Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2687▼ 562 respecto a la semana anterior
Críticas / altas1259▼ 239 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 239 respecto a la semana anterior
–

204 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.6%—Siemens Siprotec 4Siemens Siprotec Compact10/3/202017/6/2026
A vulnerability has been identified in SIPROTEC 4 and SIPROTEC Compact relays equipped with EN100 Ethernet communication modules (All versions). Specially crafted packets sent to port 50000/UDP of the EN100 Ethernet communication modules could cause a Denial-of-Service of the affected device. A manual reboot is…
ModificadaCrítica (9.8)1.9%—Compact Arena Project Compact Arena9/9/201917/6/2026
An issue was discovered in the compact_arena crate before 0.4.0 for Rust. Generativity is mishandled, leading to an out-of-bounds write or read.
ModificadaCrítica (9.8)10.0%—Rockwellautomation Compactlogix 5370 L1 FirmwareRockwellautomation Compactlogix 5370 L2 FirmwareRockwellautomation Compactlogix 5370 L3 FirmwareRockwellautomation Armor Compact Guardlogix 5370 Firmware1/5/201917/6/2026
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recovering CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor…
ModificadaAlta (7.5)6.1%—Rockwellautomation Compactlogix 5370 L1 FirmwareRockwellautomation Compactlogix 5370 L2 FirmwareRockwellautomation Compactlogix 5370 L3 FirmwareRockwellautomation Compact Guardlogix 5370 Firmware+11/5/201917/6/2026
An attacker could send crafted SMTP packets to cause a denial-of-service condition where the controller enters a major non-recoverable faulted state (MNRF) in CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier.
ModificadaMedia (6.1)3.1%—Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Compactlogix 5370 L1 Firmware+225/4/201917/6/2026
In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix…
ModificadaAlta (7.5)1.8%—Siemens Siprotec Compact 7sj80 FirmwareSiemens Siprotec Compact 7sk80 FirmwareSiemens Siprotec 4 7sj66 FirmwareSiemens Digsi 4+58/3/201817/6/2026
A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100…
ModificadaMedia (5.3)0.58%—Siemens Siprotec Compact 7sj80 FirmwareSiemens Siprotec Compact 7sk80 FirmwareSiemens Siprotec 4 7sj66 FirmwareSiemens Digsi 4+58/3/201817/6/2026
A vulnerability has been identified in DIGSI 4 (All versions < V4.92), EN100 Ethernet module DNP3 variant (All versions < V1.05.00), EN100 Ethernet module IEC 104 variant (All versions), EN100 Ethernet module IEC 61850 variant (All versions < V4.30), EN100 Ethernet module Modbus TCP variant (All versions), EN100…
ModificadaAlta (7)1.0%—Microsoft Windows Embedded CompactMicrosoft Windows 10Microsoft Windows 7Microsoft Windows 8.1+415/2/201817/6/2026
Windows 7 SP1, Windows 8.1 and RT 8.1, Windows Server 2008 SP2 and R2 SP1, Windows Server 2012 and R2, Windows 10 Gold, 1511, 1607, 1703 and 1709, Windows Server 2016 and Windows Server, version 1709 allow an elevation of privilege vulnerability due to how objects in memory are handled, aka "Windows Kernel Elevation…
ModificadaAlta (8.7)3.3%—Siemens Simatic S7-200 FirmwareSiemens Simatic S7-400pn V6 FirmwareSiemens Simatic S7-400h V6 FirmwareSiemens Simatic S7-400pn/dp V7 Firmware+3426/12/201717/6/2026
Specially crafted packets sent to port 161/udp could cause a denial of service condition. The affected devices must be restarted manually.
ModificadaMedia (5.3)7.3%💥 PoCSiemens Apogee PXC FirmwareSiemens Apogee PXC Modular FirmwareSiemens Talon TC Compact FirmwareSiemens Talon TC Modular Firmware23/10/201717/6/2026
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system…
ModificadaAlta (7.5)25%—Siemens Apogee PXC FirmwareSiemens Apogee PXC Modular FirmwareSiemens Talon TC Compact FirmwareSiemens Talon TC Modular Firmware23/10/201717/6/2026
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.
ModificadaAlta (7.8)0.37%—Lenovo Thinkpad Compact USB Keyboard Driver10/8/201717/6/2026
An unquoted service path vulnerability was identified in the driver for the ThinkPad Compact USB Keyboard with TrackPoint versions earlier than 1.5.5.0. This could allow an attacker with local privileges to execute code with administrative privileges.
ModificadaAlta (7.8)1.1%—Sourcenext File Compact17/7/201717/6/2026
Untrusted search path vulnerability in self-extracting archive files created by File Compact Ver.5 version 5.10 and earlier, Ver.6 version 6.02 and earlier, Ver.7 version 7.02 and earlier allows an attacker to gain privileges via a Trojan horse DLL in an unspecified directory.
ModificadaMedia (5.9)2.6%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Controllogix 5580 Firmware6/5/201717/6/2026
A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogix 5380 controllers V29.011. This vulnerability may allow an attacker to cause a denial of service…
ModificadaCrítica (10)10%—Rockwellautomation Softlogix 5800 Controller FirmwareRockwellautomation Rslogix Emulate 5000 FirmwareRockwellautomation Guardlogix 5570 Controller FirmwareRockwellautomation Flexlogix L34 Controller Firmware+1213/2/201717/6/2026
An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able to overflow a stack-based buffer and…
ModificadaMedia (6.1)7.6%💥 ExploitRockwellautomation Compactlogix 1769-l16er-bb1b FirmwareRockwellautomation Compactlogix 1769-l18er-bb1b FirmwareRockwellautomation Compactlogix 1769-l18erm-bb1b FirmwareRockwellautomation Compactlogix 1769-l24er-qb1b Firmware+192/3/201617/6/2026
Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)36%—Rockwellautomation Ethernet/ip FirmwareRockwellautomation Compactlogix FirmwareRockwellautomation Flexlogix FirmwareRockwellautomation Flex I/O Ethernet/ip Firmware+824/1/201316/6/2026
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected…
ModificadaMedia (5)57%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confidentiality. Rockwell Automation EtherNet/IP products; 1756-ENBT,…
ModificadaMedia (4.8)9.3%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics information. Rockwell Automation EtherNet/IP…
ModificadaAlta (8.5)23%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network parameters, a DoS condition can occur. This situation could cause loss of availability and a disruption…
ModificadaAlta (7.5)27%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successful exploitation of this vulnerability could cause loss of…
ModificadaCrítica (9.8)7.8%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a…
ModificadaAlta (7.5)27%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the CPU to crash. Successful exploitation of this vulnerability could cause loss of…
ModificadaAlta (7.5)33%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability and a disruption of…
ModificadaMedia (4.3)1.5%—Rocomotion P BoardRocomotion P Diary RRocomotion P ForumRocomotion P Link+620/1/201116/6/2026
Cross-site scripting (XSS) vulnerability in multiple Rocomotion products, including P board 1.18 and other versions, P forum 1.30 and earlier, P up board 1.38 and other versions, P diary R 1.13 and earlier, P link 1.11 and earlier, P link compact 1.04 and earlier, pplog 3.31 and earlier, pplog2 3.37 and earlier, PM…
Orbitaley — Vulnerabilidades