Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.17% | — | Softing Uatoolkit EmbeddedAI | 2/4/2024 | 17/6/2026 | An issue was discovered in Softing uaToolkit Embedded before 1.41.1. When a subscription with a very low MaxNotificationPerPublish parameter is created, a publish response is mishandled, leading to memory consumption. When that happens often enough, the device will be out of memory, i.e., a denial of service. | |
| Modificada | Alta (7.5) | 0.88% | — | Softing Uatoolkit Embedded | 26/1/2023 | 17/6/2026 | In Softing uaToolkit Embedded before 1.41, a malformed CreateMonitoredItems request may cause a memory leak. | |
| Modificada | Alta (7.5) | 0.84% | — | Softing Uatoolkit Embedded | 26/1/2023 | 17/6/2026 | In Softing uaToolkit Embedded before 1.40.1, a malformed PubSub discovery announcement message can cause a NULL pointer dereference or out-of-bounds memory access in the subscriber application. | |
| Modificada | Alta (7.5) | 1.3% | — | Softing Datafeed OPC SuiteSofting EdgeconnectorSofting OPCSofting Secure Integration Server+3 | 10/11/2021 | 17/6/2026 | An issue was discovered in Softing Industrial Automation OPC UA C++ SDK before 5.66, and uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) by sending crafted messages to a client or server. The server process may crash unexpectedly because of a double free, and must be restarted. | |
| Modificada | Alta (7.5) | 1.5% | — | Softing Smartlink Hw-dpSofting Uatoolkit Embedded | 10/11/2021 | 17/6/2026 | An issue was discovered in Softing Industrial Automation uaToolkit Embedded before 1.40. Remote attackers to cause a denial of service (DoS) or login as an anonymous user (bypassing security checks) by sending crafted messages to a OPC/UA server. The server process may crash unexpectedly because of an invalid type… |