Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
65 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 0.66% | — | Hms-networks Ewon Cosy+ Firmware | 6/8/2024 | 17/6/2026 | A compromised HMS Networks Cosy+ device could be used to request a Certificate Signing Request from Talk2m for another device, resulting in an availability issue. The issue was patched on the Talk2m production server on April 18, 2024. | |
| Modificada | Alta (7.2) | 4.0% | 💥 Exploit | Hms-networks Ewon Cosy+ Firmware | 2/8/2024 | 17/6/2026 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to code injection due to improper parameter blacklisting. This is fixed in version 21.2s10 and 22.1s3. | |
| Modificada | Media (6.6) | 0.52% | — | Hms-networks Ewon Cosy+ Firmware | 2/8/2024 | 17/6/2026 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 use a unique key to encrypt the configuration parameters. This is fixed in version 21.2s10 and 22.1s3, the key is now unique per device. | |
| Analizada | Alta (8.8) | 0.85% | — | Hms-networks Ewon Cosy+ Firmware | 2/8/2024 | 17/6/2026 | Insecure Permission vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are executing several processes with elevated privileges. | |
| Modificada | Media (6.1) | 0.71% | — | Hms-networks Ewon Cosy+ Firmware | 2/8/2024 | 17/6/2026 | Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are vulnerable to XSS when displaying the logs due to improper input sanitization. This is fixed in version 21.2s10 and 22.1s3. | |
| Modificada | Alta (7.5) | 0.45% | — | Hms-networks Ewon Cosy+ Firmware | 2/8/2024 | 17/6/2026 | Insecure Permissions vulnerability in Cosy+ devices running a firmware 21.x below 21.2s10 or a firmware 22.x below 22.1s3 are susceptible to leaking information through cookies. This is fixed in version 21.2s10 and 22.1s3 | |
| Modificada | Media (4.3) | 0.69% | — | Thecosy Icecms | 13/12/2023 | 17/6/2026 | A vulnerability, which was classified as critical, was found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /article/DelectArticleById/ of the component Article Handler. The manipulation leads to permission issues. It is possible to launch the attack remotely. The exploit has been disclosed to… | |
| Modificada | Alta (8.8) | 0.79% | — | Thecosy Icecms | 13/12/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Thecosy IceCMS up to 2.0.1. This issue affects some unknown processing of the component User Data Handler. The manipulation leads to improper access controls. The attack may be initiated remotely. The exploit has been disclosed to the public and… | |
| Modificada | Media (5.4) | 0.64% | — | Thecosy Icecms | 13/12/2023 | 17/6/2026 | A vulnerability classified as critical was found in Thecosy IceCMS up to 2.0.1. This vulnerability affects unknown code. The manipulation leads to manage user sessions. The attack can be initiated remotely. The exploit has been disclosed to the public and may be used. The identifier of this vulnerability is VDB-247888. | |
| Modificada | Alta (7.5) | 0.97% | — | Thecosy Icecms | 13/12/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. This affects an unknown part of the file /WebResource/resource of the component Love Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to initiate the attack remotely. The exploit has been… | |
| Modificada | Media (4.3) | 0.74% | — | Thecosy Icecms | 13/12/2023 | 17/6/2026 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as critical. Affected by this issue is some unknown functionality of the file /adplanet/PlanetCommentList of the component API. The manipulation leads to improper access controls. The attack may be launched remotely. The exploit has been disclosed to… | |
| Modificada | Media (6.5) | 0.98% | — | Thecosy Icecms | 13/12/2023 | 17/6/2026 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. Affected by this vulnerability is an unknown functionality of the file /adplanet/PlanetUser of the component API. The manipulation leads to information disclosure. The attack can be launched remotely. The exploit has been disclosed… | |
| Modificada | Crítica (9.8) | 1.3% | — | Thecosy Icecms | 13/12/2023 | 17/6/2026 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been classified as problematic. Affected is an unknown function of the file /login of the component Captcha Handler. The manipulation leads to improper restriction of excessive authentication attempts. It is possible to launch the attack remotely. The exploit… | |
