Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2726▼ 504 respecto a la semana anterior
Críticas / altas1294▼ 196 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)229▼ 273 respecto a la semana anterior
–

229 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.68%—Phoenix Media Rename Project Phoenix Media Rename8/11/202117/6/2026
The Phoenix Media Rename WordPress plugin before 3.4.4 does not have capability checks in its phoenix_media_rename AJAX action, which could allow users with Author roles to rename any uploaded media files, including ones they do not own.
ModificadaAlta (7.8)0.65%—Phoenixcontact PC WorxPhoenixcontact PC Worx Express4/11/202117/6/2026
Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory.
ModificadaAlta (7.5)0.98%—Phoenixcontact Plcnext Technology Starterkit FirmwarePhoenixcontact AXC F 2152 Starterkit FirmwarePhoenixcontact RFC 4072s FirmwarePhoenixcontact AXC F 3152 Firmware+227/9/202117/6/2026
Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.
ModificadaAlta (7)1.8%—Phoenixcontact Config+Phoenixcontact PC WorxPhoenixcontact PC Worx Express25/6/202117/6/2026
Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get…
ModificadaAlta (7.5)1.5%—Phoenixcontact Ilc1x0 FirmwarePhoenixcontact Ilc1x1 Firmware25/6/202117/6/2026
Phoenix Contact Classic Line Controllers ILC1x0 and ILC1x1 in all versions/variants are affected by a Denial-of-Service vulnerability. The communication protocols and device access do not feature authentication measures. Remote attackers can use specially crafted IP packets to cause a denial of service on the PLC's…
ModificadaAlta (7.3)0.72%—Phoenixcontact AXL F BK PN TPS XC FirmwarePhoenixcontact AXL F BK PN TPS FirmwarePhoenixcontact AXL F BK EIP FirmwarePhoenixcontact AXL F BK EIP EF Firmware+1425/6/202117/6/2026
In certain devices of the Phoenix Contact AXL F BK and IL BK product families an undocumented password protected FTP access to the root directory exists.
ModificadaAlta (7.5)0.68%—Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+1125/6/202117/6/2026
In Phoenix Contact FL SWITCH SMCS series products in multiple versions if an attacker sends a hand-crafted TCP-Packet with the Urgent-Flag set and the Urgent-Pointer set to 0, the network stack will crash. The device needs to be rebooted afterwards.
ModificadaMedia (6.1)0.58%—Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+1125/6/202117/6/2026
In Phoenix Contact FL SWITCH SMCS series products in multiple versions an attacker may insert malicious code via LLDP frames into the web-based management which could then be executed by the client.
ModificadaMedia (5.3)0.95%—Phoenixcontact FL Switch Smcs 16tx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx FirmwarePhoenixcontact FL Switch Smcs 14tx/2fx-sm FirmwarePhoenixcontact FL Switch Smcs 8GT Firmware+1125/6/202117/6/2026
In Phoenix Contact FL SWITCH SMCS series products in multiple versions fragmented TCP-Packets may cause a Denial of Service of Web-, SNMP- and ICMP-Echo services. The switching functionality of the device is not affected.
ModificadaAlta (7.5)0.96%—Phoenixcontact FL Comserver UNI 232/422/485 FirmwarePhoenixcontact FL Comserver UNI 232/422/485-t Firmware25/6/202117/6/2026
In Phoenix Contact FL COMSERVER UNI in versions < 2.40 a invalid Modbus exception response can lead to a temporary denial of service.
ModificadaCrítica (9.1)0.90%—Phoenixcontact TC Mguard Rs4000 4G VZW VPN FirmwarePhoenixcontact TC Mguard Rs4000 4G ATT VPN FirmwarePhoenixcontact FL Mguard Rs4004 Tx/dtx FirmwarePhoenixcontact FL Mguard Rs4004 Tx/dtx VPN Firmware+517/12/202017/6/2026
On Phoenix Contact mGuard Devices versions before 8.8.3 LAN ports get functional after reboot even if they are disabled in the device configuration. For mGuard devices with integrated switch on the LAN side, single switch ports can be disabled by device configuration. After a reboot these ports get functional…
ModificadaMedia (6.5)0.46%—Phoenixcontact Plcnext Firmware17/12/202017/6/2026
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS a specially crafted LLDP packet may lead to a high system load in the PROFINET stack. An attacker can cause failure of system services or a complete reboot.
