Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2635▼ 213 respecto a la semana anterior
Críticas / altas1376▲ 145 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)81▼ 449 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Crítica (9.3) | 0.89% | — | Automationdirect C-more EA9AI | 4/2/2025 | 17/6/2026 | AutomationDirect C-more EA9 HMI contains a function with bounds checks that can be skipped, which could result in an attacker abusing the function to cause a denial-of-service condition or achieving remote code execution on the affected device. | |
| Analizada | Alta (7.8) | 0.28% | — | Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+5 | 30/1/2025 | 17/6/2026 | AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.28% | — | Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+5 | 30/1/2025 | 17/6/2026 | AutomationDirect C-More EA9 EAP9 File Parsing Memory Corruption Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target must visit a… | |
| Analizada | Alta (7.8) | 0.31% | — | Automationdirect C-more Ea9-t10cl FirmwareAutomationdirect C-more Ea9-t10wcl FirmwareAutomationdirect C-more Ea9-t12cl FirmwareAutomationdirect C-more Ea9-t15cl Firmware+5 | 30/1/2025 | 17/6/2026 | AutomationDirect C-More EA9 EAP9 File Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows remote attackers to execute arbitrary code on affected installations of AutomationDirect C-More EA9. User interaction is required to exploit this vulnerability in that the target… | |
| Aplazada | Media (6.5) | 0.40% | — | Automationdirect C-more EA9AI | 26/3/2024 | 17/6/2026 | In AutomationDirect C-MORE EA9 HMI, credentials used by the platform are stored as plain text on the device. | |
| Aplazada | Media (4.3) | 0.45% | — | Automationdirect C-more EA9AI | 26/3/2024 | 17/6/2026 | In AutomationDirect C-MORE EA9 HMI there is a program that copies a buffer of a size controlled by the user into a limited sized buffer on the stack which may lead to a stack overflow. The result of this stack-based buffer overflow can lead to denial-of-service conditions. | |
| Aplazada | Alta (7.5) | 0.62% | — | Automationdirect C-more EA9AI | 26/3/2024 | 17/6/2026 | There is a function in AutomationDirect C-MORE EA9 HMI that allows an attacker to send a relative path in the URL without proper sanitizing of the content. | |
| Modificada | Alta (7.8) | 0.36% | — | Automationdirect C-more Ea9-t6cl FirmwareAutomationdirect C-more Ea9-t6cl-r FirmwareAutomationdirect C-more Ea9-t7cl FirmwareAutomationdirect C-more Ea9-t7cl-r Firmware+8 | 31/8/2022 | 17/6/2026 | — | |
| Modificada | Alta (7.5) | 0.52% | — | Automationdirect C-more Ea9-t6cl FirmwareAutomationdirect C-more Ea9-t6cl-r FirmwareAutomationdirect C-more Ea9-t7cl FirmwareAutomationdirect C-more Ea9-t7cl-r Firmware+8 | 31/8/2022 | 17/6/2026 | — | |
| Modificada | Crítica (9.8) | 2.4% | — | Automationdirect C-more Ea9-rhi FirmwareAutomationdirect C-more Ea9-t6cl-r FirmwareAutomationdirect C-more Ea9-t6cl FirmwareAutomationdirect C-more Ea9-t7cl-r Firmware+7 | 5/2/2020 | 17/6/2026 | It is possible to unmask credentials and other sensitive information on “unprotected” project files, which may allow an attacker to remotely access the C-More Touch Panels EA9 series: firmware versions prior to 6.53 and manipulate system configurations. |