Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2684▼ 80 respecto a la semana anterior
Críticas / altas1442▲ 302 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
25 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Media (5.3) | 0.27% | — | Autonomy Logic Openplc 3AI | 22/9/2026 | 23/9/2026 | Autonomy Logic OpenPLC 3 is susceptible to an improper neutralization of input during web page generation vulnerability when the web interface attempts to route the program based on a query string parameter with no encoding. | |
| Aplazada | Crítica (9.9) | 0.58% | — | Openplc RuntimeAI | 5/8/2026 | 26/8/2026 | OpenPLC Runtime v3's compile_program function (webserver/openplc.py) parses directives from uploaded Structured Text (.st) program files and writes the referenced content to with no validation that file_path stays within the ./core directory. A path-validation function, validate_file_path, exists elsewhere in the… | |
| Aplazada | Alta (8.7) | 0.75% | — | Openplc V3AI | 18/7/2026 | 23/7/2026 | OpenPLC_v3 contains a heap-based buffer overflow in the getData() function in webserver/core/modbus_master.cpp. getData() reads characters between two delimiters into a caller-supplied buffer with no size parameter and no bounds check. In parseConfig() the function is invoked with the 100-byte heap-allocated… | |
| Aplazada | Alta (8.7) | 0.62% | — | Openplc RuntimeAI | 10/7/2026 | 13/7/2026 | OpenPLC Runtime v3 contains an authenticated arbitrary file write vulnerability in the legacy web UI program‑upload workflow. The application stores an attacker‑supplied filename (prog_file) directly into the Programs.File database field and later uses this value as the destination path for an uploaded file without… | |
| Modificada | Media (6.5) | 0.46% | — | Openplcproject Openplc V3 Firmware | 13/5/2026 | 5/7/2026 | A path injection vulnerability exists in OpenPLC v3 (2c82b0e79c53f8c1f1458eee15fec173400d6e1a) as the binary program compiled from glue_generator.cpp does not perform any validation on the file path parameters passed via the command line. The user-controlled input parameters are directly passed to the underlying file… | |
| Analizada | Alta (8.7) | 0.43% | — | Openplcproject Openplc V3 Firmware | 9/4/2026 | 17/6/2026 | OpenPLC_V3 REST API endpoint checks for JWT presence but never verifies the caller's role. Any authenticated user with role=user can delete any other user, including administrators, by specifying their user ID or they can create new accounts with role=admin, escalating to full administrator access. | |
| Analizada | Crítica (9.2) | 0.40% | — | Openplcproject Openplc V3 Firmware | 9/4/2026 | 17/6/2026 | OpenPLC_V3 is vulnerable to a Plaintext Storage of a Password vulnerability that could allow an attacker to retrieve credentials and access sensitive information. | |
| Analizada | Crítica (9.2) | 0.67% | — | Openplcproject Openplc V3 Firmware | 9/4/2026 | 17/6/2026 | OpenPLC_V3 is vulnerable to an Initialization of a Resource with an Insecure Default vulnerability which could allow an attacker to gain access to the system by bypassing authentication via an API. | |
| Aplazada | Alta (8.6) | 0.74% | — | Openplcproject OpenplcAI | 21/1/2026 | 17/6/2026 | OpenPLC v3 contains an authenticated remote code execution vulnerability that allows attackers with valid credentials to inject malicious code through the hardware configuration interface. Attackers can upload a custom hardware layer with embedded reverse shell code that establishes a network connection to a specified… | |
| Aplazada | Alta (7) | 0.29% | — | Openplc V3AI | 13/12/2025 | 17/6/2026 | OpenPLC_V3 is vulnerable to a cross-site request forgery (CSRF) attack due to the absence of proper CSRF validation. This issue allows an unauthenticated attacker to trick a logged-in administrator into visiting a maliciously crafted link, potentially enabling unauthorized modification of PLC settings or the upload of… | |
| Aplazada | Media (5.3) | 0.46% | — | Openplcproject OpenplcAI | 7/10/2025 | 17/6/2026 | A denial of service vulnerability exists in the ModbusTCP server functionality of OpenPLC _v3 a931181e8b81e36fadf7b74d5cba99b73c3f6d58. A specially crafted series of network connections can lead to the server not processing subsequent Modbus requests. An attacker can open a series of TCP connections to trigger this… | |
