Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

475 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.9%—Ecos Embedded WEB Servers17/7/201717/6/2026
SYN Flood or FIN Flood attack in ECos 1 and other versions embedded devices results in web Authentication Bypass. "eCos Embedded Web Servers used by Multiple Routers and Home devices, while sending SYN Flood or FIN Flood packets fails to validate and handle the packets and does not ask for any sign of authentication…
ModificadaAlta (7.5)12%💥 ExploitCesanta Mongoose Embedded WEB Server LibraryCesanta Mongoose OS10/4/201717/6/2026
Use-after-free vulnerability in the mg_http_multipart_wait_for_boundary function in mongoose.c in Cesanta Mongoose Embedded Web Server Library 6.7 and earlier and Mongoose OS 1.2 and earlier allows remote attackers to cause a denial of service (crash) via a multipart/form-data POST request without a MIME boundary…
ModificadaAlta (8.8)1.7%—Embedthis Goahead13/3/201717/6/2026
A command-injection vulnerability exists in a web application on a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models. The mail-sending form in the mail.htm page allows an attacker to inject a command into the receiver1 field in the form; it will be executed with root…
ModificadaCrítica (9.8)22%—Embedthis Goahead13/3/201717/6/2026
A vulnerability in a custom-built GoAhead web server used on Foscam, Vstarcam, and multiple white-label IP camera models allows an attacker to craft a malformed HTTP ("GET system.ini HTTP/1.1\n\n" - note the lack of "/" in the path field of the request) request that will disclose the configuration file with the login…
ModificadaCrítica (9.1)4.3%—Beckhoff Embedded PC ImagesBeckhoff Twincat5/10/201617/6/2026
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components might allow remote attackers to obtain access via the (1) Windows CE Remote Configuration Tool, (2) CE Remote Display service, or (3) TELNET service.
ModificadaCrítica (9.1)4.8%—Beckhoff Embedded PC ImagesBeckhoff Twincat5/10/201617/6/2026
Beckhoff Embedded PC images before 2014-10-22 and Automation Device Specification (ADS) TwinCAT components do not restrict the number of authentication attempts, which makes it easier for remote attackers to obtain access via a brute-force attack.
ModificadaAlta (7.3)1.2%—Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+18/6/201617/6/2026
Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security: Server Advanced Server (DCS:SA) 6.x before 6.5 MP1 and…
ModificadaAlta (7.6)5.3%—Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+18/6/201617/6/2026
Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center…
ModificadaAlta (8)2.4%—Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+18/6/201617/6/2026
Directory traversal vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center…
ModificadaAlta (8.8)1.5%—Broadcom Symantec Critical System ProtectionBroadcom Symantec Data Center Security ServerBroadcom Symantec Data Center Security Server AND AgentsBroadcom Symantec Embedded Security Critical System Protection+18/6/201617/6/2026
SQL injection vulnerability in the Management Server in Symantec Embedded Security: Critical System Protection (SES:CSP) 1.0.x before 1.0 MP5, Embedded Security: Critical System Protection for Controllers and Devices (SES:CSP) 6.5.0 before MP1, Critical System Protection (SCSP) before 5.2.9 MP6, Data Center Security:…
ModificadaAlta (7.5)3.0%—Cisco Dpq3925 8X4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter9/3/201617/6/2026
The administration interface on Cisco DPQ3925 devices with firmware r1 allows remote attackers to cause a denial of service (device restart) via a crafted HTTP request, aka Bug ID CSCup48105.
ModificadaMedia (5)2.4%—Cisco Dpq3925 8X4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter18/12/201517/6/2026
Cisco DPQ3925 devices with EDVA r1 Base allow remote attackers to obtain sensitive information via a crafted HTTP request, aka Bug ID CSCuv03958.
ModificadaMedia (4.3)7.2%💥 ExploitCisco Epc3928 Docsis 3.0 8X4 Wireless Residential Gateway With Embedded Digital Voice Adapter14/12/201517/6/2026
Cross-site scripting (XSS) vulnerability in the management interface on Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allows remote attackers to inject arbitrary web script or HTML via an unspecified value, aka Bug ID CSCux24935.
ModificadaAlta (7.5)7.6%💥 ExploitCisco Epc3928 Docsis 3.0 8X4 Wireless Residential Gateway With Embedded Digital Voice Adapter14/12/201517/6/2026
Cisco EPC3928 devices with EDVA 5.5.10, 5.5.11, and 5.7.1 allow remote attackers to bypass an intended authentication requirement and execute unspecified administrative functions via a crafted HTTP request, aka Bug ID CSCux24941.
