Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
152 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.1) | 0.39% | — | Schneider-electric Struxureware Data Center Expert | 9/6/2026 | 20/7/2026 | CWE-611 Improper Restriction of XML External Entity Reference vulnerability exists that could cause information disclosure of server-side file contents when an attacker with a Data Center Expert user account submits crafted XML payloads to SOAP service endpoints. | |
| Analizada | Media (6.8) | 0.20% | — | Schneider-electric Ecostruxure Machine Expert Hvac | 14/5/2026 | 17/6/2026 | CWE-312: Cleartext Storage of Sensitive Information vulnerability exists that could cause the disclosure of a sensitive information which could result in revealing protected source code and loss of confidentiality, When an authorized attacker accesses the source code for editing or compiling it. | |
| Analizada | Alta (8.2) | 0.49% | — | Schneider-electric Ecostruxure Panel Server Pas400 FirmwareSchneider-electric Ecostruxure Panel Server Pas600 FirmwareSchneider-electric Ecostruxure Panel Server Pas600v2 FirmwareSchneider-electric Ecostruxure Panel Server Pas800 Firmware+1 | 12/5/2026 | 24/6/2026 | CWE-1188 Initialization of a Resource with an Insecure Default vulnerability exists that could cause unauthorized disclosure of sensitive information when credentials revert to initial settings in rare circumstances, enabling unauthorized authentication using known credentials. | |
| Analizada | Alta (7.2) | 0.23% | — | Schneider-electric Ecostruxure Automation Expert | 10/3/2026 | 23/6/2026 | CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exist that could cause execution of untrusted commands on the engineering workstation which could result in a limited compromise of the workstation and a potential loss of Confidentiality, Integrity and Availability of the subsequent… | |
| Analizada | Alta (7) | 0.32% | — | Schneider-electric Ecostruxure Foxboro DCS Control Software | 10/3/2026 | 24/6/2026 | CWE-502: Deserialization of untrusted data vulnerability exists that could lead to loss of confidentiality, integrity and potential remote code execution on workstation when an admin authenticated user opens a malicious project file. | |
| Analizada | Alta (8.5) | 0.19% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation | 10/3/2026 | 24/6/2026 | CWE‑502: Deserialization of Untrusted Data vulnerability exists that could cause arbitrary code execution with administrative privileges when a locally authenticated attacker sends a crafted data stream, triggering unsafe deserialization. | |
| Analizada | Alta (8.4) | 0.35% | — | Schneider-electric Ecostruxure Power Build - Rapsody | 15/1/2026 | 3/9/2026 | CWE-416: Use After Free vulnerability that could cause remote code execution when the end user imports the malicious project file (SSD file) into Rapsody. | |
| Analizada | Alta (8.4) | 0.16% | — | Schneider-electric Ecostruxure Power Build - Rapsody | 15/1/2026 | 3/9/2026 | CWE-415: Double Free vulnerability exists that could cause heap memory corruption when the end user imports a malicious project file (SSD file) shared by the attacker into Rapsody. | |
| Aplazada | Alta (8.1) | 0.53% | — | Ancorathemes StruxAI | 18/12/2025 | 17/6/2026 | Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in AncoraThemes Strux strux allows PHP Local File Inclusion.This issue affects Strux: from n/a through <= 1.9. | |
| Analizada | Crítica (10) | 0.65% | — | Schneider-electric Ecostruxure IT Gateway | 13/11/2024 | 17/6/2026 | CWE-862: Missing Authorization vulnerability exists that could cause unauthorized access when enabled on the network and potentially impacting connected devices. | |
| Analizada | Alta (7.8) | 0.21% | — | Schneider-electric Vijeo DesignerSchneider-electric Vijeo Designer Embedded IN Ecostruxure Machine Expert | 11/9/2024 | 17/6/2026 | CWE-269: Improper Privilege Management vulnerability exists that could cause unauthorized access, loss of confidentiality, integrity and availability of the workstation when non-admin authenticated user tries to perform privilege escalation by tampering with the binaries. | |
