Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 211 respecto a la semana anterior
Críticas / altas1376▲ 147 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
435 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.5) | 0.54% | — | ScadabrAI | 21/9/2026 | 21/9/2026 | A vulnerability was determined in ScadaBR up to 1.1. Impacted is the function EmportDwr.createExportJSON of the file /ScadaBR/export_project.htm of the component Export Project Endpoint. This manipulation causes information disclosure. The attack can be initiated remotely. The exploit has been publicly disclosed and… | |
| Aplazada | Alta (8.8) | 0.48% | — | ScadaltsAI | 16/9/2026 | 18/9/2026 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authorization Bypass Spring Security gates DWR endpoints by URL path pattern, but DWR itself dispatches method calls based on the POST body parameters c0-scriptName and c0-methodName. The crossDomainSessionSecurity setting in web.xml is set to false, which… | |
| Aplazada | Media (6.5) | 0.36% | — | ScadaltsAI | 16/9/2026 | 18/9/2026 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Blind SQL Injection The /api/events/search endpoint accepts a JSON body containing a sortBy array. The values in this array are concatenated directly into the SQL ORDER BY clause without any sanitization or parameterization. This allows… | |
| Aplazada | Alta (8.8) | 0.84% | — | ScadaltsAI | 16/9/2026 | 18/9/2026 | ScadaLTS 2.8.1-release-candidate build 0 is affected by an Authenticated Remote Code Execution via Scripting Sandbox Bypass The DWR "DataSourceEditDwr" class exposes the "validateScript" method that compiles and executes attacker-supplied JavaScript via the Rhino scripting engine. There are no authorization checks on… | |
| Aplazada | Crítica (9.3) | 0.78% | — | Myscada Mypro ManagerAI | 15/9/2026 | 18/9/2026 | The mySCADA myPRO Manager command API does not properly enforce authentication for privileged functions. An unauthenticated attacker with network access to the affected API could exploit this vulnerability to access privileged management functions. | |
| Analizada | Alta (8.5) | 0.14% | — | Hitachienergy Microscada X Sys600 | 3/9/2026 | 9/9/2026 | A vulnerability exists in SYS600 RBAC mechanism where users having access to the engineering tools could elevate their privileges to administrator level on the underlying Windows host, granting themselves full control over the host machine. | |
| Analizada | Alta (8.5) | 0.14% | — | Hitachienergy Microscada X Sys600 | 3/9/2026 | 9/9/2026 | A vulnerability exists in SYS600 which allows any user authenticated to the operating system of the server hosting the application to read and modify application objects without being authenticated to the SYS600 system itself. Only the SYS600 system users should be permitted to view and modify application objects. | |
| Analizada | Media (4.6) | 0.21% | — | Hitachienergy Microscada X Sys600 | 3/9/2026 | 9/9/2026 | A CSV injection vulnerability exists in SYS600. Injected malicious formulas can add or modify data to the spreadsheet, insert links, exfiltrate data, and in some cases, depending on how the user has their environment configured, execute malicious code on the user’s machine. To exploit this issue attackers would need a… | |
| Analizada | Media (6.1) | 0.28% | — | Scada-lts | 12/8/2026 | 25/8/2026 | ScadaLTS 2.7.8.1 reflects user-supplied input into an HTML response without sanitization. An unauthenticated attacker who lures a victim into visiting a crafted URL can execute arbitrary JavaScript in the context of the victim's browser session. | |
| Analizada | Crítica (9.9) | 0.52% | — | Scada-lts | 12/8/2026 | 25/8/2026 | ScadaLTS 2.7.8.1 exposes a server-side method that lacks authorization checks, allowing any authenticated user (including one holding only low-privilege, read-only permissions) to execute arbitrary operating system commands on the host. Successful exploitation results in code execution in the context of the ScadaLTS… | |
