Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3062▲ 584 respecto a la semana anterior
Críticas / altas1459▲ 293 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
77 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.18% | — | ABB Ac800mAIABB Symphony Plus SD SeriesAIABB Symphony Plus MRAIABB S+ OperationsAI+3 | 13/4/2026 | 17/6/2026 | A vulnerability exists in the command handling of the IEC 61850 communication stack included in the product revisions listed as affected in this CVE. An attacker with access to IEC 61850 networks could exploit the vulnera bility by using a specially crafted 61850 packet, forcing the communication interfaces of the PM… | |
| Aplazada | Alta (7.5) | 0.64% | — | Senstar SymphonyAI | 23/12/2025 | 17/6/2026 | Senstar Symphony FetchStoredLicense Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Senstar Symphony. Authentication is not required to exploit this vulnerability. The specific flaw exists within the implementation of… | |
| Modificada | Crítica (9.1) | 0.36% | — | Symphonyfintech XTS Mobile TraderSymphonyfintech XTS WEB Trader | 3/9/2024 | 17/6/2026 | This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Preference module of the application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to unauthorized… | |
| Modificada | Crítica (9.1) | 0.42% | — | Symphonyfintech XTS Mobile TraderSymphonyfintech XTS WEB Trader | 3/9/2024 | 17/6/2026 | This vulnerability exists in Symphony XTS Web Trading platform version 2.0.0.1_P160 due to improper access controls on APIs in the Transaction module of vulnerable application. An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to… | |
| Modificada | Crítica (9.2) | 0.43% | — | Symphonyfintech XTS Mobile TraderSymphonyfintech XTS WEB Trader | 3/9/2024 | 17/6/2026 | This vulnerability exists due to improper access controls on APIs in the Authentication module of Symphony XTS Web Trading and Mobile Trading platforms (version 2.0.0.1_P160). An authenticated remote attacker could exploit this vulnerability by manipulating parameters through HTTP request which could lead to… | |
| Modificada | Media (4.8) | 0.37% | — | Symphony-cms Symphony CMS | 13/8/2024 | 17/6/2026 | symphonycms <=2.7.10 is vulnerable to Cross Site Scripting (XSS) in the Comment component for articles. | |
| Analizada | Media (5.4) | 0.43% | — | Symphony-cms Symphony CMS | 13/8/2024 | 17/6/2026 | A Cross Site Scripting (XSS) vulnerability in Symphony CMS 2.7.10 allows remote attackers to inject arbitrary web script or HTML by editing note. | |
| Aplazada | Alta (7.5) | 0.61% | — | ABB Symphony Plus S+ OperationsAIABB Symphony Plus S+ EngineeringAIABB Symphony Plus S+ AnalystAI | 3/4/2024 | 17/6/2026 | ABB has internally identified a vulnerability in the ABB VPNI feature of the S+ Control API component which may be used by several Symphony Plus products (e.g., S+ Operations, S+ Engineering and S+ Analyst) This issue affects Symphony Plus S+ Operations: from 3..0;0 through 3.3 SP1 RU4, from 2.1;0 through 2.1 SP2 RU3,… | |
| Modificada | Crítica (9.8) | 1.2% | — | B3log Symphony | 5/2/2024 | 17/6/2026 | An issue in symphony v.3.6.3 and before allows a remote attacker to execute arbitrary code via the log4j component. | |
| Modificada | Media (6.1) | 0.41% | — | IBM Spectrum Symphony | 10/3/2023 | 17/6/2026 | IBM Spectrum Symphony 7.3 is vulnerable to HTTP header injection, caused by improper validation of input by the HOST headers. This could allow an attacker to conduct various attacks against the vulnerable system, including cross-site scripting, cache poisoning or session hijacking. IBM X-Force ID: 247030. | |
| Modificada | Alta (8.8) | 0.35% | — | ABB Symphony Plus S+ Operations | 2/3/2023 | 17/6/2026 | Improper Authentication vulnerability in ABB Symphony Plus S+ Operations.This issue affects Symphony Plus S+ Operations: from 2.X through 2.1 SP2, 2.2, from 3.X through 3.3 SP1, 3.3 SP2. | |
| Modificada | Crítica (9.1) | 1.4% | — | Getsymphony Symphony | 31/10/2021 | 9/7/2026 | A XML External Entity (XXE) vulnerability was discovered in symphony\lib\toolkit\class.xmlelement.php in Symphony 2.7.10 which can lead to an information disclosure or denial of service (DOS). | |
