Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2568▼ 304 respecto a la semana anterior
Críticas / altas1352▲ 100 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

13 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.3)0.24%—Softing SmartlinkAI4/9/20269/9/2026
Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10.
Pendiente de análisisMedia (6.5)0.36%—Softing Industrial Automation Gmbh PngateAISofting Industrial Automation Gmbh EpgateAISofting Industrial Automation Gmbh MbgateAISofting Industrial Automation Gmbh Smartlink Hw-pnAI+127/3/202617/6/2026
Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This issue affects pnGate: through 1.30 epGate: through 1.30 mbGate: through 1.30 smartLink HW-DP: through 1.30 smartLink HW-PN: through 1.01.
Pendiente de análisisMedia (6.5)0.21%—Softing Smartlink Hw-dpAISofting Smartlink Hw-pnAI27/3/202617/6/2026
Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02.
Pendiente de análisisMedia (6.8)0.32%—Softing Smartlink Sw-htAI17/3/202617/6/2026
NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43.
Pendiente de análisisAlta (7.7)0.49%—Softing Industrial Automation Gmbh Smartlink Sw-pnAISofting Smartlink Sw-htAI16/3/202617/6/2026
Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42
Pendiente de análisisMedia (5.3)0.37%—Softing Industrial Automation Gmbh Smartlink SW HTAISofting Industrial Automation Gmbh Smartlink SW PNAI16/3/202617/6/2026
Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03.
AplazadaAlta (7.2)0.23%—Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI28/10/202517/6/2026
Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31
AplazadaAlta (8.7)0.26%—Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI28/10/202517/6/2026
Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31
AplazadaAlta (7.1)0.21%—Woopy Plugins Smartlink Dynamic UrlsAI19/11/202417/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in Woopy Plugins SmartLink Dynamic URLs smartlink-dinamic-urls allows Stored XSS.This issue affects SmartLink Dynamic URLs: from n/a through <= 1.1.0.
ModificadaAlta (7.5)0.27%—Softing Smartlink Sw-ht6/11/202317/6/2026
Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL).
ModificadaMedia (6.1)0.38%—Softing Smartlink Sw-ht6/11/202317/6/2026
Cross-site Scripting vulnerability in Softing smartLink SW-HT before 1.30, which allows an attacker to execute a dynamic script (JavaScript, VBScript) in the context of the application.
ModificadaAlta (7.5)1.5%—Softing Smartlink Hw-dpSofting Uatoolkit Embedded10/11/202117/6/2026
An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type…
ModificadaCrítica (9.8)1.4%—Schneider-electric Acti9 Smartlink SI D FirmwareSchneider-electric Acti9 Smartlink SI B FirmwareSchneider-electric Acti9 Powertag Link FirmwareSchneider-electric Acti9 Powertag Link HD Firmware+31/12/202017/6/2026
A CWE-330 - Use of Insufficiently Random Values vulnerability exists in Smartlink, PowerTag, and Wiser Series Gateways (see security notification for version information) that could allow unauthorized users to login.