Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 6 respecto a la semana anterior
Críticas / altas1451▲ 315 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.1) | 0.63% | — | Pilz PasvisuAIPilz PMIAI | 22/6/2026 | 26/9/2026 | A stored cross-site scripting vulnerability in the Runtime component of Pilz PASvisu before 1.14.1 and PMI v8xx up to and including 2.0.33992 allows a low-privileged remote unauthenticated attacker to manipulate process data with potential impact on integrity and/or availability. | |
| Aplazada | Alta (7.8) | 0.21% | — | Pilz PasvisuAI | 22/6/2026 | 26/9/2026 | A cross-site scripting vulnerability in the Builder Component of Pilz PASvisu before 1.14.1 allows a local unauthenticated attacker to inject malicious javascript and gain full control over the device. | |
| Modificada | Media (5.3) | 0.45% | — | Pilz PMC | 26/12/2022 | 17/6/2026 | In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), an attacker can identify valid usernames. | |
| Analizada | Alta (7.8) | 0.16% | — | Pilz PMCCodesys Control FOR BeagleboneCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000+60 | 26/12/2022 | 17/6/2026 | In CODESYS V3 products in all versions prior V3.5.16.0 containing the CmpUserMgr, the CODESYS Control runtime system stores the online communication passwords using a weak hashing algorithm. This can be used by a local attacker with low privileges to gain full control of the device. | |
| Modificada | Alta (7.5) | 0.51% | — | Pilz PMC | 26/12/2022 | 17/6/2026 | In Pilz PMC programming tool 3.x before 3.5.17 (based on CODESYS Development System), a user's password may be changed by an attacker without knowledge of the current password. | |
| Modificada | Alta (7.5) | 0.92% | — | Pilz PasvisuPilz PMI V507 FirmwarePilz PMI V512 FirmwarePilz PMI V704e Firmware+4 | 24/11/2022 | 17/6/2026 | A path traversal vulnerability was discovered in Pilz PASvisu Server before 1.12.0. An unauthenticated remote attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability. | |
| Modificada | Media (5.5) | 0.23% | — | Pilz PAS 4000Pliz PascalPliz PasconnectPliz Pasmotion+1 | 24/11/2022 | 17/6/2026 | A path traversal vulnerability was discovered in multiple Pilz products. An unauthenticated local attacker could use a zipped, malicious configuration file to trigger arbitrary file writes ('zip-slip'). File writes do not affect confidentiality or availability. | |
| Modificada | Alta (7.8) | 0.24% | — | Pilz Pnozmulti Configurator | 25/1/2019 | 17/6/2026 | Pilz PNOZmulti Configurator prior to version 10.9 allows an authenticated attacker with local access to the system containing the PNOZmulti Configurator software to view sensitive credential data in clear-text. This sensitive data is applicable to only the PMI m107 diag HMI device. An attacker with access to this… | |
| Modificada | Alta (7.2) | 0.38% | — | Detlef Pilzecker Proc\ | 28/1/2014 | 17/6/2026 | The Proc::Daemon module 0.14 for Perl uses world-writable permissions for a file that stores a process ID, which allows local users to have an unspecified impact by modifying this file. |