Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
2424 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.3) | 0.18% | — | Siemens Ruggedcom Rst2428p Firmware | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM RST2428P (6GK6242-6PA00) (All versions). The affected device may be susceptible to resource exhaustion when subjected to high volumes of query requests. This could allow an attacker to cause a temporary denial of service, with the system recovering once the activity… | |
| Modificada | Alta (8.7) | 0.52% | — | Siemens Simatic PCS NEOSiemens User Management Component | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC… | |
| Modificada | Alta (8.7) | 0.52% | — | Siemens Simatic PCS NEOSiemens User Management Component | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC… | |
| Modificada | Alta (8.7) | 0.48% | — | Siemens Simatic PCS NEOSiemens User Management Component | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a out-of-bounds read vulnerability in the integrated UMC… | |
| Modificada | Crítica (9.3) | 0.70% | — | Siemens Simatic PCS NEOSiemens User Management Component | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC PCS neo V4.1 (All versions), SIMATIC PCS neo V5.0 (All versions), SIMATIC PCS neo V6.0 (All versions < V6.0 SP1 Update 1), User Management Component (UMC) (All versions < V2.15.1.3). Affected products contain a stack-based buffer overflow vulnerability in the integrated… | |
| Modificada | Media (6.9) | 0.21% | — | Siemens Sinamics G220 FirmwareSiemens Sinamics S200 FirmwareSiemens Sinamics S210 Firmware | 9/9/2025 | 17/6/2026 | A vulnerability has been identified in SINAMICS G220 V6.4 (All versions < V6.4 HF2), SINAMICS S200 V6.4 (All versions < V6.4 HF7), SINAMICS S210 V6.4 (All versions < V6.4 HF2). The affected devices allow a factory reset to be executed without the required privileges due to improper privilege management as well as… | |
| Aplazada | Media (5.5) | 0.46% | — | SiemprecmsAI | 9/9/2025 | 17/6/2026 | A vulnerability was identified in SiempreCMS up to 1.3.6. This vulnerability affects unknown code of the file /docs/admin/file_upload.php. Such manipulation leads to unrestricted upload. The attack may be launched remotely. The exploit is publicly available and might be used. | |
| Aplazada | Media (5.5) | 0.33% | — | SiemprecmsAI | 9/9/2025 | 17/6/2026 | A vulnerability was determined in SiempreCMS up to 1.3.6. This affects an unknown part of the file user_search_ajax.php. This manipulation of the argument name/userName causes sql injection. The attack may be initiated remotely. The exploit has been publicly disclosed and may be utilized. | |
| Analizada | Crítica (9.8) | 2.9% | ⚠ Explotación activa💥 PoC | Linux KernelDebian LinuxSiemens Simatic CN 4100 Firmware | 5/9/2025 | 7/10/2026 | In the Linux kernel, the following vulnerability has been resolved: tls: fix handling of zero-length records on the rx_list Each recvmsg() call must process either - only contiguous DATA records (any number of them) - one non-DATA record If the next record has different type than what has already been processed we… | |
| Modificada | Alta (7.1) | 0.17% | 💥 PoC | Linux KernelDebian LinuxSiemens Simatic CN 4100 Firmware | 16/8/2025 | 30/7/2026 | In the Linux kernel, the following vulnerability has been resolved: bpf: Fix oob access in cgroup local storage Lonial reported that an out-of-bounds access in cgroup local storage can be crafted via tail calls. Given two programs each utilizing a cgroup local storage with a different value size, and one program doing… | |
| Modificada | Crítica (9.8) | 65% | 💥 Exploit | Fortinet Fortisiem | 12/8/2025 | 18/8/2026 | An improper neutralization of special elements used in an OS command ('OS Command Injection') vulnerability [CWE-78] vulnerability in Fortinet FortiSIEM 7.3.0 through 7.3.1, FortiSIEM 7.2.0 through 7.2.5, FortiSIEM 7.1.0 through 7.1.7, FortiSIEM 7.0.0 through 7.0.3, FortiSIEM 6.7.0 through 6.7.9, FortiSIEM 6.6 all… | |
| Analizada | Alta (7.5) | 0.12% | — | Siemens Sinec Traffic Analyzer | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions). The affected application uses a monitoring interface that is not operating in a strictly passive mode. This could allow an attacker to interact with the interface, leading to man-in-the-middle attacks. | |
| Aplazada | Alta (7.5) | 0.15% | — | Siemens Sinec Traffic AnalyzerAI | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application uses a Content Security Policy that allows unsafe script execution methods. This could allow an attacker to execute unauthorized scripts, potentially leading to cross-site scripting… | |
