Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

230 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisMedia (6.1)0.30%—Advantech Webaccess ScadaAI22/5/202623/7/2026
Cross Site Scripting vulnerability in Advantech WebAccess/SCADA 8.0-2015.08.16 allows a remote attacker to obtain sensitive information via the decryption field in the Create New Project User component
AnalizadaMedia (5.3)0.73%—Advantech Webaccess/scada18/12/202517/6/2026
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to determine the existence of arbitrary files.
AnalizadaMedia (5.3)0.34%—Advantech Webaccess/scada18/12/202517/6/2026
Advantech WebAccess/SCADA is vulnerable to SQL injection, which may allow an attacker to execute arbitrary SQL commands.
AnalizadaAlta (7.2)0.95%—Advantech Webaccess/scada18/12/202517/6/2026
Advantech WebAccess/SCADA is vulnerable to directory traversal, which may allow an attacker to delete arbitrary files.
AnalizadaMedia (5.3)0.67%—Advantech Webaccess/scada18/12/202517/6/2026
Advantech WebAccess/SCADA is vulnerable to absolute directory traversal, which may allow an attacker to determine the existence of arbitrary files.
AnalizadaAlta (8.7)0.62%—Advantech Webaccess/scada18/12/202530/9/2026
Advantech WebAccess/SCADA is vulnerable to unrestricted file upload, which may allow an attacker to remotely execute arbitrary code.
AnalizadaMedia (5.1)0.29%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in NetworksController.addNetworkAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
AnalizadaMedia (5.3)0.29%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxPrevalidationController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
AnalizadaMedia (5.3)0.29%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxStandaloneVpnClientsController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
AnalizadaMedia (5.3)0.29%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxDeviceFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
AnalizadaMedia (5.3)0.29%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxFwRulesController.ajaxNetworkFwRulesAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
AnalizadaAlta (8.6)0.29%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxNetworkController.ajaxAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
AnalizadaMedia (5.3)0.29%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AjaxDeviceController.ajaxDeviceAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
AnalizadaAlta (8.6)0.29%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a SQL injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated low-privileged observer user to inject SQL via datatable search parameters, leading to disclosure of database information.
AnalizadaAlta (8.6)1.7%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a command injection vulnerability in AppManagementController.appUpgradeAction() that allows an authenticated system administrator to execute arbitrary commands as the web server user (www-data) by supplying a crafted uploaded filename.
AnalizadaMedia (6.9)0.38%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain an absolute path traversal via AjaxStandaloneVpnClientsController.ajaxDownloadRoadWarriorConfigFileAction() that allows an authenticated network administrator to cause the application to read and return the contents of arbitrary files the web user (www-data) can…
AnalizadaMedia (6.3)0.20%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via StandaloneVpnClientsController.addStandaloneVpnClientAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a…
AnalizadaMedia (6.2)0.21%—Advantech Webaccess/vpn6/11/202517/6/2026
Advantech WebAccess/VPN versions prior to 1.1.5 contain a stored cross-site scripting (XSS) vulnerability via NetworksController.addNetworkAction(). Insufficient validation or escaping of user-supplied input may allow an attacker to inject and execute arbitrary script in the context of a victim's browser.
AplazadaMedia (6.4)0.30%—Advantech Webaccess ScadaAI21/3/202417/6/2026
There is an SQL injection vulnerability in Advantech WebAccess/SCADA software that allows an authenticated attacker to remotely inject SQL code in the database. Successful exploitation of this vulnerability could allow an attacker to read or modify data on the remote database.
ModificadaAlta (7.5)0.46%—Advantech Webaccess17/10/202317/6/2026
Advantech WebAccess version 9.1.3 contains an exposure of sensitive information to an unauthorized actor vulnerability that could leak user credentials.
ModificadaCrítica (9.8)2.8%—Advantech Webaccess/scada2/8/202317/6/2026
All versions prior to 9.1.4 of Advantech WebAccess/SCADA are vulnerable to use of untrusted pointers. The RPC arguments the client sent could contain raw memory pointers for the server to use as-is. This could allow an attacker to gain access to the remote file system and the ability to execute commands and overwrite…
ModificadaAlta (7.8)0.14%—Advantech Webaccess7/6/202317/6/2026
If an attacker can trick an authenticated user into loading a maliciously crafted .zip file onto Advantech WebAccess version 8.4.5, a web shell could be used to give the attacker full control of the SCADA server.
ModificadaCrítica (9.8)0.71%—Advantech Webaccess/scada6/6/202317/6/2026
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to modify the file extension of a certificate file to ASP when uploading it, which can lead to remote code execution.
ModificadaCrítica (9.8)0.90%—Advantech Webaccess/scada6/6/202317/6/2026
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file overwrite vulnerability, which could allow an attacker to overwrite any file in the operating system (including system files), inject code into an XLS file, and modify the file extension, which could lead to arbitrary code execution.
ModificadaAlta (7.2)0.83%—Advantech Webaccess/scada6/6/202317/6/2026
In Advantech WebAccss/SCADA v9.1.3 and prior, there is an arbitrary file upload vulnerability that could allow an attacker to upload an ASP script file to a webserver when logged in as manager user, which can lead to arbitrary code execution.