Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2738▲ 10 respecto a la semana anterior
Críticas / altas1458▲ 322 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
30 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.8) | 0.18% | — | Omron Cx-programmerAI | 17/2/2025 | 17/6/2026 | Out-of-bounds Read vulnerability (CWE-125) was found in CX-Programmer. Attackers may be able to read sensitive information or cause an application crash by abusing this vulnerability. | |
| Aplazada | Alta (7.8) | 0.24% | — | Omron Cx-oneAIOmron Cx-programmerAI | 1/5/2024 | 17/6/2026 | Out-of-bounds read vulnerability exists in CX-Programmer included in CX-One CXONE-AL[][]D-V4 Ver. 9.81 or lower. Opening a specially crafted project file may lead to information disclosure and/or the product being crashed. | |
| Modificada | Alta (7.8) | 0.24% | — | Omron Cx-programmer | 3/8/2023 | 17/6/2026 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22317 and CVE-2023-22314. | |
| Modificada | Alta (7.8) | 0.24% | — | Omron Cx-programmer | 3/8/2023 | 17/6/2026 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22314. | |
| Modificada | Alta (7.8) | 0.24% | — | Omron Cx-programmer | 3/8/2023 | 17/6/2026 | Use after free vulnerability exists in CX-Programmer Ver.9.79 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. This vulnerability is different from CVE-2023-22277 and CVE-2023-22317. | |
| Modificada | Alta (7.8) | 0.22% | — | Omron Cx-programmer | 3/8/2023 | 17/6/2026 | Use after free vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. | |
| Modificada | Alta (7.8) | 0.24% | — | Omron Cx-programmer | 3/8/2023 | 17/6/2026 | Heap-based buffer overflow vulnerability exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. | |
| Modificada | Alta (7.8) | 0.22% | — | Omron Cx-programmer | 3/8/2023 | 17/6/2026 | Out-of-bounds read vulnerability/issue exists in CX-Programmer Included in CX-One CXONE-AL[][]D-V4 V9.80 and earlier. By having a user open a specially crafted CXP file, information disclosure and/or arbitrary code execution may occur. | |
| Modificada | Alta (7.8) | 0.28% | — | Omron Cx-programmer | 7/12/2022 | 17/6/2026 | Stack-based buffer overflow vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. | |
| Modificada | Alta (7.8) | 0.25% | — | Omron Cx-programmer | 7/12/2022 | 17/6/2026 | Out-of-bounds write vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. | |
| Modificada | Alta (7.8) | 0.26% | — | Omron Cx-programmer | 7/12/2022 | 17/6/2026 | Use-after free vulnerability exists in CX-Programmer v.9.77 and earlier, which may lead to information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. | |
| Modificada | Crítica (9.8) | 0.61% | — | Omron Cx-programmer | 6/10/2022 | 17/6/2026 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.61% | — | Omron Cx-programmer | 6/10/2022 | 17/6/2026 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. | |
| Modificada | Crítica (9.8) | 0.61% | — | Omron Cx-programmer | 6/10/2022 | 17/6/2026 | OMRON CX-Programmer 9.78 and prior is vulnerable to an Out-of-Bounds Write, which may allow an attacker to execute arbitrary code. | |
| Modificada | Alta (7.8) | 0.25% | — | Omron Cx-programmer | 12/9/2022 | 17/6/2026 | Opening a specially crafted file could cause the affected product to fail to release its memory reference potentially resulting in arbitrary code execution. | |
| Modificada | Alta (7.5) | 0.65% | — | Omron Sysmac CS1 FirmwareOmron Sysmac Cj2m FirmwareOmron Sysmac Cj2h FirmwareOmron Sysmac Cp1e Firmware+4 | 26/7/2022 | 17/6/2026 | Omron CS series, CJ series, and CP series PLCs through 2022-05-18 use cleartext passwords. They feature a UM Protection setting that allows users or system integrators to configure a password in order to restrict sensitive engineering operations (such as project/logic uploads and downloads). This password is set using… | |
| Modificada | Alta (7.8) | 1.1% | — | Omron Cx-programmer | 10/3/2022 | 17/6/2026 | Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25230. | |
| Modificada | Alta (7.8) | 1.0% | — | Omron Cx-programmer | 10/3/2022 | 17/6/2026 | Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-21124. | |
| Modificada | Alta (7.8) | 1.1% | — | Omron Cx-programmer | 10/3/2022 | 17/6/2026 | Use after free vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25325. | |
| Modificada | Alta (7.8) | 1.0% | — | Omron Cx-programmer | 10/3/2022 | 17/6/2026 | Out-of-bounds read vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. | |
| Modificada | Alta (7.8) | 1.5% | — | Omron Cx-programmer | 10/3/2022 | 17/6/2026 | Out-of-bounds write vulnerability in CX-Programmer v9.76.1 and earlier which is a part of CX-One (v4.60) suite allows an attacker to cause information disclosure and/or arbitrary code execution by having a user to open a specially crafted CXP file. This vulnerability is different from CVE-2022-25234. | |
| Modificada | Media (6.6) | 1.2% | — | Omron Common ComponentsOmron Cx-programmer | 10/4/2019 | 17/6/2026 | When processing project files, the application (Omron CX-Programmer v9.70 and prior and Common Components January 2019 and prior) fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of the application. | |
| Modificada | Alta (7.8) | 1.8% | — | Omron Cx-oneOmron Cx-programmerOmron Cx-server | 4/12/2018 | 17/6/2026 | Two stack-based buffer overflow vulnerabilities have been discovered in CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior). When processing project files, the application allows input data to exceed the buffer. An attacker could use a specially crafted… | |
| Modificada | Alta (7.8) | 1.6% | — | Omron Cx-oneOmron Cx-programmerOmron Cx-server | 4/12/2018 | 17/6/2026 | In CX-One Versions 4.42 and prior (CX-Programmer Versions 9.66 and prior and CX-Server Versions 5.0.23 and prior), when processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute code under the privileges of… | |
| Modificada | Alta (7.8) | 0.32% | — | Omron Cx-flnetOmron Cx-oneOmron Cx-programmerOmron Cx-protocol+3 | 17/4/2018 | 17/6/2026 | Parsing malformed project files in Omron CX-One versions 4.42 and prior, including the following applications: CX-FLnet versions 1.00 and prior, CX-Protocol versions 1.992 and prior, CX-Programmer versions 9.65 and prior, CX-Server versions 5.0.22 and prior, Network Configurator versions 3.63 and prior, and Switch Box… |