6/2026 | The CmbWebserver.dll module of the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to create arbitrary directories under the web root by specifying a non-existent directory using \ (backslash) characters in an HTTP GET request. | |
| Modificada | Media (5) | 10% | 💥 Exploit | 3ssoftware Codesys | 25/12/2011 | 16/6/2026 | The CmpWebServer.dll module in the Control service in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to cause a denial of service (NULL pointer dereference) via (1) a crafted Content-Length in an HTTP POST or (2) an invalid HTTP request method. | |
| Modificada | Alta (7.5) | 5.0% | — | 3ssoftware Codesys | 25/12/2011 | 16/6/2026 | Integer overflow in the GatewayService component in 3S CoDeSys 3.4 SP4 Patch 2 allows remote attackers to execute arbitrary code via a large size value in the packet header, which triggers a heap-based buffer overflow. | |
| Modificada | Alta (10) | 73% | 💥 Exploit | 3ssoftware Codesys | 25/12/2011 | 16/6/2026 | Stack-based buffer overflow in the CmpWebServer component in 3S CoDeSys 3.4 SP4 Patch 2 and earlier, as used on the ABB AC500 PLC and possibly other products, allows remote attackers to execute arbitrary code via a long URI to TCP port 8080. |