Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
–

130 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (8.7)0.43%—Allen Bradley LogixAI1/9/20261/9/2026
A denial-of-service security issue exists in the affected Logix platforms listed in the table above. The security issue stems from improper validation of input length during CIP message processing. This can result in a major nonrecoverable fault (MNRF), requiring a power cycle to recover
Pendiente de análisisAlta (8.2)0.22%—Allen Bradley Compactlogix 5380AIAllen Bradley Controllogix 5580AIAllen Bradley EN4 Communication ModuleAI14/7/202614/7/2026
A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate certificate that has been revoked via a…
AnalizadaAlta (7.3)0.17%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to…
AnalizadaAlta (7.3)0.15%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a…
AnalizadaMedia (5.4)0.18%—Rockwellautomation Studio 5000 Logix Designer14/7/202625/8/2026
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the…
Pendiente de análisisMedia (6.3)0.45%—Rockwellautomation CompactlogixAI16/6/202617/6/2026
A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can be leveraged by an attacker to construct…
Pendiente de análisisAlta (8.7)0.17%—Allen Bradley Compactlogix 1769AI16/6/202630/9/2026
A security issue exists within 1769 CompactLogix controllers due to the missing validation of sequence numbers and source IP addresses in the CIP protocol. This allows attacker to abuse the exposed Connection ID’s visible on the web interface to perform denial-of-service attacks, resulting in a minor fault.
AplazadaMedia (5.3)0.30%—Glowlogix WP Frontend ProfileAI8/4/202624/7/2026
Missing Authorization vulnerability in Glowlogix WP Frontend Profile wp-front-end-profile allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects WP Frontend Profile: from n/a through <= 1.3.9.
AplazadaMedia (5.3)0.26%—Agilelogix Post TimelineAI13/3/202617/6/2026
Missing Authorization vulnerability in Agile Logix Post Timeline post-timeline allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Post Timeline: from n/a through <= 2.4.1.
AplazadaAlta (8.5)0.21%—Rockwell Factorytalk Activation ServiceAIRockwellautomation Studio 5000 Logix DesignerAI5/2/202617/6/2026
Studio 5000 Logix Designer 30.01.00 contains an unquoted service path vulnerability in the FactoryTalk Activation Service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in C:\Program Files (x86)\Rockwell Software\FactoryTalk Activation\ to inject…
AplazadaAlta (8.5)0.30%—Agilelogix Store LocatorAI9/12/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Blind SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.6.2.
AplazadaAlta (8.7)0.37%—Rockwellautomation Studio 5000 Logix DesignerAIRockwellautomation Armorstart ClassicAI14/10/202517/6/2026
A security issue exists within the Studio 5000 Logix Designer add-on profile (AOP) for the ArmorStart Classic distributed motor controller, resulting in denial-of-service. This vulnerability is possible due to the input of invalid values into Component Object Model (COM) methods.
AnalizadaAlta (8.7)0.29%—Rockwellautomation Factorytalk Analytics Logixai9/9/20251/10/2026
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.
AnalizadaAlta (8.2)0.41%—Rockwellautomation Controllogix 5580 Firmware9/9/20251/10/2026
A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable fault on the controller.
AplazadaCrítica (9.3)0.37%—Rockwellautomation CompactlogixAI18/8/202517/6/2026
A security issue exists due to improper handling of malformed CIP Forward Close packets during fuzzing. The controller enters a solid red Fault LED state and becomes unresponsive. Upon power cycle, the controller will enter recoverable fault where the MS LED and Fault LED become flashing red and reports fault code…
AplazadaAlta (7.3)0.13%—Rockwellautomation Studio 5000 Logix DesignerAI14/8/202517/6/2026
A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the specified path lacks a valid file, Logix Designer crashes; However, it may be possible to execute malicious code without triggering a crash.
AplazadaCrítica (9.3)0.85%—Rockwellautomation Controllogix Ethernet ModulesAI14/8/202517/6/2026
A security issue exists due to the web-based debugger agent enabled on Rockwell Automation ControlLogix® Ethernet Modules. If a specific IP address is used to connect to the WDB agent, it can allow remote attackers to perform memory dumps, modify memory, and control execution flow.
AplazadaMedia (6.6)0.27%—Agilelogix Agile Store LocatorAI6/6/202517/6/2026
Unrestricted Upload of File with Dangerous Type vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows Upload a Web Shell to a Web Server.This issue affects Store Locator WordPress: from n/a through <= 1.5.2.
AplazadaAlta (7.6)0.35%—Agilelogix Store LocatorAI6/6/202517/6/2026
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Agile Logix Store Locator WordPress agile-store-locator allows SQL Injection.This issue affects Store Locator WordPress: from n/a through <= 1.5.1.
AplazadaAlta (7.1)0.31%—Wisdomlogix Solutions PVT LTD Fonts Manager Custom FontsAI1/4/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Wisdomlogix Solutions Pvt. Ltd. Fonts Manager | Custom Fonts fonts-manager-custom-fonts allows Reflected XSS.This issue affects Fonts Manager | Custom Fonts: from n/a through <= 1.2.
AnalizadaAlta (7.1)0.35%—Agilelogix Post Timeline26/2/202517/6/2026
The Post Timeline WordPress plugin before 2.3.10 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaAlta (7.1)0.26%—Agilelogix Post TimelineAI14/2/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agile Logix Post Timeline post-timeline allows Reflected XSS.This issue affects Post Timeline: from n/a through <= 2.3.9.
AplazadaMedia (6.5)0.28%—Agilelogix Free Google MapsAI15/1/202517/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Agile Logix Free Google Maps wp-map allows Stored XSS.This issue affects Free Google Maps: from n/a through <= 1.0.1.
AnalizadaAlta (8.7)0.55%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Controllogix 5580 Process FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 Firmware+414/10/202417/6/2026
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To…
AnalizadaAlta (8.8)0.18%—Rockwellautomation Rslogix 5Rockwellautomation Rslogix 500Rockwellautomation Rslogix Micro DeveloperRockwellautomation Rslogix Micro Starter Lite14/10/202417/6/2026
VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following vulnerabilities were reported to us by Sharon Brizinov of Claroty Research - Team82. A feature in the affected products enables users to prepare a project file with an…