Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2904▼ 176 respecto a la semana anterior
Críticas / altas1294▼ 55 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
–

20 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.5)0.17%—Automationdirect C-more ViewjetAI4/4/202517/6/2026
Weak encoding for password vulnerability exists in HMI ViewJet C-more series. If this vulnerability is exploited, authentication information may be obtained by a local authenticated attacker.
AplazadaMedia (5.8)0.46%—Automationdirect Viewjet C-moreAIAutomationdirect Gc-a2AI4/4/202517/6/2026
Unintended proxy or intermediary ('Confused Deputy') issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to use the product as an intermediary for FTP bounce attack.
AplazadaMedia (5.3)0.61%—Redlion Viewjet C-moreAIRedlion Gc-a2AI4/4/202517/6/2026
Allocation of resources without limits or throttling issue exists in HMI ViewJet C-more series and HMI GC-A2 series, which may allow a remote unauthenticated attacker to cause a denial-of-service (DoS) condition.
AplazadaMedia (4.3)0.35%—HMI Viewjet C-moreAI4/4/202517/6/2026
Improper restriction of rendered UI layers or frames issue exists in HMI ViewJet C-more series, which may allow a remote unauthenticated attacker to trick the product user to perform operations on the product's web pages.
AplazadaCrítica (9.3)0.89%—Automationdirect C-more EA9AI4/2/202517/6/2026
AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device.
AnalizadaAlta (7.8)0.28%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.28%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a…
AnalizadaAlta (7.8)0.31%—Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+530/1/202517/6/2026
AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target…
AplazadaMedia (6.5)0.40%—Automationdirect C-more EA9AI26/3/202417/6/2026
In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device.
AplazadaMedia (4.3)0.45%—Automationdirect C-more EA9AI26/3/202417/6/2026
In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limited sized buffer on the stack which may lead to a stack overflow. The result of this stack-based buffer overflow can lead to denial-of-service conditions.
AplazadaAlta (7.5)0.62%—Automationdirect C-more EA9AI26/3/202417/6/2026
There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content.
ModificadaAlta (7.8)0.36%—Automationdirect C-more Ea9-t6cl FirmwareAutomationdirect C-more Ea9-t6cl-r FirmwareAutomationdirect C-more Ea9-t7cl FirmwareAutomationdirect C-more Ea9-t7cl-r Firmware+831/8/202217/6/2026
—
ModificadaAlta (7.5)0.52%—Automationdirect C-more Ea9-t6cl FirmwareAutomationdirect C-more Ea9-t6cl-r FirmwareAutomationdirect C-more Ea9-t7cl FirmwareAutomationdirect C-more Ea9-t7cl-r Firmware+831/8/202217/6/2026
—
ModificadaAlta (7.5)3.7%—Automationdirect C-more HMI EA9 Firmware23/7/202017/6/2026
This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the…
ModificadaCrítica (9.8)2.8%—Automationdirect C-more HMI EA9 Firmware23/7/202017/6/2026
This vulnerability allows remote attackers to issue commands on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the EA-HTTP.exe process. The issue results from the lack of authentication…
ModificadaCrítica (9.8)4.9%—Automationdirect C-more HMI EA9 Firmware23/7/202017/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the control service, which listens on TCP port 9999 by default. The…
ModificadaMedia (5.9)1.6%—Automationdirect C-more HMI EA9 Firmware23/7/202017/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of passwords. When transmitting passwords, the…
ModificadaAlta (7.5)2.7%—Automationdirect C-more HMI EA9 Firmware23/7/202017/6/2026
This vulnerability allows remote attackers to bypass authentication on affected installations of C-MORE HMI EA9 Firmware version 6.52 touch screen panels. Authentication is not required to exploit this vulnerability. The specific flaw exists within the authentication mechanism. The issue is due to insufficient…
ModificadaCrítica (9.8)2.4%—Automationdirect C-more Ea9-rhi FirmwareAutomationdirect C-more Ea9-t6cl-r FirmwareAutomationdirect C-more Ea9-t6cl FirmwareAutomationdirect C-more Ea9-t7cl-r Firmware+75/2/202017/6/2026
It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations.
ModificadaAlta (7.8)1.1%—Automationdirect Click PLC FirmwareAutomationdirect C-more PLC FirmwareAutomationdirect C-more Micro FirmwareAutomationdirect GS Drives Fimware+113/11/201717/6/2026
In AutomationDirect CLICK Programming Software (Part Number C0-PGMSW) Versions 2.10 and prior; C-More Programming Software (Part Number EA9-PGMSW) Versions 6.30 and prior; C-More Micro (Part Number EA-PGMSW) Versions 4.20.01.0 and prior; Do-more Designer Software (Part Number DM-PGMSW) Versions 2.0.3 and prior; GS…