Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)3.0%—Siemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source CodeSiemens Apogee Modular Building Controller Firmware+189/11/202117/6/2026
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions <…
ModificadaAlta (7.5)1.2%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+79/11/202117/6/2026
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions <…
ModificadaCrítica (9.8)1.5%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+199/11/202117/6/2026
A vulnerability has been identified in APOGEE MBC (PPC) (BACnet) (All versions), APOGEE MBC (PPC) (P2 Ethernet) (All versions), APOGEE MEC (PPC) (BACnet) (All versions), APOGEE MEC (PPC) (P2 Ethernet) (All versions), APOGEE PXC Compact (BACnet) (All versions < V3.5.4), APOGEE PXC Compact (P2 Ethernet) (All versions <…
ModificadaAlta (7.5)1.5%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+69/11/202117/6/2026
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP ACK message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions.…
ModificadaAlta (7.5)1.5%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+69/11/202117/6/2026
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). The DHCP client application does not validate the length of the Domain Name Server IP option(s) (0x06) when processing DHCP ACK packets. This may lead to…
ModificadaAlta (7.5)1.5%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+69/11/202117/6/2026
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303). When processing a DHCP OFFER message, the DHCP client application does not validate the length of the Vendor option(s), leading to Denial-of-Service conditions.…
ModificadaCrítica (9.1)2.0%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+79/11/202117/6/2026
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). The total length of an ICMP payload…
ModificadaCrítica (9.1)1.6%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Source Code+69/11/202117/6/2026
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions). The total length of an UDP payload (set in the IP header) is unchecked. This may lead to various side effects, including Information…
ModificadaMedia (6.9)1.5%—Siemens Capital VstarSiemens Nucleus NETSiemens Nucleus Readystart V3Siemens Nucleus Readystart V4+79/11/202117/6/2026
A vulnerability has been identified in Capital Embedded AR Classic 431-422 (All versions), Capital Embedded AR Classic R20-11 (All versions < V2303), PLUSCONTROL 1st Gen (All versions), SIMOTICS CONNECT 400 (All versions < V0.5.0.0), SIMOTICS CONNECT 400 (All versions < V1.0.0.0). ICMP echo packets with fake IP…
ModificadaMedia (6.5)0.57%—Tipsandtricks-hq Compact WP Audio Player18/10/202117/6/2026
The Compact WP Audio Player WordPress plugin before 1.9.7 does not implement nonce checks, which could allow attackers to make a logged in admin change the "Disable Simultaneous Play" setting via a CSRF attack.
ModificadaMedia (5.4)0.65%—Tipsandtricks-hq Compact WP Audio Player18/10/202117/6/2026
The Compact WP Audio Player WordPress plugin before 1.9.7 does not escape some of its shortcodes attributes, which could allow users with a role as low as Contributor to perform Stored Cross-Site Scripting attacks.
ModificadaCrítica (10)1.9%—Siemens Cerberus DMSSiemens Desigo CCSiemens Desigo CC Compact14/9/202117/6/2026
A vulnerability has been identified in Cerberus DMS V4.0 (All versions), Cerberus DMS V4.1 (All versions), Cerberus DMS V4.2 (All versions), Cerberus DMS V5.0 (All versions < v5.0 QU1), Desigo CC Compact V4.0 (All versions), Desigo CC Compact V4.1 (All versions), Desigo CC Compact V4.2 (All versions), Desigo CC…
ModificadaCrítica (9.8)3.4%—Siemens Apogee MBC (ppc) (P2 Ethernet) FirmwareSiemens Apogee MEC (ppc) (P2 Ethernet) FirmwareSiemens Apogee PXC Bacnet Automation Controller FirmwareSiemens Apogee PXC Compact (P2 Ethernet) Firmware+414/9/202117/6/2026
A vulnerability has been identified in APOGEE MBC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE MEC (PPC) (P2 Ethernet) (All versions >= V2.6.3), APOGEE PXC Compact (BACnet) (All versions < V3.5.3), APOGEE PXC Compact (P2 Ethernet) (All versions >= V2.8), APOGEE PXC Modular (BACnet) (All versions < V3.5.3),…
ModificadaCrítica (9.8)3.7%—Idemia Morphowave Compact Mdpi FirmwareIdemia Morphowave Compact Mdpi-m FirmwareIdemia Visionpass Mdpi FirmwareIdemia Visionpass Mdpi-m Firmware+722/7/202117/6/2026
A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2, Sigma devices before 4.9.4, and MA VP MD devices before 4.9.7 allows remote attackers to achieve code execution, denial of services, and information disclosure via TCP/IP packets.
