Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

252 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.55%—Sick Tloc100-100 Firmware27/10/202517/6/2026
An attacker who tampers with the C++ CLI client may crash the UpdateService during file transfers, disrupting updates and availability.
AnalizadaCrítica (9.8)0.49%—Sick Tloc100-100 Firmware27/10/202517/6/2026
A remote unauthenticated attacker may use the unauthenticated C++ API to access or modify sensitive data and disrupt services.
AnalizadaAlta (7.5)0.43%—Sick Tloc100-100 Firmware27/10/202517/6/2026
The system is deployed in its default state, with configuration settings that do not comply with the latest best practices for restricting access. This increases the risk of unauthorised connections.
AnalizadaAlta (7.5)0.34%—Sick Tloc100-100 Firmware27/10/202517/6/2026
An attacker that gains SSH access to an unprivileged account may be able to disrupt services (including SSH), causing persistent loss of availability.
AnalizadaAlta (7.1)0.23%—Vimicro Vs-ipc1002 Firmware23/10/202517/6/2026
Vilar VS-IPC1002 IP cameras are vulnerable to DoS (Denial-of-Service) attacks. An unauthenticated attacker on the same local network might send a crafted request to /cgi-bin/action endpoint and render the device completely unresponsive. A manual restart of the device is required. The vendor did not respond in any way.…
AnalizadaMedia (4.8)0.22%—Vimicro Vs-ipc1002 Firmware23/10/202517/6/2026
Vilar VS-IPC1002 IP cameras are vulnerable to Reflected XSS (Cross-site Scripting) attacks, because parameters in GET requests sent to /cgi-bin/action endpoint are not sanitized properly, making it possible to target logged in admin users. The vendor did not respond in any way. Only version 1.1.0.18 was tested, other…
ModificadaAlta (7.5)0.24%—Trendnet Tew-wlc100p Firmware21/7/20255/7/2026
In the configuration file of racoon in the TRENDnet TEW-WLC100P 2.03b03, the first item of exchage_mode is set to aggressive. Aggressive mode in IKE Phase 1 exposes identity information in plaintext, is vulnerable to offline dictionary attacks, and lacks flexibility in negotiating security parameters.
ModificadaAlta (7.3)0.29%—Trendnet Tew-wlc100p Firmware21/7/20255/7/2026
In TRENDnet TEW-WLC100P 2.03b03, the i_dont_care_about_security_and_use_aggressive_mode_psk option is enabled in the strongSwan configuration file, so that IKE Responders are allowed to use IKEv1 Aggressive Mode with Pre-Shared Keys to conduct offline attacks on the openly transmitted hash of the PSK.
AplazadaMedia (5.5)0.17%—At&t CalypsoAINokia C100AINokia C200AIBLU View 3AI22/4/202417/6/2026
Various software builds for the AT&T Calypso, Nokia C100, Nokia C200, and BLU View 3 devices leak the device IMEI to a system property that can be accessed by any local app on the device without any permissions or special privileges. Google restricted third-party apps from directly obtaining non-resettable device…
AplazadaAlta (7.3)0.78%—Nokia C200AINokia C100AITracfone TfstatusAI22/4/202417/6/2026
Certain software builds for the Nokia C200 and Nokia C100 Android devices contain a vulnerable, pre-installed app with a package name of com.tracfone.tfstatus (versionCode='31', versionName='12') that allows local third-party apps to execute arbitrary AT commands in its context (radio user) via AT command injection…
ModificadaCrítica (9.8)61%💥 ExploitCassianetworks Xc1000 FirmwareCassianetworks Xc2000 Firmware10/1/202417/6/2026
In Cassia Gateway firmware XC1000_2.1.1.2303082218 and XC2000_2.1.1.2303090947, the queueUrl parameter in /bypass/config is not sanitized. This leads to injecting Bash code and executing it with root privileges on device startup.
ModificadaAlta (8.8)0.96%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6Codesys Control FOR Iot2000 SLCodesys Control FOR Linux ARM SL+75/12/202317/6/2026
A low-privileged remote attacker could exploit the vulnerability and inject additional system commands via file system libraries which could give the attacker full control of the device.
ModificadaMedia (5.3)0.20%—Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+320/11/202317/6/2026
Wago web-based management of multiple products has a vulnerability which allows an local authenticated attacker to change the passwords of other non-admin users and thus to escalate non-root privileges.
ModificadaMedia (6.5)0.33%—Tp-link Tapo C100 Firmware31/10/202317/6/2026
An issue in TP-Link Tapo C100 v1.1.15 Build 211130 Rel.15378n(4555) and before allows attackers to cause a Denial of Service (DoS) via supplying a crafted web request.
ModificadaAlta (8.8)0.24%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. This can be exploited to perform certain actions with administrative privileges if a logged-in user visits a malicious web site.
ModificadaMedia (6.5)0.36%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application suffers from improper access control when editing users. A user with read permissions can manipulate users, passwords, and permissions by sending a single HTTP POST request with modified parameters.
ModificadaCrítica (9.8)0.79%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The cookie session ID is of insufficient length and can be exploited by brute force, which may allow a remote attacker to obtain a valid session, bypass authentication, and manipulate the transmitter.
ModificadaAlta (8.8)0.60%—Sielco Analog FM Transmitter Exc5000gx FirmwareSielco Analog FM Transmitter Exc120gx FirmwareSielco Analog FM Transmitter Exc300gx FirmwareSielco Analog FM Transmitter Exc1600gx Firmware+1126/10/202317/6/2026
The application suffers from a privilege escalation vulnerability. A user with read permissions can elevate privileges by sending a HTTP POST to set a parameter.
ModificadaBaja (2.7)0.47%—Wago Compact Controller 100 FirmwareWago Edge Controller FirmwareWago Pfc100 FirmwareWago Pfc200 Firmware+317/10/202317/6/2026
On affected Wago products an remote attacker with administrative privileges can access files to which he has already access to through an undocumented local file inclusion. This access is logged in a different log file than expected.
ModificadaAlta (8.8)0.88%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+103/8/202317/6/2026
In CODESYS Control in multiple versions a improper restriction of operations within the bounds of a memory buffer allow an remote attacker with user privileges to gain full access of the device.
ModificadaMedia (6.5)0.63%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+123/8/202317/6/2026
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability…
ModificadaMedia (6.5)0.63%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+123/8/202317/6/2026
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted network communication requests with inconsistent content can cause the CmpAppForce component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability…
ModificadaMedia (6.5)0.63%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+123/8/202317/6/2026
After successful authentication as a user in multiple Codesys products in multiple versions, specific crafted remote communication requests can cause the CmpAppBP component to overwrite a heap-based buffer, which can lead to a denial-of-service condition.
ModificadaMedia (6.5)0.63%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+123/8/202317/6/2026
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability…
ModificadaMedia (6.5)0.63%—Codesys Control FOR Beaglebone SLCodesys Control FOR Empc-a/imx6 SLCodesys Control FOR Iot2000 SLCodesys Control FOR Linux SL+123/8/202317/6/2026
In multiple versions of multiple Codesys products, after successful authentication as a user, specific crafted network communication requests with inconsistent content can cause the CmpAppBP component to read internally from an invalid address, potentially leading to a denial-of-service condition. This vulnerability…
Orbitaley — Vulnerabilidades