Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2544▼ 345 respecto a la semana anterior
Críticas / altas1339▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
32 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.16% | — | BR Industrial Automation AprolAI | 6/7/2026 | 6/7/2026 | Untrusted Search Path vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. | |
| Aplazada | Crítica (9.1) | 0.22% | — | B AND R Industrial Automation Gmbh AprolAI | 6/7/2026 | 6/7/2026 | Improper certificate validation vulnerability in B&R Industrial Automation GmbH APROL. This issue affects APROL: before R 4.4-01P5. | |
| Aplazada | Alta (8.4) | 0.44% | — | BR AprolAI | 25/3/2025 | 17/6/2026 | An External Control of File Name or Path vulnerability in the APROL Web Portal used in B&R APROL <4.4-005P may allow an authenticated network-based attacker to access data from the file system. | |
| Aplazada | Media (6.8) | 0.13% | — | B&R AprolAI | 25/3/2025 | 17/6/2026 | An Improper Handling of Insufficient Permissions or Privileges vulnerability in scripts used in B&R APROL <4.4-00P5 may allow an authenticated local attacker to read credential information. | |
| Aplazada | Media (5.5) | 0.36% | — | BR AprolAI | 25/3/2025 | 17/6/2026 | An Incorrect Implementation of Authentication Algorithm and Exposure of Data Element to Wrong Ses-sion vulnerability in the session handling used in B&R APROL <4.4-00P5 may allow an authenticated network attacker to take over a currently active user session without login credentials. | |
| Aplazada | Alta (8.7) | 0.21% | — | B AND R AprolAI | 25/3/2025 | 17/6/2026 | An Exposure of Sensitive System Information to an Unauthorized Control Sphere and Initialization of a Resource with an Insecure Default vulnerability in the SNMP component of B&R APROL <4.4-00P5 may allow an unauthenticated adjacent-based attacker to read and alter configuration using SNMP. | |
| Aplazada | Alta (7.2) | 0.21% | — | B&R AprolAI | 25/3/2025 | 17/6/2026 | An Allocation of Resources Without Limits or Throttling vulnerability in the operating system network configuration used in B&R APROL <4.4-00P5 may allow an unauthenticated adjacent attacker to per-form Denial-of-Service (DoS) attacks against the product. | |
| Aplazada | Alta (7) | 0.23% | — | BR AprolAI | 25/3/2025 | 17/6/2026 | A Missing Authentication for Critical Function vulnerability in the GRUB configuration used B&R APROL <4.4-01 may allow an unauthenticated physical attacker to alter the boot configuration of the operating system. | |
| Aplazada | Alta (8.5) | 0.15% | — | B&R AprolAI | 25/3/2025 | 17/6/2026 | An Inclusion of Functionality from Untrusted Control Sphere vulnerability in the SSH server on B&R APROL <4.4-00P1 may allow an authenticated local attacker from a trusted remote server to execute malicious commands. | |
| Aplazada | Alta (8.5) | 0.15% | — | B&R AprolAI | 25/3/2025 | 17/6/2026 | An Incomplete Filtering of Special Elements vulnerability in scripts using the SSH server on B&R APROL <4.4-00P5 may allow an authenticated local attacker to authenticate as another legitimate user. | |
| Aplazada | Crítica (9.2) | 0.40% | — | BR AprolAI | 25/3/2025 | 17/6/2026 | An improper control of generation of code ('Code Injection') vulnerability in the AprolCreateReport component of B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to read files from the local system. | |
| Aplazada | Alta (8.5) | 0.13% | — | BR AprolAI | 25/3/2025 | 17/6/2026 | An Incorrect Permission Assignment for Critical Resource vulnerability in the file system used in B&R APROL <4.4-01 may allow an authenticated local attacker to read and alter the configuration of another engineering or runtime user. | |
| Aplazada | Media (5.1) | 0.40% | — | BR AprolAI | 25/3/2025 | 17/6/2026 | An Improper Neutralization of Input During Web Page Generation vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to insert malicious code which is then executed in the context of the user’s browser session. | |
| Aplazada | Media (5.3) | 0.35% | — | BR AprolAI | 25/3/2025 | 17/6/2026 | A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an authenticated network-based attacker to force the web server to request arbitrary URLs. | |
| Aplazada | Media (6.9) | 0.40% | — | BR AprolAI | 25/3/2025 | 17/6/2026 | A Server-Side Request Forgery vulnerability in the APROL Web Portal used in B&R APROL <4.4-00P5 may allow an unauthenticated network-based attacker to force the web server to request arbitrary URLs. | |
| Analizada | Media (5.1) | 0.25% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | Reflected Cross-Site Scripting (XSS) in Shift Logbook application of B&R APROL <= R 4.4-00P3 may allow a network-based attacker to execute arbitrary JavaScript code in the context of the user's browser session | |
| Analizada | Media (5.4) | 0.17% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | An untrusted search path vulnerability in B&R APROL <= R 4.4-00P3 may be used by an authenticated local attacker to get other users to execute arbitrary code under their privileges. | |
| Analizada | Alta (7.3) | 0.17% | — | Br-automation Industrial Automation Aprol | 29/8/2024 | 17/6/2026 | An untrusted search path vulnerability in the AprolConfigureCCServices of B&R APROL <= R 4.2.-07P3 and <= R 4.4-00P3 may allow an authenticated local attacker to execute arbitrary code with elevated privileges. | |
| Aplazada | Alta (7.2) | 0.17% | — | B&R Industrial Automation Scene ViewerAIB&R Industrial Automation Mapp VisionAIB&R Industrial Automation Mapp ViewAIB&R Industrial Automation Mapp CockpitAI+21 | 14/5/2024 | 17/6/2026 | An Uncontrolled Search Path Element vulnerability in B&R Industrial Automation Scene Viewer, B&R Industrial Automation Automation Runtime, B&R Industrial Automation mapp Vision, B&R Industrial Automation mapp View, B&R Industrial Automation mapp Cockpit, B&R Industrial Automation mapp Safety, B&R Industrial Automation… | |
| Modificada | Alta (7.5) | 0.62% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | B&R APROL versions < R 4.2-07 doesn’t process correctly specially formatted data packages sent to port 55502/tcp, which may allow a network based attacker to cause an application Denial-of-Service. | |
| Modificada | Crítica (9.8) | 0.78% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Insufficient validation of input parameters when changing configuration on Tbase server in B&R APROL versions < R 4.2-07 could result in buffer overflow. This may lead to Denial-of-Service conditions or execution of arbitrary code. | |
| Modificada | Alta (7.5) | 0.62% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Insufficient check of preconditions could lead to Denial of Service conditions when calling commands on the Tbase server of B&R APROL versions < R 4.2-07. | |
| Modificada | Crítica (9.8) | 0.62% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Lack of verification in B&R APROL Tbase server versions < R 4.2-07 may lead to memory leaks when receiving messages | |
| Modificada | Alta (7.5) | 0.55% | — | Br-automation Industrial Automation Aprol | 8/2/2023 | 17/6/2026 | Missing authentication when creating and managing the B&R APROL database in versions < R 4.2-07 allows reading and changing the system configuration. | |
| Modificada | Alta (7.5) | 1.2% | — | Br-automation Industrial Automation Aprol | 27/11/2020 | 17/6/2026 | An issue was discovered in B&R Industrial Automation APROL before R4.2 V7.08. An attacker can get access to historical data from AprolSqlServer by bypassing authentication, a different vulnerability than CVE-2019-16358. |