Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2757▲ 47 respecto a la semana anterior
Críticas / altas1482▲ 372 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

4 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.68%—Getkirby Starterkit18/8/202217/6/2026
A stored cross-site scripting (XSS) vulnerability in Kirby's Starterkit v3.7.0.2 allows attackers to execute arbitrary web scripts or HTML via a crafted payload injected into the Tags field.
ModificadaAlta (7.5)0.98%—Phoenixcontact Plcnext Technology Starterkit FirmwarePhoenixcontact AXC F 2152 Starterkit FirmwarePhoenixcontact RFC 4072s FirmwarePhoenixcontact AXC F 3152 Firmware+227/9/202117/6/2026
Multiple Phoenix Contact PLCnext control devices in versions prior to 2021.0.5 LTS are prone to a DoS attack through special crafted JSON requests.
ModificadaMedia (6.8)0.40%—Phoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 2152 Starterkit Firmware18/6/201917/6/2026
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Unlimited physical access to the PLC may lead to a manipulation of SD cards data. SD card manipulation may lead to an authentication bypass opportunity.
ModificadaMedia (5.9)1.0%—Phoenixcontact AXC F 2152 FirmwarePhoenixcontact AXC F 2152 Starterkit Firmware17/6/201917/6/2026
An issue was discovered on Phoenix Contact AXC F 2152 (No.2404267) before 2019.0 LTS and AXC F 2152 STARTERKIT (No.1046568) before 2019.0 LTS devices. Protocol Fuzzing on PC WORX Engineer by a man in the middle attacker stops the PLC service. The device must be rebooted, or the PLC service must be restarted manually…