Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

77 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (7.1)0.18%—ABB Ac800mAIABB Symphony Plus SD SeriesAIABB Symphony Plus MRAIABB S+ OperationsAI+313/4/202617/6/2026
A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a specially crafted 61850 packet, forcing the communication interfaces of the PM…
AplazadaAlta (7.5)0.64%—Senstar SymphonyAI23/12/202517/6/2026
Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Senstar Symphony. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of…
ModificadaCrítica (9.1)0.36%—Symphonyfintech XTS Mobile TraderSymphonyfintech XTS WEB Trader3/9/202417/6/2026
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module of the application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to unauthorized…
ModificadaCrítica (9.1)0.42%—Symphonyfintech XTS Mobile TraderSymphonyfintech XTS WEB Trader3/9/202417/6/2026
This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to…
ModificadaCrítica (9.2)0.43%—Symphonyfintech XTS Mobile TraderSymphonyfintech XTS WEB Trader3/9/202417/6/2026
This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platforms (version 2.0.0.1_P160). An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to…
ModificadaMedia (4.8)0.37%—Symphony-cms Symphony CMS13/8/202417/6/2026
symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles.
AnalizadaMedia (5.4)0.43%—Symphony-cms Symphony CMS13/8/202417/6/2026
A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note.
AplazadaAlta (7.5)0.61%—ABB Symphony Plus S+ OperationsAIABB Symphony Plus S+ EngineeringAIABB Symphony Plus S+ AnalystAI3/4/202417/6/2026
ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3,…
ModificadaCrítica (9.8)1.2%—B3log Symphony5/2/202417/6/2026
An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component.
ModificadaMedia (6.1)0.41%—IBM Spectrum Symphony10/3/202317/6/2026
IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 247030.
ModificadaAlta (8.8)0.35%—ABB Symphony Plus S+ Operations2/3/202317/6/2026
Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2.
ModificadaCrítica (9.1)1.4%—Getsymphony Symphony31/10/20219/7/2026
A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS).
ModificadaCrítica (9.8)1.5%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network…
ModificadaAlta (7)0.28%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database.
ModificadaCrítica (9.8)1.9%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted.
ModificadaAlta (8.8)1.5%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges.
ModificadaAlta (8.8)1.4%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data.
ModificadaAlta (7.8)0.43%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as.
ModificadaCrítica (9.8)1.2%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process.
ModificadaAlta (8.8)3.1%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines.
ModificadaCrítica (9.8)1.1%—ABB Symphony + HistorianABB Symphony + Operations22/12/202017/6/2026
In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some…
ModificadaMedia (5.4)0.71%—Getsymphony Symphony7/10/202017/6/2026
Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php
ModificadaAlta (8.8)2.0%—Senstar Symphony1/9/202017/6/2026
This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSOAuth process. The issue results from the lack of proper validation of user-supplied…
ModificadaMedia (6.1)0.70%—Getsymphony Symphony11/8/202017/6/2026
content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading.
ModificadaMedia (5.5)0.29%—Symphony-mobile I95 Lite Firmware14/11/201917/6/2026
The Symphony i95 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system…