Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
–

694 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.89%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An authenticated, remote attacker can gain access to a dereferenced pointer contained in a request. The accesses can subsequently lead to local overwriting of memory in the CmpTraceMgr, whereby the attacker can neither gain the values read internally nor control the values to be written. If invalid memory is accessed,…
ModificadaMedia (6.5)1.0%—Codesys Control FOR Beaglebone SLCodesys Control FOR Beckhoff Cx9020Codesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SL+167/4/202217/6/2026
An authenticated remote attacker can cause a null pointer dereference in the CmpSettings component of the affected CODESYS products which leads to a crash.
ModificadaMedia (5.5)0.44%—Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+1318/3/202217/6/2026
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable without any additional modification. A local, unauthenticated attacker could compromise the user…
ModificadaMedia (6.7)0.45%—Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+1318/3/202217/6/2026
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when running on Microsoft Windows systems.
ModificadaMedia (6.5)1.2%—Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+1318/3/202217/6/2026
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of encryption performed with a fixed key value using the tiny encryption algorithm (TEA) on an entered or…
ModificadaAlta (8.8)1.7%—Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+1318/3/202217/6/2026
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Data is transferred over this protocol unencrypted, which could allow a remote unauthenticated…
ModificadaCrítica (9.8)6.4%—Schneider-electric Easergy T300 FirmwareSchneider-electric Easergy C5 FirmwareSchneider-electric Micom C264 FirmwareSchneider-electric Pacis GTW Firmware+1318/3/202217/6/2026
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not checked for reserved characters, it is possible for a remote, unauthenticated attacker to traverse an…
ModificadaAlta (7.5)1.1%—Nvidia Federated Learning Application Runtime Environment17/3/202217/6/2026
NVIDIA FLARE contains a vulnerability in the admin interface, where an un-authorized attacker can cause Allocation of Resources Without Limits or Throttling, which may lead to cause system unavailable.
ModificadaAlta (8.1)0.82%—Wasmcloud Host Runtime21/1/202217/6/2026
wasmCloud Host Runtime is a server process that securely hosts and provides dispatch for web assembly (WASM) actors and capability providers. In versions prior to 0.52.2 actors can bypass capability authorization. Actors are normally required to declare their capabilities for inbound invocations, but with this…
ModificadaAlta (7.5)0.90%—Mirantis Container Runtime10/1/202217/6/2026
When running with FIPS mode enabled, Mirantis Container Runtime 20.10.8 leaks memory during TLS Handshakes which could be abused to cause a denial of service.
ModificadaAlta (7.5)81%💥 PoCApache Log4jFedoraproject FedoraRedhat Codeready StudioRedhat Integration Camel K+4214/12/202117/6/2026
JMSAppender in Log4j 1.2 is vulnerable to deserialization of untrusted data when the attacker has write access to the Log4j configuration. The attacker can provide TopicBindingName and TopicConnectionFactoryBindingName configurations causing JMSAppender to perform JNDI requests that result in remote code execution in…
ModificadaAlta (7.1)0.30%—Wibu Codemeter RuntimeSiemens PSS CapeSiemens PSS ESiemens PSS Odms+614/11/202117/6/2026
In WIBU CodeMeter Runtime before 7.30a, creating a crafted CmDongles symbolic link will overwrite the linked file without checking permissions.
AnalizadaMedia (6.5)0.85%—Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+2626/10/202117/6/2026
A crafted request may cause a read access to an uninitialized pointer in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition.
AnalizadaAlta (8.1)0.88%—Wago 750-823 FirmwareWago 750-829 FirmwareWago 750-831 FirmwareWago 750-832 Firmware+2626/10/202117/6/2026
A crafted request with invalid offsets may cause an out-of-bounds read or write access in CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56, resulting in a denial-of-service condition or local memory overwrite.
