Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3069▲ 549 respecto a la semana anterior
Críticas / altas1455▲ 270 respecto a la semana anterior
Nueva explotación activa (KEV)8▼ 2 respecto a la semana anterior
Sin puntuar (sin CVSS)383▲ 176 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.7) | 0.90% | — | Cloud Jasperreports IOCloud Jasperreports LibraryCloud Jasperreports ServerCloud Jasperreports Studio+1 | 16/9/2025 | 17/6/2026 | A Java deserialisation vulnerability has been discovered in Jaspersoft Library. Improper handling of externally supplied data may allow attackers to execute arbitrary code remotely on systems that use the affected library | |
| Modificada | Alta (7.5) | 14% | — | Aveva Indusoft WEB StudioAveva Intouch Machine Edition 2014 | 13/2/2019 | 17/6/2026 | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. An unauthenticated remote user could use a specially crafted database connection configuration file to execute an arbitrary process on the server machine. | |
| Modificada | Crítica (9.8) | 17% | — | Aveva Indusoft WEB StudioAveva Intouch Machine Edition 2014 | 13/2/2019 | 17/6/2026 | AVEVA Software, LLC InduSoft Web Studio prior to Version 8.1 SP3 and InTouch Edge HMI (formerly InTouch Machine Edition) prior to Version 2017 Update. Code is executed under the program runtime privileges, which could lead to the compromise of the machine. | |
| Modificada | Crítica (9.8) | 3.7% | — | Aveva Indusoft WEB StudioAveva EdgeAveva Intouch Machine Edition 2014 | 2/11/2018 | 17/6/2026 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. A remote attacker could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with… | |
| Modificada | Crítica (9.8) | 4.6% | — | Aveva Indusoft WEB StudioAveva EdgeAveva Intouch Machine Edition 2014 | 2/11/2018 | 17/6/2026 | InduSoft Web Studio versions prior to 8.1 SP2, and InTouch Edge HMI (formerly InTouch Machine Edition) versions prior to 2017 SP2. This vulnerability could allow an unauthenticated user to remotely execute code with the same privileges as that of the InduSoft Web Studio or InTouch Edge HMI (formerly InTouch Machine… | |
| Modificada | Crítica (9.8) | 4.2% | — | Aveva Indusoft WEB StudioAveva Intouch Machine 2017 | 19/7/2018 | 17/6/2026 | AVEVA InduSoft Web Studio v8.1 and v8.1SP1, and InTouch Machine Edition v2017 8.1 and v2017 8.1 SP1 a remote user could send a carefully crafted packet to exploit a stack-based buffer overflow vulnerability during tag, alarm, or event related actions such as read and write, with potential for code to be executed. | |
| Modificada | Crítica (9.8) | 8.6% | — | Indusoft WEB StudioIndustrial-software Intouch Machine Edition 2017 | 18/4/2018 | 17/6/2026 | A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution. | |
| Modificada | Crítica (9.8) | 5.8% | — | Schneider-electric Wonderware Indusoft WEB StudioSchneider-electric Wonderware Intouch | 13/11/2017 | 17/6/2026 | A Stack-based Buffer Overflow issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 Patch 1 and prior versions, and InTouch Machine Edition v8.0 SP2 Patch 1 and prior versions. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution with high… | |
| Modificada | Crítica (9.8) | 5.1% | — | Schneider-electric Wonderware Indusoft WEB StudioSchneider-electric Wonderware Intouch | 3/10/2017 | 17/6/2026 | A Missing Authentication for Critical Function issue was discovered in Schneider Electric InduSoft Web Studio v8.0 SP2 or prior, and InTouch Machine Edition v8.0 SP2 or prior. InduSoft Web Studio provides the capability for an HMI client to trigger script execution on the server for the purposes of performing… | |
| Modificada | Alta (7.8) | 0.43% | — | Schneider-electric Wonderware Indusoft WEB Studio | 19/5/2017 | 17/6/2026 | An Incorrect Default Permissions issue was discovered in Schneider Electric Wonderware InduSoft Web Studio v8.0 Patch 3 and prior versions. Upon installation, Wonderware InduSoft Web Studio creates a new directory and two files, which are placed in the system's path and can be manipulated by non-administrators. This… | |
| Modificada | Alta (7.5) | 2.2% | — | Indusoft WEB Studio | 25/9/2015 | 17/6/2026 | Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code or cause a denial of service (unhandled runtime exception and application crash) via a crafted Indusoft Project file. | |