| Aplazada | Alta (7.1) | 0.66% | — | Openplc RuntimeAI | 3/10/2025 | 17/6/2026 | OpenPLC Runtime v3 contains an input validation flaw in the /upload-program-action endpoint: the epoch_time field supplied during program uploads is not validated and can be crafted to induce corruption of the programs database. After a successful malformed upload the runtime continues to operate until a restart; on… | |
| Aplazada | Media (6.1) | 0.21% | — | Openplc V3AI | 1/10/2025 | 17/6/2026 | OpenPLC_V3 has a vulnerability in the enipThread function that occurs due to the lack of a return value. This leads to a crash when the server loop ends and execution hits an illegal ud2 instruction. This issue can be triggered remotely without authentication by starting the same server multiple times or if the server… | |
| Aplazada | Media (6.4) | 0.24% | — | Openplc RuntimeAI | 4/8/2025 | 17/6/2026 | /edit-user in webserver in OpenPLC Runtime 3 through 9cd8f1b allows authenticated users to upload arbitrary files (such as .html or .svg), and these are then publicly accessible under the /static URI. | |
| Aplazada | Alta (7.5) | 0.24% | — | Openplcproject OpenplcAI | 25/4/2025 | 17/6/2026 | OpenPLC 3 through 64f9c11 has server.cpp Memory Corruption because a thread may access handleConnections arguments after the parent stack frame becomes unavailable. | |
| Aplazada | Crítica (9.8) | 0.46% | — | Openplc V3AI | 6/2/2025 | 17/6/2026 | OpenPLC_V3 contains an arbitrary file upload vulnerability, which could be leveraged for malvertising or phishing campaigns. | |
| Modificada | Alta (7.5) | 1.0% | — | Openplcproject Openplc V3 Firmware | 18/9/2024 | 17/6/2026 | Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these… | |
| Modificada | Alta (7.5) | 1.0% | — | Openplcproject Openplc V3 Firmware | 18/9/2024 | 17/6/2026 | Multiple invalid pointer dereference vulnerabilities exist in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC_v3 16bf8bac1a36d95b73e7b8722d0edb8b9c5bb56a. A specially crafted EtherNet/IP request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger these… | |
| Modificada | Alta (7.5) | 1.0% | — | Openplcproject Openplc V3 Firmware | 18/9/2024 | 17/6/2026 | An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.This is… | |
| Modificada | Alta (7.5) | 1.1% | — | Openplcproject Openplc V3 Firmware | 18/9/2024 | 17/6/2026 | An out-of-bounds read vulnerability exists in the OpenPLC Runtime EtherNet/IP PCCC parser functionality of OpenPLC_v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted network request can lead to denial of service. An attacker can send a series of EtherNet/IP requests to trigger this vulnerability.This is… | |
| Modificada | Crítica (9.8) | 2.4% | — | Openplcproject Openplc V3 Firmware | 18/9/2024 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the OpenPLC Runtime EtherNet/IP parser functionality of OpenPLC _v3 b4702061dc14d1024856f71b4543298d77007b88. A specially crafted EtherNet/IP request can lead to remote code execution. An attacker can send a series of EtherNet/IP requests to trigger this… | |
| Modificada | Media (5.4) | 0.33% | — | Openplcproject Openplc V3 Firmware | 28/6/2024 | 17/6/2026 | OpenPLC 3 through 9cd8f1b allows XSS via an SVG document as a profile picture. | |
| Modificada | Alta (8.8) | 27% | — | Openplcproject Openplc V3 Firmware | 3/8/2021 | 17/6/2026 | Command Injection in Open PLC Webserver v3 allows remote attackers to execute arbitrary code via the "Hardware Layer Code Box" component on the "/hardware" page of the application. | |
| Modificada | Media (5.4) | 0.52% | — | Openplcproject Openplc | 2/8/2021 | 17/6/2026 | OpenPLC runtime V3 through 2016-03-14 allows stored XSS via the Device Name to the web server's Add New Device page. | |
| Modificada | Crítica (9.8) | 1.5% | — | Openplcproject Openplc V2 FirmwareOpenplcproject Openplc V3 Firmware | 22/4/2019 | 17/6/2026 | A buffer overflow vulnerability was discovered in the OpenPLC controller, in the OpenPLC_v2 and OpenPLC_v3 versions. It occurs in the modbus.cpp mapUnusedIO() function, which can cause a runtime crash of the PLC or possibly have unspecified other impact. |