AnalizadaAlta (7.5)2.7%—Wago 750-8202 FirmwareWago 750-8203 FirmwareWago 750-8204 FirmwareWago 750-8206 Firmware+1126/10/202117/6/2026
In CODESYS V2 Runtime Toolkit 32 Bit full and PLCWinNT prior to versions V2.4.7.56 unauthenticated crafted invalid requests may result in several denial-of-service conditions. Running PLC programs may be stopped, memory may be leaked, or further communication clients may be blocked from accessing the PLC.
ModificadaCrítica (9.1)1.2%—Talend ESB Runtime22/9/202117/6/2026
Talend ESB Runtime in all versions from 5.1 to 7.3.1-R2021-09, 7.2.1-R2021-09, 7.1.1-R2021-09, has an unauthenticated Jolokia HTTP endpoint which allows remote access to the JMX of the runtime container, which would allow an attacker the ability to read or modify the container or software running in the container.
ModificadaAlta (7.5)2.6%—Opcfoundation Local Discover ServerSiemens Simatic Process Historian OPC UA Server FirmwareSiemens Simatic NET PCSiemens Simatic Wincc+327/8/202117/6/2026
In OPC Foundation Local Discovery Server (LDS) before 1.04.402.463, remote attackers can cause a denial of service (DoS) by sending carefully crafted messages that lead to Access of a Memory Location After the End of a Buffer.
ModificadaAlta (7.1)1.2%—Apache Portable RuntimeOracle Http Server23/8/202117/6/2026
An out-of-bounds array read in the apr_time_exp*() functions was fixed in the Apache Portable Runtime 1.6.3 release (CVE-2017-12613). The fix for this issue was not carried forward to the APR 1.7.x branch, and hence version 1.7.0 regressed compared to 1.6.3 and is vulnerable to the same issue.
ModificadaMedia (5.3)0.85%—Redhat Wildfly ElytronRedhat Build OF QuarkusRedhat Codeready StudioRedhat Data Grid+95/8/202117/6/2026
A flaw was found in Wildfly Elytron in versions prior to 1.10.14.Final, prior to 1.15.5.Final and prior to 1.16.1.Final where ScramServer may be susceptible to Timing Attack if enabled. The highest threat of this vulnerability is confidentiality.
ModificadaAlta (7.5)1.0%—Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+33/8/202117/6/2026
In CODESYS V3 web server before 3.5.17.10, files or directories are accessible to External Parties.
ModificadaAlta (7.5)0.96%—Codesys Runtime Toolkit3/8/202117/6/2026
All versions of the CODESYS V3 Runtime Toolkit for VxWorks from version V3.5.8.0 and before version V3.5.17.10 have Improper Handling of Exceptional Conditions.
ModificadaCrítica (9.8)1.1%—Codesys ControlCodesys Control RTECodesys Control Runtime System ToolkitCodesys Control WIN SL+33/8/202117/6/2026
CODESYS Control Runtime system before 3.5.17.10 has a Heap-based Buffer Overflow.
ModificadaAlta (7.8)0.25%—Tibco Enterprise Runtime FOR RTibco Spotfire Analytics PlatformTibco Spotfire ServerTibco Spotfire Statistics Services29/6/202117/6/2026
The TIBCO Spotfire Server and TIBCO Enterprise Runtime for R components of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire…
ModificadaAlta (7.8)0.22%—Tibco Enterprise Runtime FOR RTibco Spotfire Analytics PlatformTibco Spotfire ServerTibco Spotfire Statistics Services29/6/202117/6/2026
The Windows Installation component of TIBCO Software Inc.'s TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Enterprise Runtime for R - Server Edition, TIBCO Spotfire Analytics Platform for AWS Marketplace, TIBCO Spotfire Server, TIBCO Spotfire Server, TIBCO…
ModificadaMedia (6.1)1.4%—Redhat FuseRedhat Jboss Enterprise Application PlatformRedhat Openshift Application RuntimesRedhat Resteasy27/5/202117/6/2026
A cross-site scripting (XSS) flaw was found in RESTEasy in versions before 3.11.1.Final and before 4.5.3.Final, where it did not properly handle URL encoding when the RESTEASY003870 exception occurs. An attacker could use this flaw to launch a reflected XSS attack.
Orbitaley — Vulnerabilidades