Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2737▼ 484 respecto a la semana anterior
Críticas / altas1302▼ 187 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
1785 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 3.7% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the ys_thirdparty system_user_script functionality of Milesight UR32L v32.3.0.5. A specially crafted series of network requests can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.0% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This OS command injection is triggered… | |
| Modificada | Alta (8.8) | 3.0% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Two OS command injection vulnerabilities exist in the urvpn_client cmd_name_action functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger these vulnerabilities.This OS command injection is triggered… | |
| Modificada | Alta (8.8) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the trace tool… | |
| Modificada | Alta (8.8) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Two OS command injection vulnerability exist in the vtysh_ubus toolsh_excute.constprop.1 functionality of Milesight UR32L v32.3.0.5. A specially-crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the ping tool… | |
| Modificada | Media (4.7) | 0.57% | — | O Milesight | 6/7/2023 | 17/6/2026 | Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the… | |
| Modificada | Media (4.7) | 0.57% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | Cross-site scripting (xss) vulnerabilities exist in the requestHandlers.js detail_device functionality of Milesight VPN v2.0.2. A specially-crafted HTTP request can lead to arbitrary Javascript code injection. An attacker can send an HTTP request to trigger these vulnerabilities.This XSS is exploited through the name… | |
| Modificada | Alta (8.1) | 0.98% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the urvpn_client http_connection_readcb functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to a buffer overflow. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the libzebra.so.0.0.0 security_decrypt_password functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to a buffer overflow. An authenticated attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.2% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | A directory traversal vulnerability exists in the server.js start functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.2% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A buffer overflow vulnerability exists in the uhttpd login functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to remote code execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.1% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An access violation vulnerability exists in the eventcore functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to denial of service. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Media (6.5) | 1.3% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 0.56% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.76% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 3.7% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 5.8% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An authenticated attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 3.4% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to command execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 2.2% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted set of network packets can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.90% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. |