Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2636▼ 212 respecto a la semana anterior
Críticas / altas1386▲ 155 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
68 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.1) | 0.50% | — | Embedded-solutions FreemodbusAI | 5/8/2026 | 26/8/2026 | The LINUXTCP port of FreeModbus contains an off-by-one bounds check in xMBPortTCPPool (demo/LINUXTCP/port/porttcp.c). The check uses a strict greater-than comparison instead of greater-than-or-equal against the 263-byte MB_TCP_BUF_SIZE limit. | |
| Aplazada | Crítica (9.8) | 0.55% | — | NanomodbusAI | 5/8/2026 | 26/8/2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds stack read leading to a wild-pointer write in nmbs_read_device_identification_basic / recv_read_device_identification_res in nanomodbus.c. A fixed 3-element stack array order[3] = {0,1,2} maps object IDs to buffer indices. The server-supplied object_id field (0-255,… | |
| Aplazada | Alta (8.6) | 0.39% | — | NanomodbusAI | 5/8/2026 | 26/8/2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus client-side recv_read_device_identification_res function (FC 0x2B/MEI 0x0E, Read Device Identification) in nanomodbus.c. The server-supplied object_length field (0-246) is validated only against the remaining PDU size (res_size_left) and is never… | |
| Aplazada | Crítica (9.8) | 0.55% | — | NanomodbusAI | 5/8/2026 | 26/8/2026 | nanoMODBUS through v1.23.0 contains an out-of-bounds write in the Modbus server-side handle_read_file_record function (FC 0x14, Read File Record) in nanomodbus.c. The function validates that the total request size does not exceed 245 bytes and that each sub-request's record_length is at most 124, but it never… | |
| Aplazada | Alta (8.7) | 0.56% | — | Charx Modbus ServerAI | 30/7/2026 | 30/7/2026 | A reboot of the charging controller can be triggered via Modbus TCP without authentication. Therefore, when the Modbus functionality is enabled by opening the port that CharxModbusServer is listening, an unauthenticated attacker can perform a Denial-of-Service attack. | |
| Aplazada | Alta (7.5) | 0.49% | — | LibmodbusAI | 13/7/2026 | 15/7/2026 | A Denial of Service (DoS) vulnerability exists in the receive loop of libmodbus 3.1.12 when running on Windows. The issue stems from improper timeout management during network read operations. | |
| Pendiente de análisis | Alta (8.2) | 0.54% | — | Codesys Modbus TCP ServerAI | 12/5/2026 | 17/6/2026 | An unauthenticated remote attacker may exhaust all available TCP connections in the CODESYS Modbus TCP Server stack if a race condition in connection handling is successfully exploited, preventing legitimate clients from establishing new connections. | |
| Aplazada | Alta (8.2) | 0.92% | — | NanomodbusAI | 8/5/2026 | 17/6/2026 | nanoMODBUS through v1.22.0 has a stack-based buffer overflow in recv_read_registers_res() in nanomodbus.c. When a client calls nmbs_read_holding_registers() or nmbs_read_input_registers(), the library writes register data from the server response to the caller-provided buffer based on the response's byte_count field… | |
| Pendiente de análisis | Crítica (9.3) | 0.20% | — | 3onedata Modbus Gateway Gw1101-1dAI | 4/5/2026 | 30/9/2026 | 3onedata modbus gateway device model GW1101-1D(RS-485)-TB-P (hardware version V2.2.0) allows authenticated users to execute arbitrary shell commands in the context of the root user by providing payload in the "IP address" field of the diagnosis test tools. This issue has been resolved in firmware version… | |
| Aplazada | Alta (7.5) | 0.51% | — | ModbusAI | 2/2/2026 | 17/6/2026 | An unauthenticated remote attacker could potentially disrupt operations by switching between multiple configuration presets via Modbus (TCP). | |
