Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

508 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)1.7%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable denial-of-service vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a semaphore deadlock, which prevents the device from receiving any physical or network inputs. An…
ModificadaAlta (7.5)1.5%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable denial-of-service vulnerability exists in the XML_GetScreen Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted set of packets can cause an invalid memory dereference, resulting in a device reboot.
ModificadaAlta (7.5)1.6%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable denial-of-service vulnerability exists in the XML_GetRawEncJpg Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an invalid memory dereference, resulting in a device reboot.
ModificadaAlta (7.5)1.6%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable denial-of-service vulnerability exists in the thumbnail display functionality of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a null pointer dereference, resulting in a device reboot.
ModificadaCrítica (9.8)2.8%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution.
ModificadaCrítica (9.8)2.3%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware, running on Anker Roav A1 Dashcam version RoavA1SWV1.9. The HTTP server allows for arbitrary firmware binaries to be uploaded which will be flashed upon next reboot. An attacker can send an HTTP PUT request or upgrade firmware request…
ModificadaAlta (8.8)0.49%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can connect to the AP to trigger this vulnerability.
ModificadaAlta (8.8)0.71%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable code execution vulnerability exists in the URL-parsing functionality of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
ModificadaCrítica (9.8)2.2%—Anker-in Roav Dashcam A1 Firmware13/5/201917/6/2026
An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability.
ModificadaMedia (5.6)1.6%—Lodash1/2/201917/6/2026
A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype.
ModificadaAlta (7.5)70%💥 ExploitKubernetes Dashboard3/1/201917/6/2026
Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster.
ModificadaAlta (7.5)3.0%—IBM Infosphere Data Replication Dashboard9/7/201816/6/2026
Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to read arbitrary files via unspecified vectors. IBM X-Force ID: 84127.
ModificadaCrítica (9.8)1.8%—IBM Infosphere Data Replication Dashboard9/7/201816/6/2026
SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. IBM X-Force ID: 84116.
ModificadaMedia (6.1)1.0%—IBM Infosphere Data Replication Dashboard9/7/201816/6/2026
Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115.
ModificadaMedia (5.3)7.1%💥 ExploitPerfsonar Monitoring AND Debugging Dashboard18/6/201817/6/2026
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing.
ModificadaMedia (5.3)7.1%💥 ExploitPerfsonar Monitoring AND Debugging Dashboard18/6/201817/6/2026
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing.
ModificadaMedia (5.3)7.1%💥 ExploitPerfsonar Monitoring AND Debugging Dashboard18/6/201817/6/2026
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing.
ModificadaMedia (5.3)7.1%💥 ExploitPerfsonar Monitoring AND Debugging Dashboard18/6/201817/6/2026
An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing.
ModificadaMedia (6.5)2.4%—LodashNetapp Active IQ Unified ManagerNetapp System Manager7/6/201817/6/2026
lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on…
ModificadaCrítica (9.8)1.8%—Balderdash Waterline-sequel29/5/201817/6/2026
waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their own SQL statements in waterline-sequel…
ModificadaCrítica (9.8)5.6%—Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms15/5/201817/6/2026
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a heap-based buffer overflow vulnerability has been identified, which may allow an attacker to…
ModificadaAlta (7.8)0.36%—Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms15/5/201817/6/2026
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may allow an authenticated user to modify files…
ModificadaCrítica (9.8)2.8%—Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms15/5/201817/6/2026
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization,…
ModificadaAlta (7.5)2.5%—Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms15/5/201817/6/2026
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to disclose…
ModificadaAlta (7.5)1.6%—Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms15/5/201817/6/2026
In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been identified, which may allow an attacker to…
Orbitaley — Vulnerabilidades