Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 449 respecto a la semana anterior
Críticas / altas1325▼ 128 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 240 respecto a la semana anterior
197 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.64% | — | Schneider-electric Modicom M340 FirmwareSchneider-electric Modicom Premium FirmwareSchneider-electric Modicom Quantum FirmwareSchneider-electric Modicom Bmxnor0200h Firmware | 30/11/2018 | 17/6/2026 | An Improper Neutralization of Script-Related HTML Tags in a Web Page (Basic XSS) vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to send a specially crafted URL to a currently authenticated web server user to execute a password change on… | |
| Modificada | Alta (7.5) | 2.4% | — | Schneider-electric Modicom M340 FirmwareSchneider-electric Modicom Premium FirmwareSchneider-electric Modicom Quantum FirmwareSchneider-electric Modicom Bmxnor0200h Firmware | 30/11/2018 | 17/6/2026 | Improper Neutralization of CRLF Sequences in HTTP Headers ('HTTP Response Splitting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 where a denial of service can occur for ~1 minute by sending a specially crafted HTTP request. | |
| Modificada | Crítica (9.8) | 3.5% | — | Schneider-electric Modicom M340 FirmwareSchneider-electric Modicom Premium FirmwareSchneider-electric Modicom Quantum FirmwareSchneider-electric Modicom Bmxnor0200h Firmware | 30/11/2018 | 17/6/2026 | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the change password function of the web server | |
| Modificada | Media (6.1) | 0.90% | — | Schneider-electric Modicom M340 FirmwareSchneider-electric Modicom Premium FirmwareSchneider-electric Modicom Quantum FirmwareSchneider-electric Modicom Bmxnor0200h Firmware | 30/11/2018 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 allowing an attacker to craft a URL containing JavaScript that will be executed within the user's browser, potentially… | |
| Modificada | Crítica (9.8) | 2.5% | — | Schneider-electric Modicom M340 FirmwareSchneider-electric Modicom Premium FirmwareSchneider-electric Modicom Quantum FirmwareSchneider-electric Modicom Bmxnor0200h Firmware | 30/11/2018 | 17/6/2026 | An Unverified Password Change vulnerability exists in the embedded web servers in all Modicon M340, Premium, Quantum PLCs and BMXNOR0200 which could allow an unauthenticated remote user to access the password delete function of the web server. | |
| Modificada | Alta (7.5) | 13% | 💥 Exploit | Lutron Quantum Bacnet Integration Firmware | 23/4/2018 | 17/6/2026 | Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) doesn't check for correct user authentication before showing the /deviceIP information, which leads to internal network information disclosure. | |
| Modificada | Alta (7.5) | 1.4% | — | Lutron Quantum Bacnet Integration Firmware | 21/2/2018 | 17/6/2026 | An issue was discovered on Lutron Quantum BACnet Integration 2.0 (firmware 3.2.243) devices. Remote attackers can obtain potentially sensitive information via a /DbXmlInfo.xml request, as demonstrated by the Latitude/Longitude of the device. | |
| Modificada | Alta (9) | 3.0% | — | Dell Powervault Ml6000 FirmwareDell Powervault Ml6000Quantum Scalar I500 FirmwareQuantum Scalar I500 | 2/6/2014 | 17/6/2026 | logViewer.htm on the Dell ML6000 tape backup system with firmware before i8.2.0.2 (641G.GS103) and the Quantum Scalar i500 tape backup system with firmware before i8.2.2.1 (646G.GS002) allows remote attackers to execute arbitrary commands via shell metacharacters in a pathname parameter. | |
| Modificada | Alta (8.5) | 3.9% | — | Schneider-electric Modicon Quantum PLCSchneider-electric Modicon M340Schneider-electric Modicon Premium | 4/4/2013 | 16/6/2026 | The FactoryCast service on the Schneider Electric Quantum 140NOE77111 and 140NWM10000, M340 BMXNOE0110x, and Premium TSXETY5103 PLC modules allows remote authenticated users to send Modbus messages, and consequently execute arbitrary code, by embedding these messages in SOAP HTTP POST requests. | |
| Modificada | Media (6.8) | 6.0% | 💥 Exploit | Schneider-electric Modicon Quantum PLCSchneider-electric Modicon M340Schneider-electric Modicon Premium | 4/4/2013 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability on the Schneider Electric Quantum 140NOE77111, 140NOE77101, and 140NWM10000; M340 BMXNOC0401, BMXNOE0100x, and BMXNOE011xx; and Premium TSXETY4103, TSXETY5103, and TSXWMY100 PLC modules allows remote attackers to hijack the authentication of arbitrary users for requests… | |
