Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2853▼ 343 respecto a la semana anterior
Críticas / altas1376▼ 50 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
41 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an… | |
| Modificada | Alta (8.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an… | |
| Modificada | Alta (8.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an… | |
| Modificada | Alta (8.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an… | |
| Modificada | Alta (8.8) | 0.82% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to… | |
| Modificada | Alta (8.8) | 0.82% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to… | |
| Modificada | Alta (8.8) | 0.82% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to… | |
| Modificada | Alta (8.8) | 0.82% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to… | |
| Modificada | Crítica (9.8) | 0.92% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and… | |
| Modificada | Crítica (9.8) | 0.92% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and… | |
| Modificada | Crítica (9.8) | 0.92% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and… | |
| Modificada | Crítica (9.8) | 0.92% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and… | |
| Modificada | Crítica (9.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a malicious XML payload to trigger this… | |
| Modificada | Crítica (9.8) | 0.97% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption, information disclosure and denial of service. An attacker can send a malicious XML payload to… | |
| Modificada | Crítica (9.9) | 4.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these… | |
| Modificada | Crítica (9.9) | 4.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these… | |
| Modificada | Crítica (9.9) | 4.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these… | |
| Modificada | Crítica (9.9) | 4.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these… | |
| Modificada | Crítica (10) | 3.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on… | |
| Modificada | Crítica (10) | 3.2% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on… | |
| Modificada | Crítica (10) | 3.2% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically… | |
| Modificada | Crítica (10) | 3.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically… | |
| Modificada | Crítica (9.8) | 3.5% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | An OS command injection vulnerability exists in the XCMD setAlexa functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.5% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | An integer overflow vulnerability exists in the web interface /action/ipcamRecordPost functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to memory corruption. An attacker can make an authenticated HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 3.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | An OS command injection vulnerability exists in the XCMD doDebug functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to arbitrary command execution. An attacker can send a malicious XML payload to trigger this vulnerability. |