Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
694 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.5) | 7.2% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+25 | 25/5/2021 | 17/6/2026 | CODESYS V2 runtime system before 2.4.7.55 has Improper Input Validation. | |
| Analizada | Crítica (9.8) | 1.3% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 runtime system SP before 2.4.7.55 has a Stack-based Buffer Overflow. | |
| Analizada | Alta (7.5) | 7.4% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+25 | 25/5/2021 | 17/6/2026 | CODESYS V2 runtime system SP before 2.4.7.55 has a Heap-based Buffer Overflow. | |
| Analizada | Media (5.3) | 0.27% | — | Wago 750-893 FirmwareWago 750-891 FirmwareWago 750-890 FirmwareWago 750-889 Firmware+24 | 25/5/2021 | 17/6/2026 | CODESYS V2 runtime system SP before 2.4.7.55 has Improper Neutralization of Special Elements used in an OS Command. | |
| Modificada | Alta (7.5) | 1.8% | — | Siemens Simatic Wincc Runtime AdvancedSiemens Sinamics Sh150 FirmwareSiemens Sinamics Sm150i FirmwareSiemens Sinamics Gh150 Firmware+14 | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)… | |
| Modificada | Alta (7.5) | 2.6% | — | Siemens Simatic Wincc Runtime AdvancedSiemens Sinamics Sh150 FirmwareSiemens Sinamics Sm150i FirmwareSiemens Sinamics Gh150 Firmware+14 | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)… | |
| Modificada | Crítica (9.8) | 2.6% | — | Siemens Simatic Wincc Runtime AdvancedSiemens Sinamics Sh150 FirmwareSiemens Sinamics Sm150i FirmwareSiemens Sinamics Gh150 Firmware+14 | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)… | |
| Modificada | Alta (7.5) | 1.8% | — | Siemens Simatic Wincc Runtime AdvancedSiemens Sinamics Sh150 FirmwareSiemens Sinamics Sm150i FirmwareSiemens Sinamics Gh150 Firmware+14 | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)… | |
| Modificada | Alta (7.5) | 1.6% | — | Siemens Simatic Wincc Runtime AdvancedSiemens Simatic HMI Comfort Outdoor Panels 7" FirmwareSiemens Simatic HMI Comfort Outdoor Panels 15" FirmwareSiemens Simatic HMI Comfort Panels 4" Firmware+6 | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)… | |
| Modificada | Alta (7.5) | 1.1% | — | Siemens Simatic Wincc Runtime AdvancedSiemens Simatic HMI Comfort Outdoor Panels 7" FirmwareSiemens Simatic HMI Comfort Outdoor Panels 15" FirmwareSiemens Simatic HMI Comfort Panels 4" Firmware+6 | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)… | |
| Modificada | Alta (7.5) | 0.97% | — | Siemens Simatic HMI Comfort Outdoor Panels 7" FirmwareSiemens Simatic HMI Comfort Outdoor Panels 15" FirmwareSiemens Simatic HMI Comfort Panels 4" FirmwareSiemens Simatic HMI Comfort Panels 22" Firmware+6 | 12/5/2021 | 17/6/2026 | A vulnerability has been identified in SIMATIC HMI Comfort Outdoor Panels V15 7\" & 15\" (incl. SIPLUS variants) (All versions < V15.1 Update 6), SIMATIC HMI Comfort Outdoor Panels V16 7\" & 15\" (incl. SIPLUS variants) (All versions < V16 Update 4), SIMATIC HMI Comfort Panels V15 4\" - 22\" (incl. SIPLUS variants)… | |
| Modificada | Alta (7.3) | 1.1% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+18 | 3/5/2021 | 17/6/2026 | CODESYS Control Runtime system before 3.5.17.0 has improper input validation. Attackers can send crafted communication packets to change the router's addressing scheme and may re-route, add, remove or change low level communication packages. | |
| Modificada | Alta (7.5) | 1.4% | — | Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+7 | 3/5/2021 | 17/6/2026 | CODESYS Gateway 3 before 3.5.16.70 has a NULL pointer dereference that may result in a denial of service (DoS). | |
| Modificada | Crítica (9.6) | 1.1% | — | Tibco AdministratorTibco Runtime Agent | 20/4/2021 | 17/6/2026 | The Administration GUI component of TIBCO Software Inc.'s TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator - Enterprise Edition Distribution for TIBCO Silver Fabric, TIBCO Administrator… | |
