Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3017▼ 66 respecto a la semana anterior
Críticas / altas1412▲ 56 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
16 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.6% | — | Invensys Wonderware Information Server | 28/8/2014 | 17/6/2026 | SQL injection vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.56% | — | Invensys Wonderware Information Server | 28/8/2014 | 17/6/2026 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to read arbitrary files or cause a denial of service via an XML external entity declaration in conjunction with an entity reference, related to an XML External Entity (XXE) issue. | |
| Modificada | Media (4.3) | 1.5% | — | Invensys Wonderware Information Server | 28/8/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Baja (2.1) | 0.14% | — | Invensys Wonderware Information Server | 28/8/2014 | 17/6/2026 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows local users to obtain sensitive information by reading a credential file. | |
| Modificada | Alta (7.8) | 0.75% | — | Invensys Wonderware Information Server | 28/8/2014 | 17/6/2026 | Schneider Electric Wonderware Information Server (WIS) Portal 4.0 SP1 through 5.5 uses weak encryption, which allows remote attackers to obtain sensitive information by reading a credential file. | |
| Modificada | Media (4.3) | 1.0% | — | Invensys Wonderware Information Server | 9/5/2013 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 2.1% | — | Invensys Wonderware Information Server | 9/5/2013 | 16/6/2026 | Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to read arbitrary files, send HTTP requests to intranet servers, or cause a denial of service (CPU and memory consumption) via an XML document containing an external entity declaration in conjunction with an… | |
| Modificada | Alta (9.3) | 3.3% | — | Invensys Wonderware Information Server | 9/5/2013 | 16/6/2026 | Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal does not restrict unspecified size and amount values, which allows remote attackers to execute arbitrary code or cause a denial of service (resource consumption) via unknown vectors. | |
| Modificada | Alta (7.5) | 1.3% | — | Invensys Wonderware Information Server | 9/5/2013 | 16/6/2026 | SQL injection vulnerability in Invensys Wonderware Information Server (WIS) 4.0 SP1SP1, 4.5- Portal, and 5.0- Portal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.9) | 0.45% | — | Invensys Foxboro Control SoftwareInvensys Infusion Ce/fe/scadaInvensys IntouchInvensys Intouch/wonderware Application Server+3 | 26/7/2012 | 16/6/2026 | Untrusted search path vulnerability in Invensys Wonderware InTouch 2012 and earlier, as used in Wonderware Application Server, Wonderware Information Server, Foxboro Control Software, InFusion CE/FE/SCADA, InBatch, and Wonderware Historian, allows local users to gain privileges via a Trojan horse DLL in an unspecified… | |
| Modificada | Media (6.8) | 3.2% | — | Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+4 | 2/4/2012 | 16/6/2026 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit… | |
| Modificada | Media (6.8) | 3.2% | — | Invensys Archestra Application Object ToolkitInvensys Foxboro Control SoftwareInvensys Infusion Control EditionInvensys Infusion Foundation Edition+4 | 2/4/2012 | 16/6/2026 | Heap-based buffer overflow in the WWCabFile ActiveX component in the Wonderware System Platform in Invensys Wonderware Application Server 2012 and earlier, Foxboro Control Software 3.1 and earlier, InFusion CE/FE/SCADA 2.5 and earlier, Wonderware Information Server 4.5 and earlier, ArchestrA Application Object Toolkit… | |
| Modificada | Alta (7.5) | 2.2% | — | Invensys Wonderware Information Server | 2/4/2012 | 16/6/2026 | Invensys Wonderware Information Server 4.0 SP1 and 4.5 does not properly implement client controls, which allows remote attackers to bypass intended access restrictions via unspecified vectors. | |
| Modificada | Alta (7.5) | 1.7% | — | Invensys Wonderware Information Server | 2/4/2012 | 16/6/2026 | SQL injection vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | Invensys Wonderware Information Server | 2/4/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in Invensys Wonderware Information Server 4.0 SP1 and 4.5 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (9.3) | 4.6% | — | Invensys Wonderware Information Server | 29/7/2011 | 16/6/2026 | Multiple stack-based buffer overflows in Invensys Wonderware Information Server 3.1, 4.0, and 4.0 SP1 allow remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via two unspecified ActiveX controls. |