| Modificada | Alta (7.5) | 3.5% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+5 | 22/3/2012 | 16/6/2026 | The Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100) and the IBM TS3310 tape library with firmware before R6C (606G.GS001), uses default passwords for unspecified user accounts, which makes it easier… | |
| Modificada | Media (6) | 1.0% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+3 | 22/3/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in saveRestore.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to hijack the authentication of users for requests… | |
| Modificada | Baja (3.5) | 1.2% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+3 | 22/3/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in checkQKMProg.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to inject arbitrary web script or HTML via unspecified… | |
| Modificada | Media (5) | 2.1% | — | Quantum Scalar I500 FirmwareQuantum Scalar I500Dell Powervault Ml6000 FirmwareDell Powervault Ml6000+3 | 22/3/2012 | 16/6/2026 | Absolute path traversal vulnerability in logShow.htm on the Quantum Scalar i500 tape library with firmware before i7.0.3 (604G.GS00100), also distributed as the Dell ML6000 tape library with firmware before A20-00 (590G.GS00100), allows remote attackers to read arbitrary files via a full pathname in the file parameter. | |
| Modificada | Crítica (9.8) | 4.8% | — | Schneider-electric Modicon Quantum PLC | 28/1/2012 | 16/6/2026 | Schneider Electric Modicon Quantum PLC does not perform authentication between the Unity software and PLC, which allows remote attackers to cause a denial of service or possibly execute arbitrary code via unspecified vectors. | |
| Modificada | Media (6.1) | 2.1% | — | Schneider-electric Modicon Quantum PLC | 28/1/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Schneider Electric Modicon Quantum PLC allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 4.8% | — | Schneider-electric Modicon Quantum PLC | 28/1/2012 | 16/6/2026 | Multiple buffer overflows in Schneider Electric Modicon Quantum PLC allow remote attackers to cause a denial of service via malformed requests to the (1) FTP server or (2) HTTP server. | |
| Modificada | Alta (10) | 3.0% | — | Schneider-electric Quantum Ethernet Module 140noe77100Schneider-electric Quantum Ethernet Module 140noe77101Schneider-electric Quantum Ethernet Module 140noe77111 | 17/12/2011 | 16/6/2026 | The modbus_125_handler function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) allows remote attackers to install arbitrary firmware updates via a MODBUS 125 function code to TCP port 502. | |
| Modificada | Alta (10) | 2.6% | — | Schneider-electric Quantum Ethernet Module 140noe77100Schneider-electric Quantum Ethernet Module 140noe77101Schneider-electric Quantum Ethernet Module 140noe77111 | 17/12/2011 | 16/6/2026 | The ComputePassword function in the Schneider Electric Quantum Ethernet Module on the NOE 771 device (aka the Quantum 140NOE771* module) generates the password for the fwupgrade account by performing a calculation on the MAC address, which makes it easier for remote attackers to obtain access via a (1) ARP request… | |
| Modificada | Alta (10) | 3.9% | — | Schneider-electric Quantum Ethernet Module 140cpu65150Schneider-electric Quantum Ethernet Module 140cpu65160Schneider-electric Quantum Ethernet Module 140cpu65260Schneider-electric Quantum Ethernet Module 140noe77100+17 | 17/12/2011 | 16/6/2026 | The Schneider Electric Quantum Ethernet Module, as used in the Quantum 140NOE771* and 140CPU65* modules, the Premium TSXETY* and TSXP57* modules, the M340 BMXNOE01* and BMXP3420* modules, and the STB DIO STBNIC2212 and STBNIP2* modules, uses hardcoded passwords for the (1) AUTCSE, (2) AUT_CSE, (3) fdrusers, (4)… | |
| Modificada | Media (6.8) | 29% | 💥 Exploit | Quantum Game Library | 28/2/2008 | 16/6/2026 | Multiple PHP remote file inclusion vulnerabilities in Quantum Game Library 0.7.2c allow remote attackers to execute arbitrary PHP code via a URL in the CONFIG[gameroot] parameter to (1) server_request.php and (2) qlib/smarty.inc.php. | |
| Modificada | Alta (7.5) | 1.2% | 💥 Exploit | Quantum ART QP7 Enterprise | 22/12/2005 | 16/6/2026 | SQL injection vulnerability in Quantum Art QP7.Enterprise (formerly Q-Publishing) allows remote attackers to execute arbitrary SQL commands via the p_news_id parameter to (1) news_and_events_new.asp and (2) news.asp. NOTE: on 20060227, the vendor disputed the accuracy of this report, saying that the p_news_id,… |