| Aplazada | Media (5.3) | 1.6% | — | ModbusAI | 14/10/2025 | 17/6/2026 | An unauthanticated remote attacker can perform a DoS of the Modbus service by sending a specific function and sub-function code without affecting the core functionality. | |
| Aplazada | Alta (7.5) | 0.34% | — | Embedded-solutions FreemodbusAI | 14/8/2025 | 17/6/2026 | An issue was discovered in the demo/LINUXTCP implementation of cwalter-at freemodbus v.2018-09-12 allowing attackers to reach an infinite loop via a crafted length value for a packet. | |
| Modificada | Crítica (9.8) | 0.56% | — | Libmodbus | 27/2/2025 | 1/8/2026 | Stack-based Buffer Overflow vulnerability in libmodbus v3.1.10 allows to overflow the buffer allocated for the Modbus response if the function tries to reply to a Modbus request with an unexpected length. | |
| Aplazada | Alta (8.8) | 0.68% | — | ModbusmechanicAI | 21/11/2024 | 5/7/2026 | An arbitrary file upload vulnerability in ModbusMechanic v3.0 allows attackers to execute arbitrary code via uploading a crafted .xml file. | |
| Analizada | Alta (7.1) | 0.38% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use a reflected XSS vulnerability to obtain information from a user or reboot the affected device once. | |
| Analizada | Alta (7.1) | 0.34% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use stored XSS vulnerability to obtain information from a user or reboot the affected device once. | |
| Analizada | Media (6.1) | 0.33% | — | Pepperl-fuchs Icdm-rx/tcp Socketserver FirmwarePepperl-fuchs Profinet FirmwarePepperl-fuchs Profinet/modbus FirmwarePepperl-fuchs Modbus Router Firmware+4 | 13/8/2024 | 17/6/2026 | An unauthenticated remote attacker may use a HTML injection vulnerability with limited length to inject malicious HTML code and gain low-privileged access on the affected device. | |
| Modificada | Alta (7.5) | 0.55% | — | Embedded-solutions Freemodbus | 8/7/2024 | 17/6/2026 | Buffer Overflow vulnerability in SILA Embedded Solutions GmbH freemodbus v.2018-09-12 allows a remtoe attacker to cause a denial of service via the LINUXTCP server component. | |
| Modificada | Media (4.3) | 0.47% | — | Libmodbus | 31/5/2024 | 17/6/2026 | An invalid pointer in the modbus_receive() function of libmodbus v3.1.6 allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. | |
| Modificada | Alta (7.5) | 0.61% | — | Libmodbus | 31/5/2024 | 17/6/2026 | libmodbus v3.1.6 was discovered to contain a use-after-free via the ctx->backend pointer. This vulnerability allows attackers to cause a Denial of Service (DoS) via a crafted message sent to the unit-test-server. | |
| Modificada | Alta (7.5) | 0.79% | — | Libmodbus | 31/5/2024 | 17/6/2026 | libmodbus v3.1.6 was discovered to contain a heap overflow via the modbus_mapping_free() function. | |
| Analizada | Alta (7.5) | 0.52% | — | Libmodbus | 8/5/2024 | 17/6/2026 | libmodbus v3.1.10 is vulnerable to Buffer Overflow via the modbus_write_bits function. This issue can be triggered when the function is fed with specially crafted input, which leads to out-of-bounds read and can potentially cause a crash or other unintended behaviors. | |
| Analizada | Crítica (9.8) | 0.73% | — | Libmodbus | 1/5/2024 | 17/6/2026 | libmodbus v3.1.10 has a heap-based buffer overflow vulnerability in read_io_status function in src/modbus.c. | |
| Modificada | Alta (7.5) | 1.2% | — | Opcfoundation UA Java LegacyProsysopc UA HistorianProsysopc UA Modbus ServerProsysopc UA Simulation Server | 15/5/2023 | 17/6/2026 | The OPC UA Legacy Java Stack before 6f176f2 enables an attacker to block OPC UA server applications via uncontrolled resource consumption so that they can no longer serve client applications. | |
| Modificada | Media (4.3) | 0.85% | — | Rockwellautomation Modbus TCP Server ADD ON Instructions | 17/3/2023 | 17/6/2026 | Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP… |