Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.57%—Codesys Gateway ClientAI30/9/202630/9/2026
The CODESYS Gateway Client allocates memory based on a size field in a gateway response without enforcing an appropriate upper limit. An unauthenticated remote attacker controlling a malicious gateway can exploit this behavior to trigger excessive memory consumption, resulting in a denial-of-service condition thus…
AplazadaAlta (7.1)0.28%—Codesys Profinet ControllerAICodesys ControlAI29/7/202630/7/2026
An out‑of‑bounds write vulnerability in the CODESYS PROFINET Controller allows an unauthenticated attacker on the same network segment to send malformed PROFINET communication data that triggers an exception in the affected PLC application. The exception is handled by the CODESYS Control runtime system and results in…
AnalizadaAlta (8.5)0.12%—Codesys Development System26/5/202624/7/2026
The affected product extracts installation files to a temporary directory with incorrect default permissions during administrative installation. A low-privileged local attacker can exploit a TOCTOU race condition with a practical time window to replace verified files with malicious ones before installation, resulting…
AnalizadaAlta (8.5)0.14%—Codesys Development System26/5/202624/7/2026
The affected product creates a directory with insecure default permissions during administrative installation. This allows a low-privileged local attacker to modify a temporary file defining the components to be installed, enabling local privilege escalation by forcing the deployment of arbitrary components.
AnalizadaMedia (6.9)0.24%—Codesys Visualization21/5/202623/7/2026
The affected product may expose credentials remotely between low privileged visualization users during concurrent login operations due to insufficient isolation of authentication data. The vulnerability affects only login operations within an active visualization session.
Pendiente de análisisAlta (8.2)0.54%—Codesys Modbus TCP ServerAI12/5/202617/6/2026
An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections.
Pendiente de análisisAlta (8.7)0.57%—Codesys Ethernet IP AdapterAI23/4/202617/6/2026
An unauthenticated remote attacker is able to exhaust all available TCP connections in the CODESYS EtherNet/IP adapter stack, preventing legitimate clients from establishing new connections.
Pendiente de análisisAlta (7.5)0.57%—Codesys ControlAI24/3/202617/6/2026
An unauthenticated remote attacker may be able to control the format string of messages processed by the Audit Log of the CODESYS Control runtime system, potentially resulting in a denial‑of‑service (DoS) condition.
Pendiente de análisisAlta (8.8)0.43%—Codesys Control Runtime SystemAI24/3/202617/6/2026
A low-privileged remote attacker may be able to replace the boot application of the CODESYS Control runtime system, enabling unauthorized code execution.
Pendiente de análisisAlta (7.3)0.08%—Codesys Development SystemAI10/3/202617/6/2026
If a legitimate user confirms a self-update prompt or initiate an installation of a CODESYS Development System, a low privileged local attacker can gain elevated rights due to a TOCTOU vulnerability in the CODESYS installer.
AplazadaMedia (5.9)0.35%—Codesys Control Runtime SystemAI1/12/202517/6/2026
An unauthenticated remote attacker, who beats a race condition, can exploit a flaw in the communication servers of the CODESYS Control runtime system on Linux and QNX to trigger an out-of-bounds read via crafted socket communication, potentially causing a denial of service.
AnalizadaAlta (7.5)0.39%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+131/12/202517/6/2026
An unauthenticated remote attacker may cause the visualisation server of the CODESYS Control runtime system to access a resource with a pointer of wrong type, potentially leading to a denial-of-service (DoS) condition.
AnalizadaAlta (7.8)0.15%—Codesys1/12/202517/6/2026
An unauthenticated attacker can trick a local user into executing arbitrary code by opening a deliberately manipulated CODESYS project file with a CODESYS development system. This arbitrary code is executed in the user context.
AplazadaAlta (7.5)0.55%—Codesys Control RuntimeAI4/8/202517/6/2026
An unauthenticated remote attacker may trigger a NULL pointer dereference in the affected CODESYS Control runtime systems by sending specially crafted communication requests, potentially leading to a denial-of-service (DoS) condition.
AplazadaAlta (8.3)0.22%—Codesys ControlAI4/8/202517/6/2026
A low-privileged attacker can remotely access the PKI folder of the CODESYS Control runtime system and thus read and write certificates and its keys. This allows sensitive data to be extracted or to accept certificates as trusted. Although all services remain available, only unencrypted communication is possible if…
AplazadaMedia (5.5)0.12%—Codesys Runtime ToolkitAI4/8/202517/6/2026
CODESYS Runtime Toolkit-based products may expose sensitive files to local low-privileged operating system users due to default file permissions.
AplazadaMedia (5.3)0.46%—Codesys VisualizationAI23/4/202517/6/2026
An unauthenticated remote attacker can bypass the user management in CODESYS Visualization and read visualization template files or static elements by means of forced browsing.
AplazadaAlta (7.5)0.63%—Codesys OPC UA ServerAI18/3/202517/6/2026
An unauthenticated remote attacker can gain access to sensitive information including authentication information when using CODESYS OPC UA Server with the non-default Basic128Rsa15 security policy.
AplazadaMedia (6.6)0.27%—Codesys ControlAI18/3/202517/6/2026
Insufficient path validation in CODESYS Control allows low privileged attackers with physical access to gain full filesystem access.
AplazadaAlta (8.8)0.50%—Codesys V3AI18/11/202417/6/2026
A low privileged remote attacker may modify the configuration of the CODESYS V3 service through a missing authentication vulnerability which could lead to full system access and/or DoS.
AplazadaAlta (7.5)0.62%—CodesysAI25/9/202417/6/2026
An unauthenticated remote attacker can causes the CODESYS web server to access invalid memory which results in a DoS.
ModificadaMedia (4.4)0.19%—Codesys Oscat Basic Library10/9/202417/6/2026
Out-of-Bounds read vulnerability in OSCAT Basic Library allows an local, unprivileged attacker to access limited internal data of the PLC which may lead to a crash of the affected service.
AplazadaAlta (7.5)0.57%—CodesysAI4/6/202417/6/2026
An unauthenticated remote attacker can use a malicious OPC UA client to send a crafted request to affected CODESYS products which can cause a DoS due to incorrect calculation of buffer size.
ModificadaAlta (8.8)0.96%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+75/12/202317/6/2026
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
ModificadaAlta (8.8)0.88%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+103/8/202317/6/2026
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.