Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2614▼ 473 respecto a la semana anterior
Críticas / altas1270▼ 74 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)243▼ 274 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.1) | 0.22% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This external control vulnerability, if exploited, could allow a local OS-authenticated user with standard privileges to delete files with System privilege on the machine where these products are installed, resulting in denial of service. | |
| Modificada | Alta (7.8) | 0.24% | — | Aveva Batch ManagementAveva Communication DriversAveva EdgeAveva Enterprise Licensing+9 | 15/11/2023 | 17/6/2026 | This privilege escalation vulnerability, if exploited, cloud allow a local OS-authenticated user with standard privileges to escalate to System privilege on the machine where these products are installed, resulting in complete compromise of the target machine. | |
| Modificada | Baja (2.5) | 0.20% | — | Supcon Inplant Scada | 15/9/2023 | 17/6/2026 | A vulnerability classified as problematic was found in Supcon InPlant SCADA up to 20230901. Affected by this vulnerability is an unknown functionality of the file Project.xml. The manipulation leads to password hash with insufficient computational effort. Local access is required to approach this attack. The… | |
| Modificada | Alta (7.8) | 0.38% | — | Supcon Inplant Scada | 15/9/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Supcon InPlant SCADA up to 20230901. Affected is an unknown function of the file Project.xml. The manipulation leads to improper authentication. An attack has to be approached locally. The exploit has been disclosed to the public and may be used. The identifier… | |
| Modificada | Crítica (9.8) | 0.68% | — | Aveva Plant ScadaAveva Telemetry Server | 16/3/2023 | 17/6/2026 | The listed versions of AVEVA Plant SCADA and AVEVA Telemetry Server are vulnerable to an improper authorization exploit which could allow an unauthenticated user to remotely read data, cause denial of service, and tamper with alarm states. | |
| Modificada | Crítica (9.9) | 0.97% | — | Aveva Intouch Access AnywhereAveva Plant Scada Access Anywhere | 23/5/2022 | 17/6/2026 | Windows OS can be configured to overlay a “language bar” on top of any application. When this OS functionality is enabled, the OS language bar UI will be viewable in the browser alongside the AVEVA InTouch Access Anywhere and Plant SCADA Access Anywhere applications. It is possible to manipulate the Windows OS… |