Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaCrítica (9.8)0.75%—Yokogawa Gx10AIYokogawa Gx20AIYokogawa Gp10AIYokogawa Gp20AI+1218/4/202517/6/2026
Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the affected products. Therefore, when connected to a network with default settings, anyone can access all functions related to settings and…
ModificadaCrítica (9.8)2.7%—Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware11/6/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-22767
ModificadaCrítica (9.8)2.7%—Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware11/6/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-2276
ModificadaAlta (7.5)1.3%—Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware11/6/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafted HTTP packet
ModificadaCrítica (9.8)2.7%—Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware11/6/202117/6/2026
A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet