Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2676▼ 422 respecto a la semana anterior
Críticas / altas1295▼ 73 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.90%—APC Network Management Card 4AI11/12/202517/6/2026
APC Network Management Card 4 contains a path traversal vulnerability that allows unauthenticated attackers to access sensitive system files by manipulating URL parameters. Attackers can exploit directory traversal techniques to read critical system files like /etc/passwd by using encoded path traversal characters in…
ModificadaAlta (8)0.77%—Schneider-electric Rack Power Distribution Unit With Network Management Card 2 FirmwareSchneider-electric Rack Power Distribution Unit With Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-200: Exposure of Sensitive Information to an Unauthorized Actor vulnerability exists that could allow an attacker to access the system with elevated privileges when a privileged account clicks on a malicious URL that compromises the security token. Affected Products: AP7xxxx and AP8xxx with NMC2 (V6.9.6 or…
ModificadaMedia (5.3)0.77%—Schneider-electric Network Management Card 2 FirmwareSchneider-electric Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-200: Information Exposure vulnerability exists which could cause the troubleshooting archive to be accessed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including Smart-UPS, Symmetra, and Galaxy 3500 with Network Management Card 2 (NMC2): AP9630/AP9630CH/AP9630J,…
ModificadaMedia (6.1)0.74%—Schneider-electric Network Management Card 2 FirmwareSchneider-electric Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists which could cause arbritrary script execution when a malicious file is read and displayed. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2 including Smart-UPS, Symmetra, and…
ModificadaMedia (6.1)0.74%—Schneider-electric Network Management Card 2 FirmwareSchneider-electric Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to an edit policy file. Affected Products: 1-Phase…
ModificadaMedia (6.1)0.74%—Schneider-electric Network Management Card 2 FirmwareSchneider-electric Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2…
ModificadaMedia (6.1)0.74%—Schneider-electric Network Management Card 2 FirmwareSchneider-electric Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause script execution when the request of a privileged account accessing the vulnerable web page is intercepted. Affected Products: 1-Phase Uninterruptible Power Supply (UPS) using NMC2…
ModificadaMedia (6.1)0.75%—Schneider-electric Network Management Card 2 FirmwareSchneider-electric Network Management Card 3 Firmware28/1/202217/6/2026
A CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability exists that could cause arbritrary script execution when a privileged account clicks on a malicious URL specifically crafted for the NMC pointing to a delete policy file. Affected Products: 1-Phase…
ModificadaCrítica (9.8)0.84%—Schneider-electric 66074 MGE Network Management Card Transverse18/4/201817/6/2026
A cleartext transmission of sensitive information vulnerability exists in Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. he integrated web server (Port 80/443/TCP) of the affected devices could allow remote attackers to discover an administrative account. If default…
ModificadaCrítica (9.1)1.2%—Schneider-electric 66074 MGE Network Management Card Transverse18/4/201817/6/2026
An improper authorization vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to change UPS control and shutdown parameters or other critical…
ModificadaMedia (5.3)1.0%—Schneider-electric 66074 MGE Network Management Card Transverse18/4/201817/6/2026
An information disclosure vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to obtain sensitive device information if network access was obtained.
ModificadaCrítica (9.8)2.8%—Schneider-electric 66074 MGE Network Management Card Transverse18/4/201817/6/2026
An authorization bypass vulnerability exists In Schneider Electric's 66074 MGE Network Management Card Transverse installed in MGE UPS and MGE STS. The integrated web server (Port 80/443/TCP) of the affected devices could allow a remote attacker to get a full access to device, bypassing the authorization system.
ModificadaMedia (4.3)2.0%—APC Network Management CardAPC Switched Rack PDU28/12/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. NOTE: the login_username…
ModificadaMedia (6.8)0.67%—APC Network Management CardAPC Switched Rack PDU28/12/200916/6/2026
Multiple cross-site request forgery (CSRF) vulnerabilities on the Network Management Card (NMC) on American Power Conversion (APC) Switched Rack PDU (aka Rack Mount Power Distribution) devices and other devices allow remote attackers to hijack the authentication of (1) administrator or (2) device users for requests…