| Modificada | Alta (7.5) | 2.9% | — | Indusoft WEB Studio | 25/9/2015 | 17/6/2026 | The Remote Agent component in Schneider Electric InduSoft Web Studio before 8.0 allows remote attackers to execute arbitrary code via unspecified vectors, aka ZDI-CAN-2649. | |
| Modificada | Baja (1.7) | 0.32% | — | Indusoft WEB StudioWonderware Intouch | 1/8/2015 | 17/6/2026 | Schneider Electric InduSoft Web Studio before 7.1.3.5 Patch 5 and Wonderware InTouch Machine Edition through 7.1 SP3 Patch 4 use cleartext for project-window password storage, which allows local users to obtain sensitive information by reading a file. | |
| Analizada | Crítica (9.8) | 75% | ⚠ Explotación activa | Indusoft WEB Studio | 25/4/2014 | 17/6/2026 | Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 7.1 before SP2 Patch 4 allows remote attackers to read administrative passwords in APP files, and consequently execute arbitrary code, via unspecified web requests. | |
| Modificada | Alta (7.8) | 3.4% | — | Advantech StudioIndusoft WEB Studio | 11/3/2013 | 16/6/2026 | Absolute path traversal vulnerability in NTWebServer.exe in Indusoft Studio 7.0 and earlier and Advantech Studio 7.0 and earlier allows remote attackers to read arbitrary files via a full pathname in an argument to the sub_401A90 CreateFileW function. | |
| Modificada | Alta (9.3) | 5.7% | — | Indusoft WEB Studio | 5/12/2011 | 16/6/2026 | Stack-based buffer overflow in CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 allows remote attackers to execute arbitrary code via a crafted 0x15 (aka Remove File) operation for a file with a long name. | |
| Modificada | Alta (10) | 69% | — | Indusoft WEB Studio | 5/12/2011 | 16/6/2026 | CEServer.exe in the CEServer component in the Remote Agent module in InduSoft Web Studio 6.1 and 7.0 does not require authentication, which allows remote attackers to execute arbitrary code via vectors related to creation of a file, loading a DLL, and process control. | |
| Modificada | Alta (10) | 5.9% | — | Indusoft WEB Studio | 2/9/2011 | 16/6/2026 | Multiple buffer overflows in the InduSoft ISSymbol ActiveX control in ISSymbol.ocx 301.1104.601.0 in InduSoft Web Studio 7.0B2 hotfix 7.0.01.04 allow remote attackers to execute arbitrary code via a long parameter to the (1) Open, (2) Close, or (3) SetCurrentLanguage method. | |
| Modificada | Alta (10) | 32% | — | Indusoft WEB Studio | 4/5/2011 | 16/6/2026 | Directory traversal vulnerability in NTWebServer in InduSoft Web Studio 6.1 and 7.x before 7.0+Patch 1 allows remote attackers to execute arbitrary code via an invalid request. | |
| Modificada | Alta (9.3) | 32% | — | Advantech StudioIndusoft Thin ClientIndusoft WEB Studio | 4/5/2011 | 16/6/2026 | Multiple buffer overflows in the ISSymbol ActiveX control in ISSymbol.ocx 61.6.0.0 and 301.1009.2904.0 in the ISSymbol virtual machine, as distributed in Advantech Studio 6.1 SP6 61.6.01.05, InduSoft Web Studio before 7.0+SP1, and InduSoft Thin Client 7.0, allow remote attackers to execute arbitrary code via a long… | |
| Modificada | Alta (10) | 8.6% | — | Advantech StudioIndusoft WEB Studio | 18/1/2011 | 16/6/2026 | Stack-based buffer overflow in NTWebServer.exe in the test web service in InduSoft NTWebServer, as distributed in Advantech Studio 6.1 and InduSoft Web Studio 7.0, allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a long request to TCP port 80. | |
| Modificada | Alta (7.5) | 1.0% | — | PLX WEB Studio PLX AD Trader | 7/7/2008 | 16/6/2026 | SQL injection vulnerability in ad.php in plx Ad Trader 3.2 allows remote attackers to execute arbitrary SQL commands via the adid parameter in a redir action. | |
| Modificada | Alta (7.5) | 1.2% | — | Lotus WEB Studios INC Smoothflash | 2/4/2008 | 16/6/2026 | SQL injection vulnerability in admin_view_image.php in Smoothflash allows remote attackers to execute arbitrary SQL commands via the cid parameter. | |
| Modificada | Alta (7.5) | 1.8% | — | PLX WEB Studio PLX PAY | 8/12/2006 | 16/6/2026 | Directory traversal vulnerability in index.php in plx Web Studio (aka plxWebDev) plx Pay 3.2 and earlier allows remote attackers to include and execute arbitrary local files, or obtain user credentials and other sensitive information, via a .. (dot dot) in the read parameter. NOTE: The provenance of this information… |