| Modificada | Crítica (9.8) | 1.5% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | The affected versions of S+ Operations (version 2.1 SP1 and earlier) used an approach for user authentication which relies on validation at the client node (client-side authentication). This is not as secure as having the server validate a client application before allowing a connection. Therefore, if the network… | |
| Modificada | Alta (7) | 0.28% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In S+ Operations and S+ Historian, the passwords of internal users (not Windows Users) are encrypted but improperly stored in a database. | |
| Modificada | Crítica (9.8) | 1.9% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | A S+ Operations and S+ Historian service is subject to a DoS by special crafted messages. An attacker might use this flaw to make it crash or even execute arbitrary code on the machine where the service is hosted. | |
| Modificada | Alta (8.8) | 1.5% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | An authenticated user might execute malicious code under the user context and take control of the system. S+ Operations or S+ Historian database is affected by multiple vulnerabilities such as the possibility to allow remote authenticated users to gain high privileges. | |
| Modificada | Alta (8.8) | 1.4% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | Vulnerabilities in the S+ Operations and S+ Historian web applications can lead to a possible code execution and privilege escalation, redirect the user somewhere else or download unwanted data. | |
| Modificada | Alta (7.8) | 0.43% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In Symphony Plus Operations and Symphony Plus Historian, some services can be vulnerable to privilege escalation attacks. An unprivileged (but authenticated) user could execute arbitrary code and result in privilege escalation, depending on the user that the service runs as. | |
| Modificada | Crítica (9.8) | 1.2% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In S+ Operations and S+ History, it is possible that an unauthenticated user could inject values to the Operations History server (or standalone S+ History server) and ultimately write values to the controlled process. | |
| Modificada | Alta (8.8) | 3.1% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In S+ Operations and S+ Historian, not all client commands correctly check user permission as expected. Authenticated but Unauthorized remote users could execute a Denial-of-Service (DoS) attack, execute arbitrary code, or obtain more privilege than intended on the machines. | |
| Modificada | Crítica (9.8) | 1.1% | — | ABB Symphony + HistorianABB Symphony + Operations | 22/12/2020 | 17/6/2026 | In S+ Operations and S+ Historian, a successful SQL injection exploit can read sensitive data from the database, modify database data (Insert/Update/Delete), execute administration operations on the database (such as shutdown the DBMS), recover the content of a given file present on the DBMS file system and in some… | |
| Modificada | Media (5.4) | 0.71% | — | Getsymphony Symphony | 7/10/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerabilities in Symphony CMS 3.0.0 allow remote attackers to inject arbitrary web script or HTML to fields['body'] param via events\event.publish_article.php | |
| Modificada | Alta (8.8) | 2.0% | — | Senstar Symphony | 1/9/2020 | 17/6/2026 | This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Senstar Symphony 7.3.2.2. Authentication is not required to exploit this vulnerability. The specific flaw exists within the SSOAuth process. The issue results from the lack of proper validation of user-supplied… | |
| Modificada | Media (6.1) | 0.70% | — | Getsymphony Symphony | 11/8/2020 | 17/6/2026 | content/content.blueprintsevents.php in Symphony CMS 3.0.0 allows XSS via fields['name'] to appendSubheading. | |
| Modificada | Media (5.5) | 0.29% | — | Symphony-mobile I95 Lite Firmware | 14/11/2019 | 17/6/2026 | The Symphony i95 Lite Android device with a build fingerprint of LAVA/iris88_lite/iris88_lite:8.1.0/O11019/1536323070:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system… |