Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
31 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7) | 0.65% | — | Laquis ScadaAI | 17/10/2024 | 17/6/2026 | In LAquis SCADA version 4.7.1.511, a cross-site scripting vulnerability could allow an attacker to inject arbitrary code into a web page. This could allow an attacker to steal cookies, redirect users, or perform unauthorized actions. | |
| Aplazada | Alta (8.5) | 0.41% | — | Lcds Laquis ScadaAI | 21/5/2024 | 17/6/2026 | There are multiple ways in LCDS LAquis SCADA for an attacker to access locations outside of their own directory. | |
| Modificada | Media (6.1) | 2.5% | — | Lcds Laquis Scada | 25/5/2022 | 17/6/2026 | When a non-existent resource is requested, the LCDS LAquis SCADA application (version 4.3.1.1011 and prior) returns error messages which may allow reflected cross-site scripting. | |
| Modificada | Alta (7.8) | 1.3% | — | Laquisscada Scada | 4/10/2021 | 17/6/2026 | LCDS LAquis SCADA through 4.3.1.1085 is vulnerable to a control bypass and path traversal. If an attacker can get a victim to load a malicious els project file and use the play feature, then the attacker can bypass a consent popup and write arbitrary files to OS locations where the user has permission, leading to code… | |
| Modificada | Alta (7.8) | 1.9% | — | Laquisscada Scada | 14/10/2020 | 17/6/2026 | An attacker who convinces a valid user to open a specially crafted project file to exploit could execute code under the privileges of the application due to an out-of-bounds read vulnerability on the LAquis SCADA (Versions prior to 4.3.1.870). | |
| Modificada | Alta (7.8) | 0.81% | — | Lcds Laquis Scada | 4/5/2020 | 17/6/2026 | LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to arbitrary file creation by unauthorized users | |
| Modificada | Media (5.5) | 0.83% | — | Lcds Laquis Scada | 4/5/2020 | 17/6/2026 | LCDS LAquis SCADA Versions 4.3.1 and prior. The affected product is vulnerable to sensitive information exposure by unauthorized users. | |
| Modificada | Baja (3.3) | 0.86% | — | Laquisscada Scada | 5/8/2019 | 17/6/2026 | Processing a specially crafted project file in LAquis SCADA 4.3.1.71 may trigger an out-of-bounds read, which may allow an attacker to obtain sensitive information. The attacker must have local access to the system. A CVSS v3 base score of 2.5 has been calculated; the CVSS vector string is… | |
| Modificada | Alta (7.8) | 1.0% | — | Laquisscada Scada | 5/8/2019 | 17/6/2026 | A type confusion vulnerability may be exploited when LAquis SCADA 4.3.1.71 processes a specially crafted project file. This may allow an attacker to execute remote code. The attacker must have local access to the system. A CVSS v3 base score of 7.8 has been calculated; the CVSS vector string is… | |
| Modificada | Alta (7.1) | 1.1% | — | Laquisscada Laquis Scada | 27/3/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an out of bounds read when opening a specially crafted project file, which may cause a system crash or allow data exfiltration. | |
| Modificada | Alta (7.8) | 1.2% | — | Lcds Laquis Scada | 27/3/2019 | 17/6/2026 | Opening a specially crafted LCDS LAquis SCADA before 4.3.1.71 ELS file may result in a write past the end of an allocated buffer, which may allow an attacker to execute remote code in the context of the current process. | |
| Modificada | Alta (7.8) | 2.7% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an attacker using a specially crafted project file to supply a pointer for a controlled memory address, which may allow remote code execution, data exfiltration, or cause a system crash. | |
| Modificada | Alta (7.8) | 2.7% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows improper control of generation of code when opening a specially crafted project file, which may allow remote code execution, data exfiltration, or cause a system crash. | |
| Modificada | Media (5.3) | 8.8% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows an authentication bypass, which may allow an attacker access to sensitive data. | |
| Modificada | Crítica (9.8) | 2.4% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 uses hard coded credentials, which may allow an attacker unauthorized access to the system with high privileges. | |
| Modificada | Crítica (9.8) | 2.5% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper authorization or sanitation, which may allow an attacker to execute remote code on the server. | |
| Modificada | Alta (8.8) | 2.0% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows taking in user input without proper sanitation, which may allow an attacker to execute remote code on the server. | |
| Modificada | Media (5.3) | 39% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows a user-supplied path in file operations prior to proper validation. An attacker can leverage this vulnerability to disclose sensitive information under the context of the web server process. | |
| Modificada | Alta (7.8) | 2.7% | — | Lcds Laquis Scada | 5/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows the opening of a specially crafted report format file that may cause an out of bounds read, which may cause a system crash, allow data exfiltration, or remote code execution. | |
| Modificada | Baja (3.3) | 3.7% | — | Lcds Laquis Scada | 1/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows out of bounds read when opening a specially crafted project file, which may allow data exfiltration. | |
| Modificada | Alta (8.8) | 2.6% | — | Lcds Laquis Scada | 1/2/2019 | 17/6/2026 | LCDS Laquis SCADA prior to version 4.1.0.4150 allows execution of script code by opening a specially crafted report format file. This may allow remote code execution, data exfiltration, or cause a system crash. | |
| Modificada | Alta (7.8) | 3.2% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior has several stack-based buffer overflow vulnerabilities, which may allow remote code execution. | |
| Modificada | Alta (7.8) | 1.6% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior, when processing project files the application fails to sanitize user input prior to performing write operations on a stack object, which may allow an attacker to execute code under the current process. | |
| Modificada | Alta (8.8) | 8.1% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior has a path traversal vulnerability, which may allow remote code execution. | |
| Modificada | Crítica (9.8) | 6.0% | — | Lcds Laquis Scada | 17/10/2018 | 17/6/2026 | LAquis SCADA Versions 4.1.0.3870 and prior has several integer overflow to buffer overflow vulnerabilities, which may allow remote code execution. |