Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2989▼ 73 respecto a la semana anterior
Críticas / altas1415▲ 65 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.1%—Advantech Webaccess21/2/201216/6/2026
SQL injection vulnerability in Advantech/BroadWin WebAccess 7.0 allows remote authenticated users to execute arbitrary SQL commands via a malformed URL. NOTE: this vulnerability exists because of an incomplete fix for CVE-2012-0234.
ModificadaAlta (7.5)1.1%—Advantech Webaccess21/2/201216/6/2026
Multiple SQL injection vulnerabilities in Advantech/BroadWin WebAccess before 7.0 allow remote attackers to execute arbitrary SQL commands via crafted string input.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
Buffer overflow in an ActiveX control in bwocxrun.ocx in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code by leveraging the ability to write arbitrary content to any pathname.
ModificadaAlta (10)6.9%💥 ExploitAdvantech Webaccess21/2/201216/6/2026
Format string vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via format string specifiers in a message string.
ModificadaMedia (5)4.5%💥 ExploitAdvantech Webaccess21/2/201216/6/2026
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to cause a denial of service (memory corruption) via a modified stream identifier to a function.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
GbScriptAddUp.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (5)1.1%—Advantech Webaccess21/2/201216/6/2026
uaddUpAdmin.asp in Advantech/BroadWin WebAccess before 7.0 does not properly perform authentication, which allows remote attackers to modify an administrative password via a password-change request.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
Stack-based buffer overflow in opcImg.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via unspecified vectors.
ModificadaMedia (6.4)1.2%—Advantech Webaccess21/2/201216/6/2026
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to (1) enable date and time syncing or (2) disable date and time syncing via a crafted URL.
ModificadaMedia (5)1.2%—Advantech Webaccess21/2/201216/6/2026
Advantech/BroadWin WebAccess 7.0 and earlier allows remote attackers to obtain sensitive information via a direct request to a URL. NOTE: the vendor reportedly "does not consider it to be a security risk."
ModificadaMedia (6)0.47%—Advantech Webaccess21/2/201216/6/2026
Cross-site request forgery (CSRF) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to hijack the authentication of unspecified victims via unknown vectors.
ModificadaAlta (7.5)1.1%—Advantech Webaccess21/2/201216/6/2026
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via a malformed URL.
ModificadaMedia (4.3)0.91%—Advantech Webaccess21/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via a malformed URL.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
Buffer overflow in an ActiveX control in Advantech/BroadWin WebAccess before 7.0 might allow remote attackers to execute arbitrary code via a long string value in unspecified parameters.
ModificadaAlta (10)2.0%—Advantech Webaccess21/2/201216/6/2026
Advantech/BroadWin WebAccess before 7.0 allows remote attackers to trigger the extraction of arbitrary web content into a batch file on a client system, and execute this batch file, via unspecified vectors.
ModificadaAlta (10)4.1%—Advantech Webaccess21/2/201216/6/2026
Buffer overflow in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary code via a long string value in unspecified parameters.
ModificadaMedia (4.3)0.91%—Advantech Webaccess21/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in bwview.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
ModificadaMedia (4.3)0.91%—Advantech Webaccess21/2/201216/6/2026
Cross-site scripting (XSS) vulnerability in bwerrdn.asp in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to inject arbitrary web script or HTML via unspecified parameters.
ModificadaAlta (7.5)1.1%—Advantech Webaccess21/2/201216/6/2026
SQL injection vulnerability in Advantech/BroadWin WebAccess before 7.0 allows remote attackers to execute arbitrary SQL commands via crafted string input.