| Modificada | Media (5.9) | 1.1% | — | Jose-node-cjs-runtime Project Jose-node-cjs-runtime | 16/4/2021 | 17/6/2026 | jose-node-cjs-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed`… | |
| Modificada | Media (5.9) | 1.1% | — | Jose-node-cjs-runtime Project Jose-node-cjs-runtime | 16/4/2021 | 17/6/2026 | jose-node-esm-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed`… | |
| Modificada | Media (5.9) | 1.1% | — | Jose-node-cjs-runtime Project Jose-node-cjs-runtime | 16/4/2021 | 17/6/2026 | jose-browser-runtime is an npm package which provides a number of cryptographic functions. In versions prior to 3.11.4 the AES_CBC_HMAC_SHA2 Algorithm (A128CBC-HS256, A192CBC-HS384, A256CBC-HS512) decryption would always execute both HMAC tag verification and CBC decryption, if either failed `JWEDecryptionFailed`… | |
| Modificada | Media (5.9) | 64% | 💥 PoC | OpensslDebian LinuxFreebsdNetapp Active IQ Unified Manager+102 | 25/3/2021 | 17/6/2026 | An OpenSSL TLS server may crash if sent a maliciously crafted renegotiation ClientHello message from a client. If a TLSv1.2 renegotiation ClientHello omits the signature_algorithms extension (where it was present in the initial ClientHello), but includes a signature_algorithms_cert extension then a NULL pointer… | |
| Modificada | Alta (7.5) | 1.4% | — | Redhat Jboss FuseRedhat Openshift Application RuntimesRedhat Undertow | 23/2/2021 | 17/6/2026 | A flaw was found in the Undertow AJP connector. Malicious requests and abrupt connection closes could be triggered by an attacker using query strings with non-RFC compliant characters resulting in a denial of service. The highest threat from this vulnerability is to system availability. This affects Undertow… | |
| Modificada | Baja (2.7) | 0.77% | — | Redhat KeycloakRedhat Jboss FuseRedhat Openshift Application RuntimesRedhat Single Sign-on | 11/2/2021 | 17/6/2026 | A flaw was found in Keycloak 7.0.1. A logged in user can do an account email enumeration attack. | |
| Modificada | Baja (3.3) | 0.21% | — | Redhat KeycloakRedhat Jboss FuseRedhat Openshift Application RuntimesRedhat Single Sign-on | 11/2/2021 | 17/6/2026 | A vulnerability was found in keycloak in the way that the OIDC logout endpoint does not have CSRF protection. Versions shipped with Red Hat Fuse 7, Red Hat Single Sign-on 7, and Red Hat Openshift Application Runtimes are believed to be vulnerable. | |
| Modificada | Crítica (9.1) | 1.5% | — | Lucet-runtime-internals Project Lucet-runtime-internals | 31/12/2020 | 17/6/2026 | An issue was discovered in the lucet-runtime-internals crate before 0.5.1 for Rust. It mishandles sigstack allocation. Guest programs may be able to obtain sensitive information, or guest programs can experience memory corruption. | |
| Modificada | Alta (7.8) | 0.31% | — | Schneider-electric Operator Terminal Expert Runtime | 19/11/2020 | 17/6/2026 | A CWE-269 Improper Privilege Management vulnerability exists in EcoStruxureª Operator Terminal Expert runtime (Vijeo XD) that could cause privilege escalation on the workstation when interacting directly with a driver installed by the runtime software of EcoStruxureª Operator Terminal Expert. | |
| Modificada | Alta (7.3) | 0.88% | — | Beckhoff Twincat Extended Automation Runtime | 19/11/2020 | 17/6/2026 | The default installation path of the TwinCAT XAR 3.1 software in all versions is underneath C:\TwinCAT. If the directory does not exist it and further subdirectories are created with permissions which allow every local user to modify the content. The default installation registers TcSysUI.exe for automatic execution… | |
| Modificada | Media (6.5) | 1.5% | — | Redhat WildflyRedhat FuseRedhat Jboss Data GridRedhat Jboss Enterprise Application Platform+6 | 2/11/2020 | 17/6/2026 | A memory leak flaw was found in WildFly in all versions up to 21.0.0.Final, where host-controller tries to reconnect in a loop, generating new connections which are not properly closed while not able to connect to domain-controller. This flaw allows an attacker to cause an Out of memory (OOM) issue, leading to a… |