| Modificada | Alta (7.8) | 0.24% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 11/7/2024 | 17/6/2026 | CWE-20: Improper Input Validation vulnerability exists that could cause local denial-of-service, privilege escalation, and potentially kernel execution when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Media (5.5) | 0.15% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 11/7/2024 | 17/6/2026 | CWE-129: Improper Validation of Array Index vulnerability exists that could cause local denial-of-service when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Alta (7.1) | 0.15% | — | Schneider-electric Ecostruxure Foxboro DCS Control Core Services | 11/7/2024 | 17/6/2026 | CWE-787: Out-of-Bounds Write vulnerability exists that could cause local denial-of-service, or kernel memory leak when a malicious actor with local user access crafts a script/program using an IOCTL call in the Foxboro.sys driver. | |
| Modificada | Alta (7.8) | 0.24% | — | Schneider-electric Ecostruxure IT Gateway | 12/6/2024 | 17/6/2026 | CWE-798: Use of hard-coded credentials vulnerability exists that could cause local privilege escalation when logged in as a non-administrative user. | |
| Analizada | Alta (7.7) | 0.23% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert | 14/2/2024 | 17/6/2026 | CWE-798: Use of Hard-coded Credentials vulnerability exists that could cause unauthorized access to a project file protected with application password when opening the file with EcoStruxure Control Expert. | |
| Analizada | Alta (8.1) | 0.32% | — | Schneider-electric Modicon M340 Bmxp341000 FirmwareSchneider-electric Modicon M340 Bmxp341000h FirmwareSchneider-electric Modicon M340 Bmxp342000 FirmwareSchneider-electric Modicon M340 Bmxp342010 Firmware+42 | 14/2/2024 | 17/6/2026 | CWE-924: Improper Enforcement of Message Integrity During Transmission in a Communication Channel vulnerability exists that could cause a denial of service and loss of confidentiality, integrity of controllers when conducting a Man in the Middle attack. | |
| Analizada | Alta (7.1) | 0.15% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Ecostruxure Process Expert | 14/2/2024 | 17/6/2026 | CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause unauthorized access to the project file in EcoStruxure Control Expert when a local user tampers with the memory of the engineering workstation. | |
| Modificada | Media (6.1) | 0.41% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-79 Improper Neutralization of Input During Web Page Generation (Cross-site Scripting) vulnerability that could cause a vulnerability leading to a cross site scripting condition where attackers can have a victim’s browser run arbitrary JavaScript when they visit a page containing the injected payload. | |
| Modificada | Media (6.1) | 0.45% | — | Schneider-electric Ecostruxure Power Monitoring Expert | 15/11/2023 | 17/6/2026 | A CWE-601 URL Redirection to Untrusted Site vulnerability exists that could cause an openredirect vulnerability leading to a cross site scripting attack. By providing a URL-encoded input attackers can cause the software’s web application to redirect to the chosen domain after a successful login is performed. | |
| Modificada | Crítica (9.8) | 0.92% | — | Schneider-electric Ecostruxure Power Monitoring ExpertSchneider-electric Ecostruxure Power Operation With Advanced ReportsSchneider-electric Ecostruxure Power Scada Operation With Advanced Reports | 4/10/2023 | 17/6/2026 | A CWE-502: Deserialization of untrusted data vulnerability exists that could allow an attacker to execute arbitrary code on the targeted system by sending a specifically crafted packet to the application. | |
| Modificada | Media (5.5) | 0.21% | — | Ecostruxure OPC UA Server Expert | 12/7/2023 | 17/6/2026 | A CWE-611: Improper Restriction of XML External Entity Reference vulnerability exists that could cause loss of confidentiality when replacing a project file on the local filesystem and after manual restart of the server. | |
| Modificada | Alta (7.2) | 0.86% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE tampers with backups which are then manually restored. | |
| Modificada | Alta (7.2) | 0.86% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-94: Improper Control of Generation of Code ('Code Injection') vulnerability exists that could cause remote code execution when an admin user on DCE uploads or tampers with install packages. | |
| Modificada | Alta (8.8) | 0.60% | — | Schneider-electric Struxureware Data Center Expert | 12/7/2023 | 17/6/2026 | A CWE-89: Improper Neutralization of Special Elements vulnerability used in an SQL Command ('SQL Injection') vulnerability exists that could allow a user already authenticated on DCE to access unauthorized content, change, or delete content, or perform unauthorized actions when tampering with the mass configuration… |