Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3061▲ 555 respecto a la semana anterior
Críticas / altas1459▲ 279 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.6) | 1.4% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PRO | 11/12/2020 | 17/6/2026 | A CWE-123: Write-what-where Condition vulnerability exists in EcoStruxure™ Control Expert (all versions) and Unity Pro (former name of EcoStruxure™ Control Expert) (all versions), that could cause a crash of the software or unexpected code execution when opening a malicious file in EcoStruxure™ Control Expert software. | |
| Modificada | Crítica (9.8) | 1.6% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PROSchneider-electric Modicon M340 FirmwareSchneider-electric Modicon M580 Firmware | 23/3/2020 | 17/6/2026 | A CWE-74: Improper Neutralization of Special Elements in Output Used by a Downstream Component ('Injection'), reflective DLL, vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20), Modicon M580 (all versions prior… | |
| Modificada | Alta (7.3) | 0.95% | — | Schneider-electric Ecostruxure Control ExpertSchneider-electric Unity PROSchneider-electric Modicon M580 Bmep584040 FirmwareSchneider-electric Modicon M580 Bmeh584040 Firmware+19 | 6/1/2020 | 17/6/2026 | Incorrect Authorization vulnerability exists in EcoStruxure Control Expert (all versions prior to 14.1 Hot Fix), Unity Pro (all versions), Modicon M340 (all versions prior to V3.20) , and Modicon M580 (all versions prior to V3.10), which could cause a bypass of the authentication process between EcoStruxure Control… | |
| Modificada | Alta (7) | 1.1% | — | Schneider-electric Unity PRO | 13/2/2017 | 17/6/2026 | An issue was discovered in Schneider Electric Unity PRO prior to V11.1. Unity projects can be compiled as x86 instructions and loaded onto the PLC Simulator delivered with Unity PRO. These x86 instructions are subsequently executed directly by the simulator. A specially crafted patched Unity project file can make the… | |
| Modificada | Alta (7.5) | 5.6% | — | Schneider-electric SomachineSchneider-electric SomoveSchneider-electric Somove LiteSchneider-electric Unity PRO | 1/2/2015 | 17/6/2026 | Stack-based buffer overflow in an unspecified DLL file in a DTM development kit in Schneider Electric Unity Pro, SoMachine, SoMove, SoMove Lite, Modbus Communication Library 2.2.6 and earlier, CANopen Communication Library 1.0.2 and earlier, EtherNet/IP Communication Library 1.0.0 and earlier, EM X80 Gateway DTM (MB… | |
| Modificada | Alta (9.3) | 22% | — | Schneider-electric ConceptSchneider-electric Modbus Serial DriverSchneider-electric Modbuscommdtm SLSchneider-electric OPC Factory Server+9 | 1/4/2014 | 16/6/2026 | Multiple stack-based buffer overflows in ModbusDrv.exe in Schneider Electric Modbus Serial Driver 1.10 through 3.2 allow remote attackers to execute arbitrary code via a large buffer-size value in a Modbus Application Header. | |
| Modificada | Alta (7.2) | 1.3% | — | Schneider-electric Monitor PROSchneider-electric OPC Factory ServerSchneider-electric PL7 PROSchneider-electric Telemecanique Driver Pack+2 | 4/11/2011 | 16/6/2026 | Buffer overflow in the UnitelWay Windows Device Driver, as used in Schneider Electric Unity Pro 6 and earlier, OPC Factory Server 3.34, Vijeo Citect 7.20 and earlier, Telemecanique Driver Pack 2.6 and earlier, Monitor Pro 7.6 and earlier, and PL7 Pro 4.5 and earlier, allows local users, and possibly remote attackers,… | |
| Modificada | Media (6.8) | 1.5% | — | Jasperforge Jasperreports Server Community Project | 20/9/2011 | 16/6/2026 | JasperServer in JasperReports Server Community Project 3.7.0 and 3.7.1 uses a predictable _flowExecutionKey parameter, which makes it easier for remote attackers to conduct cross-site request forgery (CSRF) attacks via a brute-force approach. |