| Analizada | Alta (7) | 0.14% | — | Siemens Sinec Traffic Analyzer | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application exposes an internal service port to be accessible from outside the system. This could allow an unauthorized attacker to access the application. | |
| Analizada | Alta (8.8) | 0.13% | — | Siemens Sinec Traffic Analyzer | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate security controls to enforce isolation. This could allow an attacker to gain elevated access, potentially accessing sensitive host system resources. | |
| Analizada | Media (6.8) | 0.18% | 💥 PoC | Siemens Sinec Traffic Analyzer | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINEC Traffic Analyzer (6GK8822-1BG01-0BA0) (All versions < V3.0). The affected application runs docker containers without adequate resource and security limitations. This could allow an attacker to perform a denial-of-service (DoS) attack. | |
| Analizada | Alta (7.3) | 0.15% | — | Siemens Simcenter Femap | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002). The affected applications contains an out of bounds read vulnerability while parsing specially crafted BMP files. This could allow an attacker to execute code in the context of… | |
| Analizada | Alta (7.3) | 0.16% | — | Siemens Simcenter Femap | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in Simcenter Femap V2406 (All versions < V2406.0003), Simcenter Femap V2412 (All versions < V2412.0002). The affected applications contain an out of bounds write vulnerability when parsing a specially crafted STP file. This could allow an attacker to execute code in the context of… | |
| Aplazada | Alta (8.6) | 0.24% | — | Siemens Ruggedcom ROX Mx5000AISiemens Ruggedcom ROX Mx5000reAISiemens Ruggedcom ROX Rx1400AISiemens Ruggedcom ROX Rx1500AI+7 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in RUGGEDCOM ROX MX5000 (All versions), RUGGEDCOM ROX MX5000RE (All versions), RUGGEDCOM ROX RX1400 (All versions), RUGGEDCOM ROX RX1500 (All versions), RUGGEDCOM ROX RX1501 (All versions), RUGGEDCOM ROX RX1510 (All versions), RUGGEDCOM ROX RX1511 (All versions), RUGGEDCOM ROX… | |
| Aplazada | Alta (8.5) | 0.18% | — | Siemens Simatic S7-plcsimAISiemens Simatic Step 7AISiemens Simatic WinccAISiemens Simocode ESAI+5 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC S7-PLCSIM V17 (All versions), SIMATIC STEP 7 V17 (All versions < V17 Update 9), SIMATIC STEP 7 V18 (All versions), SIMATIC STEP 7 V19 (All versions < V19 Update 4), SIMATIC STEP 7 V20 (All versions < V20 Update 4), SIMATIC WinCC V17 (All versions < V17 Update 9), SIMATIC… | |
| Aplazada | Media (6.8) | 0.10% | — | Siemens Power Meter Sicam Q100AISiemens Power Meter Sicam Q200AI | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All… | |
| Aplazada | Media (6.8) | 0.10% | — | Siemens Sicam Q100AISiemens Sicam Q200AI | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in POWER METER SICAM Q100 (7KG9501-0AA01-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA01-2AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-0AA1) (All versions >= V2.60 < V2.62), POWER METER SICAM Q100 (7KG9501-0AA31-2AA1) (All… | |
| Analizada | Media (4.8) | 0.12% | — | Siemens Simatic Rtls Locating Manager | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.3). Affected SIMATIC RTLS Locating Manager Report Clients do not properly protect credentials that are used to authenticate to the server. This could allow an authenticated local attacker to extract the credentials and use them to… | |
| Analizada | Crítica (9.4) | 0.67% | — | Siemens Simatic Rtls Locating Manager | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SIMATIC RTLS Locating Manager (All versions < V3.2). Affected products do not properly validate input for a backup script. This could allow an authenticated remote attacker with high privileges in the application to execute arbitrary code with 'NT Authority/SYSTEM' privileges. | |
| Aplazada | Alta (8.7) | 0.24% | — | Siemens Sinumerik 828d Ppu.4AISiemens Sinumerik 828d Ppu.5AISiemens Sinumerik 840d SLAISiemens Sinumerik MCAI+1 | 12/8/2025 | 17/6/2026 | A vulnerability has been identified in SINUMERIK 828D PPU.4 (All versions < V4.95 SP5), SINUMERIK 828D PPU.5 (All versions < V5.25 SP1), SINUMERIK 840D sl (All versions < V4.95 SP5), SINUMERIK MC (All versions < V1.25 SP1), SINUMERIK MC V1.15 (All versions < V1.15 SP5), SINUMERIK ONE (All versions < V6.25 SP1),… |