Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

375 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm cache data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to…
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted setting value messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to…
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted alarm data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to V15.0.0.22170)
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted time reduced data messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to…
ModificadaCrítica (9.8)1.3%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted online data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe (Versions prior to…
ModificadaCrítica (9.8)1.1%—Schneider-electric Interactive Graphical Scada System30/1/202317/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow, potentially leading to remote code execution when an attacker sends specially crafted mathematically reduced data request messages. Affected Products: IGSS Data Server - IGSSdataServer.exe…
ModificadaMedia (5.4)0.57%—Rushstreetinteractive Rushbet18/1/202317/6/2026
RushBet version 2022.23.1-b490616d allows a remote attacker to steal customer accounts via use of a malicious application. This is possible because the application exposes an activity and does not properly validate the data it receives.
ModificadaMedia (5.4)0.47%—Vision Interactive Project Vision Interactive9/1/202317/6/2026
The Vision Interactive For WordPress plugin through 1.5.3 does not sanitise and escape some of its settings, which could allow users such as contributor+ to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaCrítica (9.8)2.0%—Pypi Rootinteractive24/6/202217/6/2026
The RootInteractive package in PyPI v0.0.5 to v0.0.19b0 was discovered to contain a code execution backdoor via the request package. This vulnerability allows attackers to access sensitive user information and digital currency keys, as well as escalate privileges.
ModificadaMedia (5.4)0.49%—Oracle Peoplesoft Enterprise Prtl Interaction HUB19/4/202217/6/2026
Vulnerability in the PeopleSoft Enterprise PRTL Interaction Hub product of Oracle PeopleSoft (component: My Links). The supported version that is affected is 9.1. Easily exploitable vulnerability allows low privileged attacker with network access via HTTP to compromise PeopleSoft Enterprise PRTL Interaction Hub.…
ModificadaMedia (4.8)0.60%—Humananatomyillustrations Interactive Medical Drawing OF Human Body28/3/202217/6/2026
The Interactive Medical Drawing of Human Body WordPress plugin before 2.6 does not sanitise and escape the Link field, allowing high privilege users to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed.
ModificadaMedia (4.8)0.62%—Unboxinteractive Petfinder-listings14/3/202217/6/2026
The Petfinder Listings WordPress plugin through 1.0.18 does not escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaMedia (4.8)0.62%—Chrsinteractive Simple Tracking14/3/202217/6/2026
The Simple Tracking WordPress plugin before 1.7 does not sanitise and escape its settings, allowing high privilege users such as admin to perform Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed
ModificadaAlta (7.5)14%—Schneider-electric Interactive Graphical Scada System Data Collector11/2/202217/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in denial of service, due to missing length check on user-supplied data from a constructed message received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)
ModificadaCrítica (9.1)21%—Schneider-electric Interactive Graphical Scada System Data Collector11/2/202217/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21320 and prior)
ModificadaCrítica (9.1)0.85%—Schneider-electric Interactive Graphical Scada System Data Collector11/2/202217/6/2026
A CWE-306: Missing Authentication for Critical Function vulnerability exists that could cause deletion of arbitrary files in the context of the user running IGSS due to lack of validation of network messages. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and prior)
ModificadaAlta (7.5)1.3%—Schneider-electric Interactive Graphical Scada System Data Collector11/2/202217/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause disclosure of arbitrary files being read in the context of the user running IGSS, due to missing validation of user supplied data in network messages. Affected Product: Interactive Graphical SCADA System Data…
ModificadaCrítica (9.8)1.9%—Schneider-electric Interactive Graphical Scada System Data Collector11/2/202217/6/2026
A CWE-434: Unrestricted Upload of File with Dangerous Type vulnerability exists that could lead to remote code execution through a number of paths, when an attacker, writes arbitrary files to folders in context of the DC module, by sending constructed messages on the network. Affected Product: Interactive Graphical…
ModificadaCrítica (9.8)20%—Schneider-electric Interactive Graphical Scada System Data Collector11/2/202217/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could result in remote code execution due to missing length check on user supplied data, when a constructed message is received on the network. Affected Product: Interactive Graphical SCADA System Data Collector (dc.exe) (V15.0.0.21243 and…
ModificadaAlta (7.5)1.2%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-862: Missing Authorization vulnerability exists that could cause information exposure when an attacker sends a specific message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
ModificadaAlta (7.5)1.3%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-665: Improper Initialization vulnerability exists that could cause information exposure when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
ModificadaAlta (7.5)19%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-125: Out-of-bounds Read vulnerability exists that could cause denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
ModificadaAlta (7.5)18%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-125: Out-of-bounds Read vulnerability exists that could cause memory leaks potentially resulting in denial of service when an attacker repeatedly sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
ModificadaCrítica (9.8)45%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-120: Buffer Copy without Checking Size of Input vulnerability exists that could cause a stack-based buffer overflow potentially leading to remote code execution when an attacker sends a specially crafted message. Affected Product: Interactive Graphical SCADA System Data Server (V15.0.0.22020 and prior)
ModificadaCrítica (9.8)3.5%—Schneider-electric Interactive Graphical Scada System Data Server9/2/202217/6/2026
A CWE-22: Improper Limitation of a Pathname to a Restricted Directory vulnerability exists that could cause modification of an existing file by adding at end of file or create a new file in the context of the Data Server potentially leading to remote code execution when an attacker sends a specially crafted message.…