Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2747▼ 495 respecto a la semana anterior
Críticas / altas1308▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

96 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.3)0.17%—Milesight IOT DevicesAI26/8/20269/9/2026
A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The…
Pendiente de análisisAlta (7.3)1.5%—Milesight Camera FirmwareAI28/4/202625/7/2026
A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras.
Pendiente de análisisCrítica (9.2)0.39%—Milesight Aiot CamerasAI28/4/202625/7/2026
Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys.
Pendiente de análisisAlta (8.6)0.29%—Milesight Aiot Camera FirmwareAI28/4/202620/7/2026
An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras.
Pendiente de análisisAlta (7.7)0.35%—Milesight Aiot Camera FirmwareAI28/4/202625/7/2026
Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials.
Pendiente de análisisAlta (7.3)0.28%—Milesight Aiot CamerasAI27/4/202625/7/2026
A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed.
AnalizadaMedia (6.1)0.35%—Milesight Ug65-868m-ea Firmware7/5/202517/6/2026
An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot.
AnalizadaMedia (6.1)0.27%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')
AnalizadaAlta (7.4)0.35%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic
AnalizadaAlta (7.5)0.42%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service
AnalizadaCrítica (9.8)0.52%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass
AnalizadaCrítica (9.8)0.47%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function
AnalizadaCrítica (9.8)0.60%—Milesight Devicehub2/6/202417/6/2026
MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE
ModificadaAlta (8.8)0.64%—Milesight Ur32l Firmware1/5/202417/6/2026
A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger this vulnerability.
ModificadaMedia (6.1)0.42%—Milesight Ur51 FirmwareMilesight Ur52 FirmwareMilesight Ur55 FirmwareMilesight Ur32l Firmware+35/10/202317/6/2026
Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel.
ModificadaAlta (7.5)64%💥 ExploitMilesight Ur5x FirmwareMilesight Ur32l FirmwareMilesight Ur32 FirmwareMilesight Ur35 Firmware+14/10/20239/7/2026
An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components.
ModificadaAlta (7.2)3.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages a new…
ModificadaAlta (7.2)3.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages an…
ModificadaAlta (7.2)1.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer…
ModificadaAlta (7.2)1.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer…
ModificadaAlta (7.2)1.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer…
ModificadaAlta (7.2)1.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer…
ModificadaAlta (7.2)1.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer…
ModificadaAlta (7.2)1.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer…
ModificadaAlta (7.2)1.5%—Milesight Ur32l Firmware6/7/202317/6/2026
Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer…
Orbitaley — Vulnerabilidades