ModificadaMedia (6.8)0.82%—Cisco Dpq3925 8X4 Docsis 3.0 Wireless Residential Gateway With Embedded Digital Voice Adapter14/12/201517/6/2026
Cross-site request forgery (CSRF) vulnerability on Cisco DPQ3925 devices with EDVA 5.5.2 allows remote attackers to hijack the authentication of arbitrary users, aka Bug ID CSCuv05943.
ModificadaBaja (3.5)1.3%—Youtube Embed Project Youtube Embed31/8/201517/6/2026
Cross-site scripting (XSS) vulnerability in includes/options-profiles.php in the YouTube Embed plugin before 3.3.3 for WordPress allows remote administrators to inject arbitrary web script or HTML via the Profile name field (youtube_embed_name parameter).
ModificadaMedia (5)56%—Oracle Enterprise Communications BrokerEmbedthis AppwebJuniper Junos31/3/201517/6/2026
Embedthis Appweb before 4.6.6 and 5.x before 5.2.1 allows remote attackers to cause a denial of service (NULL pointer dereference) via a Range header with an empty value, as demonstrated by "Range: x=,".
ModificadaAlta (7.5)28%—Embedthis Goahead31/3/201517/6/2026
EmbedThis GoAhead 3.0.0 through 3.4.1 does not properly handle path segments starting with a . (dot), which allows remote attackers to conduct directory traversal attacks, cause a denial of service (heap-based buffer overflow and crash), or possibly execute arbitrary code via a crafted URI.
ModificadaAlta (7.5)24%💥 ExploitWebgate Embedded Standard Protocol SDK9/3/201517/6/2026
Multiple buffer overflows in WebGate Embedded Standard Protocol (WESP) SDK allow remote attackers to execute arbitrary code via unspecified vectors to the (1) LoadImage or (2) LoadImageEx function in the WESPMonitor.WESPMonitorCtrl.1 control, (3) ChangePassword function in the WESPCONFIGLib.UserItem control, Connect…
ModificadaMedia (4.3)2.1%—Google DOC Embedder19/2/201517/6/2026
Cross-site scripting (XSS) vulnerability in the Google Doc Embedder plugin before 2.5.19 for WordPress allows remote attackers to inject arbitrary web script or HTML via the profile parameter in an edit action in the gde-settings page to wp-admin/options-general.php.
ModificadaAlta (7.5)5.0%💥 ExploitGoogle DOC Embedder Project Google DOC Embedder2/12/201417/6/2026
SQL injection vulnerability in view.php in the Google Doc Embedder plugin before 2.5.15 for WordPress allows remote attackers to execute arbitrary SQL commands via the gpid parameter.
ModificadaMedia (4.3)1.8%—Redhat SatelliteRedhat Satellite With Embedded OracleRedhat Spacewalk-javaSuse Manager Server+13/11/201417/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in spacewalk-java 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.5 and 5.6 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors to (1) kickstart/cobbler/CustomSnippetList.do, (2) channels/software/Entitlements.do, or (3)…
ModificadaMedia (4.3)1.8%—Redhat SatelliteRedhat Satellite With Embedded OracleRedhat Spacewalk-javaSuse Manager+122/9/201417/6/2026
Cross-site scripting (XSS) vulnerability in spacewalk-java 1.2.39, 1.7.54, and 2.0.2 in Spacewalk and Red Hat Network (RHN) Satellite 5.4 through 5.6 allows remote attackers to inject arbitrary web script or HTML via a crafted request that is not properly handled when logging.
ModificadaMedia (6.9)0.32%—IBM Embedded Websphere Application ServerIBM Tivoli Integrated Portal29/7/201417/6/2026
install.sh in the Embedded WebSphere Application Server (eWAS) 7.0 before FP33 in IBM Tivoli Integrated Portal (TIP) 2.1 and 2.2 sets world-writable permissions for the installRoot directory tree, which allows local users to gain privileges via a Trojan horse program.
ModificadaMedia (5)50%💥 ExploitDavistribe Google DOC Embedder29/5/201416/6/2026
Directory traversal vulnerability in the Google Doc Embedder plugin before 2.5.4 for WordPress allows remote attackers to read arbitrary files via a .. (dot dot) in the file parameter to libs/pdf.php.
Orbitaley — Vulnerabilidades