Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
508 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.7% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a semaphore deadlock, which prevents the device from receiving any physical or network inputs. An… | |
| Modificada | Alta (7.5) | 1.5% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the XML_GetScreen Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted set of packets can cause an invalid memory dereference, resulting in a device reboot. | |
| Modificada | Alta (7.5) | 1.6% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the XML_GetRawEncJpg Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause an invalid memory dereference, resulting in a device reboot. | |
| Modificada | Alta (7.5) | 1.6% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable denial-of-service vulnerability exists in the thumbnail display functionality of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a null pointer dereference, resulting in a device reboot. | |
| Modificada | Crítica (9.8) | 2.8% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the XML_UploadFile Wi-Fi command of the NT9665X Chipset firmware, running on the Anker Roav A1 Dashcam, version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. | |
| Modificada | Crítica (9.8) | 2.3% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable firmware update vulnerability exists in the NT9665X Chipset firmware, running on Anker Roav A1 Dashcam version RoavA1SWV1.9. The HTTP server allows for arbitrary firmware binaries to be uploaded which will be flashed upon next reboot. An attacker can send an HTTP PUT request or upgrade firmware request… | |
| Modificada | Alta (8.8) | 0.49% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable vulnerability exists in the Wi-Fi Access Point feature of the Roav A1 Dashcam running version RoavA1SWV1.9. A set of default credentials can potentially be used to connect to the device. An attacker can connect to the AP to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 0.71% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in the URL-parsing functionality of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 2.2% | — | Anker-in Roav Dashcam A1 Firmware | 13/5/2019 | 17/6/2026 | An exploitable code execution vulnerability exists in Wi-Fi Command 9999 of the Roav A1 Dashcam running version RoavA1SWV1.9. A specially crafted packet can cause a stack-based buffer overflow, resulting in code execution. An attacker can send a packet to trigger this vulnerability. | |
| Modificada | Media (5.6) | 1.6% | — | Lodash | 1/2/2019 | 17/6/2026 | A prototype pollution vulnerability was found in lodash <4.17.11 where the functions merge, mergeWith, and defaultsDeep can be tricked into adding or modifying properties of Object.prototype. | |
| Modificada | Alta (7.5) | 70% | 💥 Exploit | Kubernetes Dashboard | 3/1/2019 | 17/6/2026 | Kubernetes Dashboard before 1.10.1 allows attackers to bypass authentication and use Dashboard's Service Account for reading secrets within the cluster. | |
| Modificada | Alta (7.5) | 3.0% | — | IBM Infosphere Data Replication Dashboard | 9/7/2018 | 16/6/2026 | Directory traversal vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to read arbitrary files via unspecified vectors. IBM X-Force ID: 84127. | |
| Modificada | Crítica (9.8) | 1.8% | — | IBM Infosphere Data Replication Dashboard | 9/7/2018 | 16/6/2026 | SQL injection vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to execute arbitrary SQL commands via unspecified vectors. IBM X-Force ID: 84116. | |
| Modificada | Media (6.1) | 1.0% | — | IBM Infosphere Data Replication Dashboard | 9/7/2018 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in IBM InfoSphere Data Replication Dashboard 9.7 and 10.1 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. IBM X-Force ID: 84115. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /images/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /lib/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /etc/ provides a directory listing. | |
| Modificada | Media (5.3) | 7.1% | 💥 Exploit | Perfsonar Monitoring AND Debugging Dashboard | 18/6/2018 | 17/6/2026 | An issue was discovered in perfSONAR Monitoring and Debugging Dashboard (MaDDash) 2.0.2. A direct request to /style/ provides a directory listing. | |
| Modificada | Media (6.5) | 2.4% | — | LodashNetapp Active IQ Unified ManagerNetapp System Manager | 7/6/2018 | 17/6/2026 | lodash node module before 4.17.5 suffers from a Modification of Assumed-Immutable Data (MAID) vulnerability via defaultsDeep, merge, and mergeWith functions, which allows a malicious user to modify the prototype of "Object" via __proto__, causing the addition or modification of an existing property that will exist on… | |
| Modificada | Crítica (9.8) | 1.8% | — | Balderdash Waterline-sequel | 29/5/2018 | 17/6/2026 | waterline-sequel is a module that helps generate SQL statements for Waterline apps Any user input that goes into Waterline's `like`, `contains`, `startsWith`, or `endsWith` will end up in waterline-sequel with the potential for malicious code. A malicious user can input their own SQL statements in waterline-sequel… | |
| Modificada | Crítica (9.8) | 5.6% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a heap-based buffer overflow vulnerability has been identified, which may allow an attacker to… | |
| Modificada | Alta (7.8) | 0.36% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, an improper privilege management vulnerability may allow an authenticated user to modify files… | |
| Modificada | Crítica (9.8) | 2.8% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a TFTP application has unrestricted file uploads to the web application without authorization,… | |
| Modificada | Alta (7.5) | 2.5% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, a path transversal vulnerability has been identified, which may allow an attacker to disclose… | |
| Modificada | Alta (7.5) | 1.6% | — | Advantech WebaccessAdvantech Webaccess DashboardAdvantech Webaccess ScadaAdvantech Webaccess/nms | 15/5/2018 | 17/6/2026 | In Advantech WebAccess versions V8.2_20170817 and prior, WebAccess versions V8.3.0 and prior, WebAccess Dashboard versions V.2.0.15 and prior, WebAccess Scada Node versions prior to 8.3.1, and WebAccess/NMS 2.0.3 and prior, several SQL injection vulnerabilities have been identified, which may allow an attacker to… |