Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.64% | — | Hitachienergy Microscada X Sys600 | 12/9/2022 | 17/6/2026 | Improper Authorization vulnerability exists in the Workplace X WebUI of the Hitachi Energy MicroSCADA X SYS600 allows an authenticated user to execute any MicroSCADA internal scripts irrespective of the authenticated user's role. This issue affects: Hitachi Energy MicroSCADA X SYS600 version 10 to version 10.3.1.… | |
| Modificada | Media (5.5) | 0.23% | — | Measuresoft Scadapro ClientMeasuresoft Scadapro Server | 31/8/2022 | 17/6/2026 | Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow a denial-of-service condition. | |
| Modificada | Alta (7.8) | 0.30% | — | Measuresoft Scadapro ClientMeasuresoft Scadapro Server | 31/8/2022 | 17/6/2026 | Measuresoft ScadaPro Server and Client (All Versions) do not properly resolve links before file access; this could allow privilege escalation.. | |
| Modificada | Alta (7.8) | 0.32% | — | Measuresoft Scadapro Server | 31/8/2022 | 17/6/2026 | Measuresoft ScadaPro Server (All Versions) allows use after free while processing a specific project file. | |
| Modificada | Alta (7.8) | 0.31% | — | Measuresoft Scadapro Server | 31/8/2022 | 17/6/2026 | Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. These controls may allow two stack-based buffer overflow instances while processing a specific project file. | |
| Modificada | Alta (7.8) | 0.30% | — | Measuresoft Scadapro Server | 31/8/2022 | 17/6/2026 | Measuresoft ScadaPro Server (All Versions) uses unmaintained ActiveX controls. The controls may allow seven untrusted pointer deference instances while processing a specific project file. | |
| Modificada | Alta (7.8) | 0.31% | — | Measuresoft Scadapro Server | 31/8/2022 | 17/6/2026 | Measuresoft ScadaPro Server (Versions prior to 6.8.0.1) uses an unmaintained ActiveX control, which may allow an out-of-bounds write condition while processing a specific project file. | |
| Modificada | Alta (8.8) | 42% | — | Myscada Mypro | 24/8/2022 | 17/6/2026 | An authenticated mySCADA myPRO 8.26.0 user may be able to modify parameters to run commands directly in the operating system. | |
| Modificada | Alta (7.8) | 0.44% | — | Schneider-electric GEO Scada Mobile | 24/6/2022 | 17/6/2026 | A CWE-668 Exposure of Resource to Wrong Sphere vulnerability exists that could cause users to be misled, hiding alarms, showing the wrong server connection option or the wrong control request when a mobile device has been compromised by a malicious application. Affected Product: Geo SCADA Mobile (Build 222 and prior) | |
| Modificada | Media (6.1) | 2.5% | — | Lcds Laquis Scada | 25/5/2022 | 17/6/2026 | When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting. | |
| Modificada | Crítica (9.9) | 0.97% | — | Aveva Intouch Access AnywhereAveva Plant Scada Access Anywhere | 23/5/2022 | 17/6/2026 | Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS… | |
| Modificada | Media (6.5) | 0.10% | — | Emerson Openenterprise Scada Server | 19/5/2022 | 17/6/2026 | Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained. | |
| Modificada | Alta (7.5) | 0.86% | — | Myscada Mypro | 13/5/2022 | 17/6/2026 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive system information. | |
| Modificada | Alta (7.5) | 1.3% | — | Myscada Mypro | 13/5/2022 | 17/6/2026 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to the file system. | |
| Modificada | Alta (7.5) | 1.6% | — | Myscada Mypro | 13/5/2022 | 17/6/2026 | mySCADA myPRO versions prior to 8.20.0 allows an unauthenticated remote attacker to upload arbitrary files to arbitrary directories. | |
| Modificada | Alta (7.5) | 1.1% | — | Myscada Mypro | 13/5/2022 | 17/6/2026 | mySCADA myPRO versions prior to 8.20.0 does not restrict unauthorized read access to sensitive directory listing information. | |
| Modificada | Crítica (9.8) | 1.1% | — | Smartptt Scada Server | 29/4/2022 | 17/6/2026 | Elcomplus SmartPTT SCADA Server is vulnerable to an unauthenticated user can request various files from the server without any authentication or authorization. | |
| Modificada | Alta (8.8) | 0.37% | — | Smartptt Scada Server | 29/4/2022 | 17/6/2026 | Elcomplus SmartPTT SCADA Server web application does not, or cannot, sufficiently verify whether a well-formed, valid, consistent request was intentionally provided by the user who submitted the request. | |
| Modificada | Alta (8.8) | 0.64% | — | Smartptt Scada | 28/4/2022 | 17/6/2026 | Elcomplus SmartPTT is vulnerable when a low-authenticated user can access higher level administration authorization by issuing requests directly to the desired endpoints. | |
| Modificada | Crítica (9.8) | 1.2% | — | Smartptt Scada | 28/4/2022 | 17/6/2026 | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate upload requests, enabling a malicious user to potentially upload arbitrary files. | |
| Modificada | Media (6.1) | 0.65% | — | Smartptt Scada | 28/4/2022 | 17/6/2026 | Elcomplus SmartPTT is vulnerable when an attacker injects JavaScript code into a specific parameter that can executed upon accessing the dashboard or the main page. | |
| Modificada | Media (4.9) | 1.0% | — | Smartptt Scada | 28/4/2022 | 17/6/2026 | Elcomplus SmartPTT is vulnerable as the backup and restore system does not adequately validate download requests, enabling malicious users to perform path traversal attacks and potentially download arbitrary files from the system. | |
| Modificada | Media (5.5) | 0.96% | — | Schneider-electric Scadapack Workbench | 13/4/2022 | 17/6/2026 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could result in information disclosure when opening a malicious solution file provided by an attacker with SCADAPack Workbench. This could be exploited to pass data from local files to a remote system controlled by an attacker.… | |
| Modificada | Alta (7.5) | 1.1% | — | Fernhillsoftware Scada Server | 12/4/2022 | 17/6/2026 | A specially crafted packet sent to the Fernhill SCADA Server Version 3.77 and earlier may cause an exception, causing the server process (FHSvrService.exe) to exit. | |
| Modificada | Alta (8.8) | 1.4% | — | Myscada Mypro | 11/4/2022 | 17/6/2026 | An authenticated user may be able to misuse parameters to inject arbitrary operating system commands into mySCADA myPRO versions 8.25.0 and prior. |