ModificadaMedia (5.9)1.4%—Idemia Morphowave Compact Mdpi FirmwareIdemia Morphowave Compact Mdpi-m FirmwareIdemia Visionpass Mdpi FirmwareIdemia Visionpass Mdpi-m Firmware+222/7/202117/6/2026
A path traversal in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows remote authenticated attackers to achieve denial of services and information disclosure via TCP/IP packets.
ModificadaMedia (6.2)0.34%—Idemia Morphowave Compact Mdpi FirmwareIdemia Morphowave Compact Mdpi-m FirmwareIdemia Visionpass Mdpi FirmwareIdemia Visionpass Mdpi-m Firmware22/7/202117/6/2026
A Buffer Overflow in Thrift command handlers in IDEMIA Morpho Wave Compact and VisionPass devices before 2.6.2 allows physically proximate authenticated attackers to achieve code execution, denial of services, and information disclosure via serial ports.
AnalizadaAlta (7.8)100%⚠ Explotación activa💥 ExploitSudo Project SudoFedoraproject FedoraDebian LinuxNetapp Active IQ Unified Manager+2026/1/202117/6/2026
Sudo before 1.9.5p2 contains an off-by-one error that can result in a heap-based buffer overflow, which allows privilege escalation to root via "sudoedit -s" and a command-line argument that ends with a single backslash character.
ModificadaAlta (7.5)1.1%—NI Compactrio Firmware11/12/202017/6/2026
Incorrect permissions are set by default for an API entry-point of a specific service, allowing a non-authenticated user to trigger a function that could reboot the CompactRIO (Driver versions prior to 20.5) remotely.
ModificadaCrítica (9.8)6.0%—Siemens Desigo Consumption ControlSiemens Desigo Consumption Control Compact14/8/202017/6/2026
A vulnerability has been identified in Desigo CC (V4.x), Desigo CC (V3.x), Desigo CC Compact (V4.x), Desigo CC Compact (V3.x). Affected applications are delivered with a 3rd party component (BIRT) that contains a remote code execution vulnerability if the Advanced Reporting Engine is enabled. The vulnerability could…
ModificadaMedia (5.4)0.73%—Jenkins Compact Columns3/6/202017/6/2026
Jenkins Compact Columns Plugin 1.11 and earlier displays the unprocessed job description in tooltips, resulting in a stored cross-site scripting vulnerability that can be exploited by users with Job/Configure permission.
ModificadaCrítica (9.8)2.3%—ABB 800xa SystemABB Compact HMIABB Control Builder Safe29/4/202017/6/2026
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony…
ModificadaAlta (7.5)1.5%—ABB 800xa SystemABB Compact HMIABB Control Builder Safe29/4/202017/6/2026
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony…
ModificadaAlta (7.5)1.2%—ABB 800xa SystemABB Compact HMIABB Control Builder Safe29/4/202017/6/2026
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony…
ModificadaAlta (7.8)0.37%—ABB 800xa SystemABB Compact HMIABB Control Builder Safe29/4/202017/6/2026
For the Central Licensing Server component used in ABB products ABB Ability™ System 800xA and related system extensions versions 5.1, 6.0 and 6.1, Compact HMI versions 5.1 and 6.0, Control Builder Safe 1.0, 1.1 and 2.0, Symphony Plus -S+ Operations 3.0 to 3.2 Symphony Plus -S+ Engineering 1.1 to 2.2, Composer Harmony…
ModificadaAlta (7.5)1.2%—Sharp Aquos Sh-m02 FirmwareSharp Aquos Sh-rm02 FirmwareSharp Aquos Mini Sh-m03 FirmwareSharp Aquos L2 Firmware+623/4/202017/6/2026
SHARP AQUOS series (AQUOS SH-M02 build number 01.00.05 and earlier, AQUOS SH-RM02 build number 01.00.04 and earlier, AQUOS mini SH-M03 build number 01.00.04 and earlier, AQUOS Keitai SH-N01 build number 01.00.01 and earlier, AQUOS L2 (UQ mobile/J:COM) build number 01.00.05 and earlier, AQUOS sense lite SH-M05 build…