Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
375 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted setting value messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170) | |
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time reduced data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.8) | 1.3% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to… | |
| Modificada | Crítica (9.8) | 1.1% | — | Schneider-electric Interactive Graphical Scada System | 30/1/2023 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe… | |
| Modificada | Media (5.4) | 0.57% | — | Rushstreetinteractive Rushbet | 18/1/2023 | 17/6/2026 | RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives. | |
| Modificada | Media (5.4) | 0.47% | — | Vision Interactive Project Vision Interactive | 9/1/2023 | 17/6/2026 | The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Crítica (9.8) | 2.0% | — | Pypi Rootinteractive | 24/6/2022 | 17/6/2026 | The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges. | |
| Modificada | Media (5.4) | 0.49% | — | Oracle Peoplesoft Enterprise Prtl Interaction HUB | 19/4/2022 | 17/6/2026 | Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: My Links). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub.… | |
| Modificada | Media (4.8) | 0.60% | — | Humananatomyillustrations Interactive Medical Drawing OF Human Body | 28/3/2022 | 17/6/2026 | The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed. | |
| Modificada | Media (4.8) | 0.62% | — | Unboxinteractive Petfinder-listings | 14/3/2022 | 17/6/2026 | The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Media (4.8) | 0.62% | — | Chrsinteractive Simple Tracking | 14/3/2022 | 17/6/2026 | The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed | |
| Modificada | Alta (7.5) | 14% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior) | |
| Modificada | Crítica (9.1) | 21% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior) | |
| Modificada | Crítica (9.1) | 0.85% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior) | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product: Interactive Graphical SCADA System Data… | |
| Modificada | Crítica (9.8) | 1.9% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network. Affected Product: Interactive Graphical… | |
| Modificada | Crítica (9.8) | 20% | — | Schneider-electric Interactive Graphical Scada System Data Collector | 11/2/2022 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and… | |
| Modificada | Alta (7.5) | 1.2% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Alta (7.5) | 19% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Alta (7.5) | 18% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Crítica (9.8) | 45% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior) | |
| Modificada | Crítica (9.8) | 3.5% | — | Schneider-electric Interactive Graphical Scada System Data Server | 9/2/2022 | 17/6/2026 | A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leading to remote code execution when an attacker sends a specially crafted message.… |