Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2585▼ 302 respecto a la semana anterior
Críticas / altas1355▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

55 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.6)0.48%—Softing OPC UA C++ SDKAISofting Secure Integration ServerAI14/9/202622/9/2026
An issue was discovered in Softing OPC UA C++ SDK through 6.20 and Softing Secure Integration Server through 1.22. By using FileType renames, it is possible to bypass limitations on assignment of a directory path to FileDirectory OPC UA objects and a file path to File OPC UA objects.
AplazadaMedia (6.3)0.24%—Softing SmartlinkAI4/9/20269/9/2026
Missing release of memory after effective lifetime vulnerability in Softing smartLink allows resource leak exposure. This issue affects smartLink HW-PN: from 1.04 before 1.10.
Pendiente de análisisMedia (6.5)0.36%—Softing Industrial Automation Gmbh PngateAISofting Industrial Automation Gmbh EpgateAISofting Industrial Automation Gmbh MbgateAISofting Industrial Automation Gmbh Smartlink Hw-pnAI+127/3/202617/6/2026
Stack-based buffer overflow vulnerability in Softing Industrial Automation GmbH gateways allows overflow buffers. This issue affects pnGate: through 1.30 epGate: through 1.30 mbGate: through 1.30 smartLink HW-DP: through 1.30 smartLink HW-PN: through 1.01.
Pendiente de análisisMedia (6.5)0.21%—Softing Smartlink Hw-dpAISofting Smartlink Hw-pnAI27/3/202617/6/2026
Use after free vulnerability in Softing smartLink HW-DP or smartLink HW-PN webserver allows HTTP DoS. This issue affects: smartLink HW-DP: through 1.31 smartLink HW-PN: before 1.02.
Pendiente de análisisMedia (6.8)0.32%—Softing Smartlink Sw-htAI17/3/202617/6/2026
NULL Pointer Dereference vulnerability in Softing Industrial Automation GmbH smartLink SW-HT (Webserver modules) allows HTTP DoS.This issue affects smartLink SW-HT: 1.43.
Pendiente de análisisAlta (7.7)0.49%—Softing Industrial Automation Gmbh Smartlink Sw-pnAISofting Smartlink Sw-htAI16/3/202617/6/2026
Heap-based buffer overflow vulnerability in Softing Industrial Automation GmbH smartLink SW-PN and smartLink SW-HT (Webserver modules) allows overflow buffers.This issue affects: smartLink SW-PN: through 1.03 smartLink SW-HT: through 1.42
Pendiente de análisisMedia (5.3)0.37%—Softing Industrial Automation Gmbh Smartlink SW HTAISofting Industrial Automation Gmbh Smartlink SW PNAI16/3/202617/6/2026
Global file reads caused by improper URL checks in webserver in Softing Industrial Automation GmbH smartLinks on docker (filesystem modules) allows file access. This issue affects smartLink SW-HT: through 1.42 smartLink SW-PN: through 1.03.
AplazadaAlta (7.2)0.23%—Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI28/10/202517/6/2026
Improper locking vulnerability in Softing Industrial Automation GmbH gateways allows infected memory and/or resource leak exposure.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31
AplazadaAlta (8.7)0.26%—Softing Industrial Automation Gmbh Smartlink Hw-pnAISofting Smartlink Hw-dpAI28/10/202517/6/2026
Webserver crash caused by scanning on TCP port 80 in Softing Industrial Automation GmbH gateways and switch.This issue affects smartLink HW-PN: from 1.02 through 1.03 smartLink HW-DP: 1.31
AnalizadaMedia (6.5)1.2%—Softing EdgeaggregatorSofting EdgeconnectorSofting Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server Hardcoded Cryptographic Key Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the…
AnalizadaAlta (8.8)1.6%—Softing Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server Interpretation Conflict Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing…
AnalizadaMedia (6.5)1.2%—Softing Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server FileDirectory OPC UA Object Arbitrary File Creation Vulnerability. This vulnerability allows remote attackers to create arbitrary files on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing…
AnalizadaAlta (8.8)1.6%—Softing Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server OPC UA Gateway Directory Creation Vulnerability. This vulnerability allows remote attackers to create directories on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the existing authentication mechanism…
AnalizadaAlta (8.8)1.6%—Softing Secure Integration Server3/5/202417/6/2026
Softing Secure Integration Server Exposure of Resource to Wrong Sphere Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing Secure Integration Server. Although authentication is required to exploit this vulnerability, the…
AnalizadaAlta (8.8)1.3%—Softing EdgeaggregatorSofting EdgeconnectorSofting Secure Integration Server3/5/202417/6/2026
Softing edgeAggregator Permissive Cross-domain Policy with Untrusted Domains Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability. The specific flaw exists…
AnalizadaAlta (7.5)0.81%—Softing EdgeaggregatorSofting EdgeconnectorSofting Secure Integration Server3/5/202417/6/2026
Softing edgeConnector Siemens OPC UA Server Null Pointer Dereference Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific…
AnalizadaCrítica (9.6)1.4%—Softing EdgeaggregatorSofting Secure Integration Server3/5/202417/6/2026
Softing edgeAggregator Client Cross-Site Scripting Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or…
AnalizadaAlta (7.5)1.4%—Softing EdgeaggregatorSofting EdgeconnectorSofting OPC UA C++ Software Development KITSofting Secure Integration Server3/5/202417/6/2026
Softing edgeConnector Siemens ConditionRefresh Resource Exhaustion Denial-of-Service Vulnerability. This vulnerability allows remote attackers to create a denial-of-service condition on affected installations of Softing edgeConnector Siemens. Authentication is not required to exploit this vulnerability. The specific…
AplazadaMedia (5.1)0.17%—Softing Uatoolkit EmbeddedAI2/4/202417/6/2026
An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotificationPerPublish parameter is created, a publish response is mishandled, leading to memory consumption. When that happens often enough, the device will be out of memory, i.e., a denial of service.
AnalizadaAlta (7.5)0.51%—Softing EdgeaggregatorSofting Edgeconnector14/3/202417/6/2026
The affected product is vulnerable to a cleartext transmission of sensitive information vulnerability, which may allow an attacker to capture packets to craft their own requests.
ModificadaMedia (6.1)0.31%—Softing TH Scope30/1/202417/6/2026
Softing TH SCOPE through 3.70 allows XSS.
ModificadaAlta (7.2)71%—Softing Edgeaggregator19/12/202317/6/2026
Softing edgeAggregator Restore Configuration Directory Traversal Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of Softing edgeAggregator. Authentication is required to exploit this vulnerability. The specific flaw exists within the…
ModificadaAlta (7.5)0.70%—Softing OPCSofting OPC UA C++ Software Development KITSofting Secure Integration Server14/12/202317/6/2026
An uncaught exception issue discovered in Softing OPC UA C++ SDK before 6.30 for Windows operating system may cause the application to crash when the server wants to send an error packet, while socket is blocked on writing.
ModificadaAlta (7.5)0.59%—Softing OPC5/12/202317/6/2026
Softing OPC Suite version 5.25 and before has Incorrect Access Control, allows attackers to obtain sensitive information via weak permissions in OSF_discovery service. The service executable could be changed or the service could be deleted.
ModificadaAlta (7.5)0.27%—Softing Smartlink Sw-ht6/11/202317/6/2026
Weak ciphers in Softing smartLink SW-HT before 1.30 are enabled during secure communication (SSL).