Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2882▼ 181 respecto a la semana anterior
Críticas / altas1279▼ 60 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)487▼ 22 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.33% | — | Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+14 | 14/12/2023 | 17/6/2026 | Download of Code Without Integrity Check vulnerability in PHOENIX CONTACT classic line PLCs allows an unauthenticated remote attacker to modify some or all applications on a PLC. | |
| Modificada | Crítica (9.8) | 0.88% | — | Phoenixcontact Automationworx Software SuitePhoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 Firmware+14 | 14/12/2023 | 17/6/2026 | Incorrect Permission Assignment for Critical Resource vulnerability in multiple products of the PHOENIX CONTACT classic line allow an remote unauthenticated attacker to gain full access of the affected device. | |
| Modificada | Crítica (9.8) | 1.6% | — | Phoenixcontact AXC 1050 FirmwarePhoenixcontact AXC 1050 XC FirmwarePhoenixcontact AXC 3050 FirmwarePhoenixcontact FC 350 PCI ETH Firmware+13 | 21/6/2022 | 17/6/2026 | An unauthenticated, remote attacker could upload malicious logic to devices based on ProConOS/ProConOS eCLR in order to gain full control over the device. | |
| Modificada | Alta (7.8) | 0.65% | — | Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 4/11/2021 | 17/6/2026 | Improper Input Validation vulnerability in PC Worx Automation Suite of Phoenix Contact up to version 1.88 could allow an attacker with a manipulated project file to unpack arbitrary files outside of the selected project directory. | |
| Modificada | Alta (7) | 1.8% | — | Phoenixcontact Config+Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 25/6/2021 | 17/6/2026 | Phoenix Contact Classic Automation Worx Software Suite in Version 1.87 and below is affected by a remote code execution vulnerability. Manipulated PC Worx or Config+ projects could lead to a remote code execution when unallocated memory is freed because of incompletely initialized data. The attacker needs to get… | |
| Modificada | Alta (7.8) | 2.1% | — | Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 1/7/2020 | 17/6/2026 | mwe file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier is vulnerable to out-of-bounds read remote code execution. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation. | |
| Modificada | Alta (7.8) | 15% | — | Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 1/7/2020 | 17/6/2026 | PLCopen XML file parsing in Phoenix Contact PC Worx and PC Worx Express version 1.87 and earlier can lead to a stack-based overflow. Manipulated PC Worx projects could lead to a remote code execution due to insufficient input data validation. | |
| Modificada | Alta (7.8) | 0.30% | — | Phoenixcontact PC Worx SRT | 27/3/2020 | 17/6/2026 | Insecure, default path permissions in PHOENIX CONTACT PC WORX SRT through 1.14 allow for local privilege escalation. | |
| Modificada | Alta (7.8) | 3.3% | — | Phoenixcontact Config+Phoenixcontact PC WorxPhoenixcontact PC Worx Express | 31/10/2019 | 17/6/2026 | An issue was discovered in PHOENIX CONTACT PC Worx through 1.86, PC Worx Express through 1.86, and Config+ through 1.86. A manipulated PC Worx or Config+ project file could lead to an Out-of-bounds Read and remote code execution. The attacker needs to get access to an original PC Worx or Config+ project to be able to… |