Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.3) | 4.8% | — | Rockwellautomation Thinmanager Thinserver | 26/8/2024 | 17/6/2026 | A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be overwritten. | |
| Analizada | Alta (8.5) | 0.32% | — | Rockwellautomation Thinmanager Thinserver | 26/8/2024 | 17/6/2026 | A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. To exploit this vulnerability and a threat actor must abuse the ThinServer™ service by creating a junction and use it to upload arbitrary files. | |
| Modificada | Alta (8.7) | 2.3% | — | Rockwellautomation ThinmanagerRockwellautomation Thinserver | 25/6/2024 | 17/6/2026 | Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device. | |
| Modificada | Crítica (9.3) | 2.4% | — | Rockwellautomation ThinmanagerRockwellautomation Thinserver | 25/6/2024 | 17/6/2026 | Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™. | |
| Modificada | Crítica (9.3) | 2.7% | — | Rockwellautomation ThinmanagerRockwellautomation Thinserver | 25/6/2024 | 17/6/2026 | Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™. | |
| Modificada | Crítica (9.8) | 72% | — | Rockwellautomation Thinmanager Thinserver | 17/8/2023 | 17/6/2026 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an unauthenticated remote attacker can upload… | |
| Modificada | Crítica (9.1) | 82% | — | Rockwellautomation Thinmanager Thinserver | 17/8/2023 | 17/6/2026 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a certain function. If exploited, an unauthenticated remote threat actor can delete arbitrary files… | |
| Modificada | Alta (7.5) | 40% | — | Rockwellautomation Thinmanager Thinserver | 17/8/2023 | 17/6/2026 | The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a read access violation occurs and terminates the process. A malicious user could exploit this… |