Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.8) | 0.75% | — | Yokogawa Gx10AIYokogawa Gx20AIYokogawa Gp10AIYokogawa Gp20AI+12 | 18/4/2025 | 17/6/2026 | Insecure default settings have been found in recorder products provided by Yokogawa Electric Corporation. The default setting of the authentication function is disabled on the affected products. Therefore, when connected to a network with default settings, anyone can access all functions related to settings and… | |
| Modificada | Crítica (9.8) | 2.7% | — | Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware | 11/6/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-22767 | |
| Modificada | Crítica (9.8) | 2.7% | — | Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware | 11/6/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet.This CVE ID is unique from CVE-2021-2276 | |
| Modificada | Alta (7.5) | 1.3% | — | Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware | 11/6/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service via a specially crafted HTTP packet | |
| Modificada | Crítica (9.8) | 2.7% | — | Schneider-electric Powerlogic Egx100 FirmwareSchneider-electric Powerlogic Egx300 Firmware | 11/6/2021 | 17/6/2026 | A CWE-20: Improper Input Validation vulnerability exists in PowerLogic EGX100 (Versions 3.0.0 and newer) and PowerLogic EGX300 (All Versions) that could cause denial of service or remote code execution via a specially crafted HTTP packet |