Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
694 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.89% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed,… | |
| Modificada | Media (6.5) | 1.0% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+16 | 7/4/2022 | 17/6/2026 | An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash. | |
| Modificada | Media (5.5) | 0.44% | — | Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+13 | 18/3/2022 | 17/6/2026 | Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user… | |
| Modificada | Media (6.7) | 0.45% | — | Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+13 | 18/3/2022 | 17/6/2026 | Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems. | |
| Modificada | Media (6.5) | 1.2% | — | Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+13 | 18/3/2022 | 17/6/2026 | Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or… | |
| Modificada | Alta (8.8) | 1.7% | — | Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+13 | 18/3/2022 | 17/6/2026 | ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated… | |
| Modificada | Crítica (9.8) | 6.4% | — | Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+13 | 18/3/2022 | 17/6/2026 | Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an… | |
| Modificada | Alta (7.5) | 1.1% | — | Nvidia Federated Learning Application Runtime Environment | 17/3/2022 | 17/6/2026 | NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable. | |
| Modificada | Alta (8.1) | 0.82% | — | Wasmcloud Host Runtime | 21/1/2022 | 17/6/2026 | wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for inbound invocations, but with this… | |
| Modificada | Alta (7.5) | 0.90% | — | Mirantis Container Runtime | 10/1/2022 | 17/6/2026 | When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service. | |
| Modificada | Alta (7.5) | 81% | 💥 PoC | Apache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+42 | 14/12/2021 | 17/6/2026 | JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in… | |
| Modificada | Alta (7.1) | 0.30% | — | Wibu Codemeter RuntimeSiemens PSS CapeSiemens PSS ESiemens PSS Odms+6 | 14/11/2021 | 17/6/2026 | In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions. | |
| Analizada | Media (6.5) | 0.85% | — | Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+26 | 26/10/2021 | 17/6/2026 | A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition. | |
| Analizada | Alta (8.1) | 0.88% | — | Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+26 | 26/10/2021 | 17/6/2026 | A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite. | |
| Analizada | Alta (7.5) | 2.7% | — | Wago 750-8202 FirmwareWago 750-8203 FirmwareWago 750-8204 FirmwareWago 750-8206 Firmware+11 | 26/10/2021 | 17/6/2026 | In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC. | |
| Modificada | Crítica (9.1) | 1.2% | — | Talend ESB Runtime | 22/9/2021 | 17/6/2026 | Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container. | |
| Modificada | Alta (7.5) | 2.6% | — | Opcfoundation Local Discover ServerSiemens Simatic Process Historian OPC UA Server FirmwareSiemens Simatic NET PCSiemens Simatic Wincc+3 | 27/8/2021 | 17/6/2026 | In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer. | |
| Modificada | Alta (7.1) | 1.2% | — | Apache Portable RuntimeOracle Http Server | 23/8/2021 | 17/6/2026 | An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue. | |
| Modificada | Media (5.3) | 0.85% | — | Redhat Wildfly ElytronRedhat Build OF QuarkusRedhat Codeready StudioRedhat Data Grid+9 | 5/8/2021 | 17/6/2026 | A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality. | |
| Modificada | Alta (7.5) | 1.0% | — | Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+3 | 3/8/2021 | 17/6/2026 | In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties. | |
| Modificada | Alta (7.5) | 0.96% | — | Codesys Runtime Toolkit | 3/8/2021 | 17/6/2026 | All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions. | |
| Modificada | Crítica (9.8) | 1.1% | — | Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+3 | 3/8/2021 | 17/6/2026 | CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow. | |
| Modificada | Alta (7.8) | 0.25% | — | Tibco Enterprise Runtime FOR RTibco Spotfire Analytics PlatformTibco Spotfire ServerTibco Spotfire Statistics Services | 29/6/2021 | 17/6/2026 | The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire… | |
| Modificada | Alta (7.8) | 0.22% | — | Tibco Enterprise Runtime FOR RTibco Spotfire Analytics PlatformTibco Spotfire ServerTibco Spotfire Statistics Services | 29/6/2021 | 17/6/2026 | The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO… | |
| Modificada | Media (6.1) | 1.4% | — | Redhat FuseRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Resteasy | 27/5/2021 | 17/6/2026 | A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack. |