Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
11 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.82% | — | GE Proficy Historian | 18/1/2023 | 17/6/2026 | Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status. | |
| Modificada | Media (6.5) | 0.56% | — | GE Proficy Historian | 18/1/2023 | 17/6/2026 | An unauthorized user could alter or write files with full control over the path and content of the file. | |
| Modificada | Alta (8.1) | 0.52% | — | GE Proficy Historian | 18/1/2023 | 17/6/2026 | An unauthorized user could possibly delete any file on the system. | |
| Modificada | Media (6.5) | 0.55% | — | GE Proficy Historian | 18/1/2023 | 17/6/2026 | An unauthorized user could be able to read any file on the system, potentially exposing sensitive information. | |
| Modificada | Alta (7.5) | 0.61% | — | GE Proficy Historian | 18/1/2023 | 17/6/2026 | An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords. | |
| Modificada | Alta (9.3) | 40% | — | Intelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy HistorianIntelligent Platforms Proficy Hmi/scada IfixIntelligent Platforms Proficy Pulse+1 | 5/7/2012 | 16/6/2026 | An ActiveX control in KeyHelp.ocx in KeyWorks KeyHelp Module (aka the HTML Help component), as used in GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5; Proficy HMI/SCADA iFIX 5.0 and 5.1; Proficy Pulse 1.0; Proficy Batch Execution 5.6; SI7 I/O Driver 7.20 through 7.42; and other products, allows… | |
| Modificada | Alta (9.3) | 28% | — | EMC Captiva Quickscan PROEMC Documentum Applicationxtender DesktopIntelligent Platforms Proficy Batch ExecutionIntelligent Platforms Proficy Historian+3 | 5/7/2012 | 16/6/2026 | Multiple stack-based buffer overflows in the KeyHelp.KeyCtrl.1 ActiveX control in KeyHelp.ocx 1.2.312 in KeyWorks KeyHelp Module (aka the HTML Help component), as used in EMC Documentum ApplicationXtender Desktop 5.4; EMC Captiva Quickscan Pro 4.6 SP1; GE Intelligent Platforms Proficy Historian 3.1, 3.5, 4.0, and 4.5;… | |
| Modificada | Alta (10) | 5.0% | — | Intelligent Platforms Proficy Historian | 15/3/2012 | 16/6/2026 | The Data Archiver service in GE Intelligent Platforms Proficy Historian 4.5 and earlier allows remote attackers to cause a denial of service (memory corruption) or possibly execute arbitrary code via a crafted session on TCP port 14000 to (1) ihDataArchiver.exe or (2) ihDataArchiver_x64.exe. | |
| Modificada | Media (4.3) | 0.91% | — | Intelligent Platforms Proficy Historian | 2/11/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Web Administrator component in GE Intelligent Platforms Proficy Historian 4.x and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified parameters. | |
| Modificada | Alta (10) | 4.6% | — | Intelligent Platforms Proficy Historian | 2/11/2011 | 16/6/2026 | Multiple stack-based buffer overflows in GE Intelligent Platforms Proficy Applications before 4.4.1 SIM 101 and 5.x before 5.0 SIM 43 allow remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic to (1) PRProficyMgr.exe in Proficy Server Manager,… | |
| Modificada | Alta (10) | 6.3% | — | Intelligent Platforms Proficy Historian | 2/11/2011 | 16/6/2026 | Stack-based buffer overflow in the Data Archiver service in GE Intelligent Platforms Proficy Historian before 3.5 SIM 17 and 4.x before 4.0 SIM 12 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via crafted TCP message traffic. |