Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.3)0.18%—Schneider-electric Pro-face Gp-pro EX9/8/202317/6/2026
A CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability exists that could cause memory corruption when an authenticated user opens a tampered log file from GP-Pro EX.
ModificadaAlta (7.8)0.33%—Schneider-electric Gp-pro EX2/9/202117/6/2026
A CWE-427: Uncontrolled Search Path Element vulnerability exists in GP-Pro EX,V4.09.250 and prior, that could cause local code execution with elevated privileges when installing the software.
ModificadaMedia (6.5)1.1%—Schneider-electric Gp-pro EX Firmware16/6/202017/6/2026
A CWE-521: Weak Password Requirements vulnerability exists in the GP-Pro EX V1.00 to V4.09.100 which could cause the discovery of the password when the user is entering the password because it is not masqueraded.
ModificadaAlta (8.8)2.2%—Schneider-electric Pro-face Gp-pro EX24/12/201817/6/2026
An Improper Input Validation vulnerability exists in Pro-Face GP-Pro EX v4.08 and previous versions which could cause the execution arbitrary executable when GP-Pro EX is launched.
ModificadaMedia (6.5)2.3%—Schneider-electric Proface Gp-pro EX Ex-edSchneider-electric Proface Gp-pro EX PfxexedlsSchneider-electric Proface Gp-pro EX PfxexedvSchneider-electric Proface Gp-pro EX Pfxexgrpls6/4/201617/6/2026
Stack-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.5)2.2%—Schneider-electric Proface Gp-pro EX Ex-edSchneider-electric Proface Gp-pro EX PfxexedlsSchneider-electric Proface Gp-pro EX PfxexedvSchneider-electric Proface Gp-pro EX Pfxexgrpls6/4/201617/6/2026
Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allow remote attackers to execute arbitrary code or cause a denial of service (out-of-bounds read) via unspecified vectors.
ModificadaAlta (8.8)2.3%—Schneider-electric Proface Gp-pro EX Ex-edSchneider-electric Proface Gp-pro EX PfxexedlsSchneider-electric Proface Gp-pro EX PfxexedvSchneider-electric Proface Gp-pro EX Pfxexgrpls6/4/201617/6/2026
Heap-based buffer overflow in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaCrítica (9.1)2.0%—Schneider-electric Proface Gp-pro EX Ex-edSchneider-electric Proface Gp-pro EX PfxexedlsSchneider-electric Proface Gp-pro EX PfxexedvSchneider-electric Proface Gp-pro EX Pfxexgrpls6/4/201617/6/2026
The FTP server in Pro-face GP-Pro EX EX-ED before 4.05.000, PFXEXEDV before 4.05.000, PFXEXEDLS before 4.05.000, and PFXEXGRPLS before 4.05.000 has hardcoded credentials, which makes it easier for remote attackers to bypass authentication by leveraging knowledge of these credentials.
Orbitaley — Vulnerabilidades