ModificadaCrítica (9.8)0.86%—Phoenixcontact Plcnext Firmware17/12/202017/6/2026
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use this vulnerability i.e. to open a reverse shell with root privileges.
ModificadaMedia (5.5)0.75%—Phoenixcontact Plcnext Firmware17/12/202017/6/2026
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an attacker can use the knowledge gained by reading the insufficiently protected sensitive information to plan further attacks.
ModificadaCrítica (9)1.1%—Phoenixcontact Plcnext Firmware17/12/202017/6/2026
On Phoenix Contact PLCnext Control Devices versions before 2021.0 LTS an authenticated low privileged user could embed malicious Javascript code to gain admin rights when the admin user visits the vulnerable website (local privilege escalation).
ModificadaAlta (7.5)1.1%—Phoenixcontact BTP 2043w FirmwarePhoenixcontact BTP 2070w FirmwarePhoenixcontact BTP 2102w Firmware2/12/202017/6/2026
Uncontrolled Resource Consumption can be exploited to cause the Phoenix Contact HMIs BTP 2043W, BTP 2070W and BTP 2102W in all versions to become unresponsive and not accurately update the display content (Denial of Service).
ModificadaMedia (6.1)0.96%—Oscommerce CE Phoenix3/9/202017/6/2026
Several XSS vulnerabilities in osCommerce CE Phoenix before 1.0.6.0 allow an attacker to inject and execute arbitrary JavaScript code. The malicious code can be injected as follows: the page parameter to catalog/admin/order_status.php, catalog/admin/tax_rates.php, catalog/admin/languages.php,…
ModificadaAlta (7.3)0.40%—Phoenixcontact Plcnext Engineer21/7/202017/6/2026
In PHOENIX CONTACT PLCnext Engineer version 2020.3.1 and earlier an improper path sanitation vulnerability exists on import of project files.
ModificadaAlta (7.8)2.1%—Phoenixcontact PC WorxPhoenixcontact PC Worx Express1/7/202017/6/2026
mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.
ModificadaAlta (7.8)15%—Phoenixcontact PC WorxPhoenixcontact PC Worx Express1/7/202017/6/2026
PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation.
ModificadaAlta (7.5)0.45%—Baxter Phoenix X36 Firmware29/6/202017/6/2026
Phoenix Hemodialysis Delivery System SW 3.36 and 3.40, The Phoenix Hemodialysis device does not support data-in-transit encryption (e.g., TLS/SSL) when transmitting treatment and prescription data on the network between the Phoenix system and the Exalis dialysis data management tool. An attacker with access to the…
ModificadaAlta (7.8)0.30%—Phoenixcontact Portico Server 1 ClientPhoenixcontact Portico Server 16 ClientPhoenixcontact Portico Server 4 Client27/3/202017/6/2026
Local Privilege Escalation can occur in PHOENIX CONTACT PORTICO SERVER through 3.0.7 when installed to run as a service.
ModificadaAlta (7.8)0.30%—Phoenixcontact PC Worx SRT27/3/202017/6/2026
Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation.
ModificadaAlta (8.8)2.6%—Phoenixcontact TC Router 3002t-4g FirmwarePhoenixcontact TC Router 2002t-3g FirmwarePhoenixcontact TC Router 3002t-4g VZW FirmwarePhoenixcontact TC Router 3002t-4g ATT Firmware+212/3/202017/6/2026
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices allow authenticated users to inject system commands through…
ModificadaAlta (7.5)1.2%—Phoenixcontact TC Router 3002t-4g FirmwarePhoenixcontact TC Router 2002t-3g FirmwarePhoenixcontact TC Router 3002t-4g VZW FirmwarePhoenixcontact TC Router 3002t-4g ATT Firmware+212/3/202017/6/2026
PHOENIX CONTACT TC ROUTER 3002T-4G through 2.05.3, TC ROUTER 2002T-3G through 2.05.3, TC ROUTER 3002T-4G VZW through 2.05.3, TC ROUTER 3002T-4G ATT through 2.05.3, TC CLOUD CLIENT 1002-4G through 2.03.17, and TC CLOUD CLIENT 1002-TXTX through 1.03.17 devices contain a hardcoded certificate (and key) that is used by…
Orbitaley — Vulnerabilidades