Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3059▲ 556 respecto a la semana anterior
Críticas / altas1460▲ 282 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
35 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.4) | 0.18% | — | Hornerautomation CscapeAI | 25/6/2026 | 25/6/2026 | Horner Automation Cscape versions prior to 10.2 SP3 are vulnerable to an Out-of-Bounds Read vulnerability through parsing CSP files. Successful exploitation of this vulnerability could allow an attacker to disclose information and execute arbitrary code. | |
| Aplazada | Alta (8.4) | 0.29% | — | Hornerautomation CscapeAI | 8/5/2025 | 17/6/2026 | Horner Automation Cscape version 10.0 (10.0.415.2) SP1 is vulnerable to an out-of-bounds read vulnerability that could allow an attacker to disclose information and execute arbitrary code on affected installations of Cscape. | |
| Aplazada | Alta (8.5) | 0.19% | — | Hornerautomation CscapeAI | 13/12/2024 | 17/6/2026 | Horner Automation Cscape contains a memory corruption vulnerability, which could allow an attacker to disclose information and execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.21% | — | Hornerautomation Cscape | 15/1/2024 | 17/6/2026 | In Horner Automation Cscape versions 9.90 SP10 and prior, local attackers are able to exploit this vulnerability if a user opens a malicious CSP file, which would result in execution of arbitrary code on affected installations of Cscape. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e374b. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected product does not properly validate user-supplied data. If a user opens a maliciously formed CSP file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a stack-based buffer overflow. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.24% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to a use-after-free vulnerability. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing font files (e.g., FNT). This could lead to an out-of-bounds read. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | Horner Automation Cscape lacks proper validation of user-supplied data when parsing project files (e.g., HMI). This could lead to an out-of-bounds write at CScape_EnvisionRV+0x2e3c04. An attacker could leverage this vulnerability to potentially execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g.., CSP). This could lead to an out-of-bounds read in IO_CFG. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in the FontManager. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation CscapeHornerautomation Cscape Envisionrv | 6/6/2023 | 17/6/2026 | The affected application lacks proper validation of user-supplied data when parsing project files (e.g., CSP). This could lead to an out-of-bounds read in Cscape!CANPortMigration. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process. | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds write vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in writes past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.23% | — | Hornerautomation Cscape Envision RV | 9/3/2023 | 17/6/2026 | Cscape Envision RV version 4.60 is vulnerable to an out-of-bounds read vulnerability when parsing project (i.e. HMI) files. The product lacks proper validation of user-supplied data, which could result in reads past the end of allocated data structures. An attacker could leverage these vulnerabilities to execute… | |
| Modificada | Alta (7.8) | 0.25% | — | Hornerautomation Cscape | 15/11/2022 | 17/6/2026 | Horner Automation's Cscape version 9.90 SP 6 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory read. | |
| Modificada | Alta (7.8) | 0.24% | — | Hornerautomation Cscape | 27/10/2022 | 17/6/2026 | Horner Automation's Cscape version 9.90 SP7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by writing outside the memory buffer. | |
| Modificada | Alta (7.8) | 0.25% | — | Hornerautomation Cscape | 27/10/2022 | 17/6/2026 | Horner Automation's Cscape version 9.90 SP 7 and prior does not properly validate user-supplied data. If a user opens a maliciously formed FNT file, then an attacker could execute arbitrary code within the current process by accessing an uninitialized pointer, leading to an out-of-bounds memory write. | |
| Modificada | Alta (7.8) | 1.0% | — | Hornerautomation Cscape | 2/6/2022 | 17/6/2026 | The affected product is vulnerable to a heap-based buffer overflow via uninitialized pointer, which may allow an attacker to execute arbitrary code | |
| Modificada | Alta (7.8) | 0.91% | — | Hornerautomation Cscape | 2/6/2022 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds read via uninitialized pointer, which may allow an attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.91% | — | Hornerautomation Cscape | 2/6/2022 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds write via uninitialized pointer, which may allow an attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.89% | — | Hornerautomation Cscape | 2/6/2022 | 17/6/2026 | The affected product is vulnerable to an out-of-bounds write, which may allow an attacker to execute arbitrary code. | |
| Modificada | Alta (7.1) | 0.71% | — | Hornerautomation Cscape Envisionrv | 25/3/2022 | 17/6/2026 | This vulnerability can be exploited by parsing maliciously crafted project files with Horner Automation Cscape EnvisionRV v4.50.3.1 and prior. The issues result from the lack of proper validation of user-supplied data, which can result in reads and writes past the end of allocated data structures. User interaction is… |