| Aplazada | Media (4.8) | 0.18% | — | ITP Technology ITS Intelligent Scada SystemAI | 29/5/2026 | 21/7/2026 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load. | |
| Aplazada | Media (4.8) | 0.18% | — | ITP Technology ITS Intelligent Scada SystemAI | 29/5/2026 | 21/7/2026 | ITS Intelligent SCADA System developed by ITP Technology has a Stored Cross-Site Scripting vulnerability, allowing privileged remote attackers to inject persistent JavaScript codes that are executed in users' browsers upon page load. | |
| Analizada | Media (6.1) | 0.26% | — | Scadabr | 28/5/2026 | 17/8/2026 | A reflected cross-site scripting issue exists in URL handling. | |
| Analizada | Crítica (9.9) | 0.52% | — | Scadabr | 28/5/2026 | 17/8/2026 | Exposed methods allow authenticated users to create and execute arbitrary JavaScript code on the server. The scripts execute with full access, enabling complete system compromise as commands are executed as root. | |
| Pendiente de análisis | Media (6.1) | 0.30% | — | Advantech Webaccess ScadaAI | 22/5/2026 | 23/7/2026 | Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component | |
| Analizada | Media (5.1) | 0.50% | — | Scadabr | 19/5/2026 | 23/7/2026 | In ScadaBR version 1.2.0, a Use of Hard-Coded Credentials vulnerability could allow an attacker to access the SCADA system as admin. | |
| Analizada | Alta (8.6) | 0.21% | — | Scadabr | 19/5/2026 | 23/7/2026 | In ScadaBR version 1.2.0, a CSRF vulnerability could allow an attacker to trigger any authenticated action through a victim's session by luring any logged-in user to a malicious webpage. | |
| Analizada | Alta (8.7) | 2.1% | — | Scadabr | 19/5/2026 | 23/7/2026 | In ScadaBR version 1.2.0, an OS Command Injection vulnerability could allow an attacker to execute commands as root on the SCADA system. | |
| Analizada | Alta (8.8) | 0.58% | — | Scadabr | 19/5/2026 | 23/7/2026 | In ScadaBR version 1.2.0, a Missing Authentication for Critical Function vulnerability could allow an unauthenticated attacker to send a HTTP GET requests to the SCADA system and inject arbitrary sensor readings. | |
| Analizada | Media (4.8) | 0.20% | — | Scadabr | 9/3/2026 | 17/6/2026 | ScadaBR 1.12.4 is vulnerable to Session Fixation. The application assigns a JSESSIONID session cookie to unauthenticated users and does not regenerate the session identifier after successful authentication. As a result, a session created prior to login becomes authenticated once the victim logs in, allowing an… | |
| Analizada | Crítica (9.3) | 1.5% | — | Insat Masterscada | 24/2/2026 | 17/6/2026 | All versions of InSAT MasterSCADA BUK-TS are susceptible to OS command injection through a field in its MMadmServ web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution. | |
| Analizada | Crítica (9.3) | 0.55% | — | Insat Masterscada | 24/2/2026 | 17/6/2026 | InSAT MasterSCADA BUK-TS is susceptible to SQL Injection through its main web interface. Malicious users that use the vulnerable endpoint are potentially able to cause remote code execution. | |
| Aplazada | Media (4.6) | 0.25% | — | ScadaappAI | 18/2/2026 | 17/6/2026 | ScadaApp for iOS 1.1.4.0 contains a denial of service vulnerability that allows attackers to crash the application by inputting an oversized buffer in the Servername field. Attackers can paste a 257-character buffer during login to trigger an application crash on iOS devices. | |
| Aplazada | Media (4.6) | 0.38% | — | Proficy ScadaAI | 5/2/2026 | 17/6/2026 | ProficySCADA for iOS 5.0.25920 contains a denial of service vulnerability that allows attackers to crash the application by manipulating the password input field. Attackers can overwrite the password field with 257 bytes of repeated characters to trigger an application crash and prevent successful authentication. | |
| Analizada | Media (5.3) | 0.73% | — | Advantech Webaccess/scada | 18/12/2025 | 17/6/2026 | Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files. |