Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.24% | — | Softing SmartlinkAI | 4/9/2026 | 9/9/2026 | Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10. | |
| Pendiente de análisis | Media (6.5) | 0.36% | — | Softing Industrial Automation Gmbh PngateAISofting Industrial Automation Gmbh EpgateAISofting Industrial Automation Gmbh MbgateAISofting Industrial Automation Gmbh Smartlink Hw-pnAI+1 | 27/3/2026 | 17/6/2026 | Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This issue affects pnGate: through 1.30 epGate: through 1.30 mbGate: through 1.30 smartLink HW-DP: through 1.30 smartLink HW-PN: through 1.01. | |
| Pendiente de análisis | Media (6.5) | 0.21% | — | Softing Smartlink Hw-dpAISofting Smartlink Hw-pnAI | 27/3/2026 | 17/6/2026 | Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02. | |
| Pendiente de análisis | Media (6.8) | 0.32% | — | Softing Smartlink Sw-htAI | 17/3/2026 | 17/6/2026 | NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43. | |
| Pendiente de análisis | Alta (7.7) | 0.49% | — | Softing Industrial Automation Gmbh Smartlink Sw-pnAISofting Smartlink Sw-htAI | 16/3/2026 | 17/6/2026 | Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42 | |
| Pendiente de análisis | Media (5.3) | 0.37% | — | Softing Industrial Automation Gmbh Smartlink SW HTAISofting Industrial Automation Gmbh Smartlink SW PNAI | 16/3/2026 | 17/6/2026 | Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03. | |
| Aplazada | Alta (7.2) | 0.23% | — | Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI | 28/10/2025 | 17/6/2026 | Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31 | |
| Aplazada | Alta (8.7) | 0.26% | — | Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI | 28/10/2025 | 17/6/2026 | Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31 | |
| Aplazada | Alta (7.1) | 0.21% | — | Woopy Plugins Smartlink Dynamic UrlsAI | 19/11/2024 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs smartlink-dinamic-urls allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through <= 1.1.0. | |
| Modificada | Alta (7.5) | 0.27% | — | Softing Smartlink Sw-ht | 6/11/2023 | 17/6/2026 | Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL). | |
| Modificada | Media (6.1) | 0.38% | — | Softing Smartlink Sw-ht | 6/11/2023 | 17/6/2026 | Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application. | |
| Modificada | Alta (7.5) | 1.5% | — | Softing Smartlink Hw-dpSofting Uatoolkit Embedded | 10/11/2021 | 17/6/2026 | An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type… | |
| Modificada | Crítica (9.8) | 1.4% | — | Schneider-electric Acti9 Smartlink SI D FirmwareSchneider-electric Acti9 Smartlink SI B FirmwareSchneider-electric Acti9 Powertag Link FirmwareSchneider-electric Acti9 Powertag Link HD Firmware+3 | 1/12/2020 | 17/6/2026 | A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login. |