Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

48 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.3)0.97%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual16/2/202117/6/2026
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An incomplete filter applied to a database response allows an authenticated attacker to gain non-public information about other users and devices in the account.
ModificadaAlta (7.8)0.24%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2416/2/202117/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The software uses a secure password for database access, but this password is shared across instances.
ModificadaMedia (5.3)1.2%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual16/2/202117/6/2026
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. An attacker can read arbitrary JSON files via Local File Inclusion.
ModificadaCrítica (9.8)1.1%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2416/2/202117/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. The login pages bruteforce detection is disabled by default.
ModificadaAlta (7.5)0.93%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2416/2/202117/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an outdated and unused component allowing for malicious user input of active code.
ModificadaMedia (5.4)0.52%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2416/2/202117/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an incomplete XSS filter allowing an attacker to inject crafted malicious code into the page.
ModificadaMedia (5.3)1.2%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual16/2/202117/6/2026
An issue was discovered MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2. There is an SSRF in the HA module allowing an unauthenticated attacker to scan for open ports.
ModificadaMedia (6.1)0.65%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2416/2/202117/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unauthenticated open redirect in the redirect.php.
ModificadaMedia (4.3)0.81%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2416/2/202117/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.2. There is an unused function that allows an authenticated attacker to use up all available IPs of an account and thus not allow creation of new devices and users.
ModificadaAlta (7.5)1.5%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual16/2/202117/6/2026
An issue was discovered in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual through 2.11.2. There is an SSRF in the in the MySQL access check, allowing an attacker to scan for open ports and gain some information about possible credentials.
ModificadaMedia (6.5)1.0%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect24Helmholz Myrex24Helmholz Myrex24.virtual16/2/202117/6/2026
An issue in MB connect line mymbCONNECT24, mbCONNECT24 and Helmholz myREX24 and myREX24.virtual in all versions through v2.11.2 allows a logged in user to see devices in the account he should not have access to due to improper use of access validation.
ModificadaMedia (6.5)0.84%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect242/10/202017/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the lancompenent component, allowing logged-in attackers to discover arbitrary information.
ModificadaMedia (6.5)0.48%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2430/9/202017/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a CSRF issue (with resultant SSRF) in the com_mb24proxy module, allowing attackers to steal session information from logged-in users with a crafted link.
ModificadaMedia (4.3)0.69%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2430/9/202017/6/2026
An issue was discovered in MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 through 2.6.1. There is a blind SQL injection in the knximport component via an advanced attack vector, allowing logged in attackers to discover arbitrary information.
ModificadaAlta (7.8)0.26%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2414/4/202017/6/2026
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.6.1. There is a local privilege escalation from the www-data account to the root account.
ModificadaCrítica (9.8)1.8%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2414/4/202017/6/2026
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated remote code execution in the com_mb24sysapi module.
ModificadaAlta (8.8)1.9%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2414/4/202017/6/2026
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an authenticated remote code execution in the backup-scheduler.
ModificadaMedia (5.3)1.1%—Mbconnectline Mbconnect24Mbconnectline Mymbconnect2414/4/202017/6/2026
An issue was discovered in the MB CONNECT LINE mymbCONNECT24 and mbCONNECT24 software in all versions through 2.5.0. There is an unauthenticated SQL injection in DATA24, allowing attackers to discover database and table names.
ModificadaCrítica (9.8)11%💥 PoCConnect2id Nimbus Jose+jwtApache HadoopOracle Communications Cloud Native Core Security Edge Protection ProxyOracle Communications Pricing Design Center+1115/10/201917/6/2026
Connect2id Nimbus JOSE+JWT before v7.9 can throw various uncaught exceptions while parsing a JWT, which could result in an application crash (potential information disclosure) or a potential authentication bypass.
ModificadaAlta (7.5)1.3%—Connect2id Nimbus Jose+jwt20/8/201717/6/2026
Nimbus JOSE+JWT before 4.36 proceeds with ECKey construction without ensuring that the public x and y coordinates are on the specified curve, which allows attackers to conduct an Invalid Curve Attack in environments where the JCE provider lacks the applicable curve validation.
ModificadaBaja (3.1)0.64%—Connect2id Nimbus Jose+jwt20/8/201717/6/2026
Nimbus JOSE+JWT before 4.39 proceeds improperly after detection of an invalid HMAC in authenticated AES-CBC decryption, which allows attackers to conduct a padding oracle attack.
ModificadaAlta (7.5)0.89%—Connect2id Nimbus Jose+jwt20/8/201717/6/2026
In Nimbus JOSE+JWT before 4.39, there is no integer-overflow check when converting length values from bytes to bits, which allows attackers to conduct HMAC bypass attacks by shifting Additional Authenticated Data (AAD) and ciphertext so that different plaintext is obtained for the same HMAC.
ModificadaMedia (4.8)0.53%—Lenovo Connect217/7/201717/6/2026
In Lenovo Connect2 versions earlier than 4.2.5.4885 for Windows and 4.2.5.3071 for Android, when an ad-hoc connection is made between two systems for the purpose of sharing files, the password for this ad-hoc connection will be stored in a user-readable location. An attacker with read access to the user's contents…
Orbitaley — Vulnerabilidades