| Modificada | Baja (3.7) | 0.62% | — | Thecosy Icecms | 2/12/2023 | 17/6/2026 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been rated as problematic. This issue affects some unknown processing of the file /Websquare/likeClickComment/ of the component Comment Like Handler. The manipulation leads to improper enforcement of a single, unique action. The attack may be initiated… | |
| Modificada | Media (6.1) | 0.61% | — | Thecosy Icecms | 2/12/2023 | 17/6/2026 | A vulnerability was found in Thecosy IceCMS 2.0.1. It has been declared as problematic. This vulnerability affects unknown code of the file /planet of the component User Comment Handler. The manipulation leads to cross site scripting. The attack can be initiated remotely. The exploit has been disclosed to the public… | |
| Modificada | Media (5.3) | 0.70% | — | Thecosy Icecms | 30/11/2023 | 17/6/2026 | A vulnerability classified as problematic has been found in Thecosy IceCMS 2.0.1. Affected is an unknown function of the file /WebArticle/articles/ of the component Like Handler. The manipulation leads to improper enforcement of a single, unique action. It is possible to launch the attack remotely. The exploit has… | |
| Modificada | Crítica (9.8) | 0.72% | — | Thecosy Icecms | 12/10/2023 | 17/6/2026 | An issue in Thecosy IceCMS v.1.0.0 allows a remote attacker to gain privileges via the Id and key parameters in getCosSetting. | |
| Modificada | Media (5.4) | 0.38% | — | Thecosy Icecms | 25/5/2023 | 17/6/2026 | IceCMS v1.0.0 is vulnerable to Cross Site Scripting (XSS). | |
| Modificada | Alta (7.5) | 0.61% | — | Thecosy Icecms | 25/5/2023 | 17/6/2026 | IceCMS v1.0.0 has Insecure Permissions. There is unauthorized access to the API, resulting in the disclosure of sensitive information. | |
| Modificada | Media (4.8) | 0.75% | — | Kyocera Taskalfa 7550ci FirmwareKyocera Taskalfa 6550ci FirmwareKyocera Taskalfa 5550ci FirmwareKyocera Taskalfa 4550ci Firmware+36 | 5/12/2022 | 17/6/2026 | Stored cross-site scripting vulnerability in Kyocera Document Solutions MFPs and printers allows a remote authenticated attacker with an administrative privilege to inject arbitrary script. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa 5550ci/4550ci/3550ci/3050ci, TASKalfa 255c/205c,… | |
| Modificada | Media (6.5) | 0.43% | — | Kyocera Taskalfa 7550ci FirmwareKyocera Taskalfa 6550ci FirmwareKyocera Taskalfa 5550ci FirmwareKyocera Taskalfa 4550ci Firmware+36 | 5/12/2022 | 17/6/2026 | Missing authorization vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to alter the product settings without authentication by sending a specially crafted request. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa… | |
| Modificada | Media (6.5) | 0.52% | — | Kyocera Taskalfa 7550ci FirmwareKyocera Taskalfa 6550ci FirmwareKyocera Taskalfa 5550ci FirmwareKyocera Taskalfa 4550ci Firmware+36 | 5/12/2022 | 17/6/2026 | Session information easily guessable vulnerability exists in Kyocera Document Solutions MFPs and printers, which may allow a network-adjacent attacker to log in to the product by spoofing a user with guessed session information. Affected products/versions are as follows: TASKalfa 7550ci/6550ci, TASKalfa… | |
| Modificada | Media (6.1) | 1.5% | — | Kyocera Ecosys M2640idw Firmware | 17/11/2020 | 17/6/2026 | The web application of Kyocera printer (ECOSYS M2640IDW) is affected by Stored XSS vulnerability, discovered in the addition a new contact in "Machine Address Book". Successful exploitation of this vulnerability can lead to session hijacking of the administrator in the web application or the execution of unwanted… | |
| Modificada | Baja (2.3) | 0.34% | — | Hms-networks Ewon Flexy FirmwareHms-networks Ewon Cosy Firmware | 18/9/2020 | 17/6/2026 | All version of Ewon Flexy and Cosy prior to 14.1 use wildcards such as (*) under which domains can request resources. An attacker with local access and high privileges could inject scripts into the Cross-origin Resource Sharing (CORS) configuration that could abuse this vulnerability, allowing the attacker to retrieve… | |
| Modificada | Media (6.1) | 0.69% | — | Hms-networks Ewon Flexy FirmwareHms-networks Ewon Cosy Firmware | 8/4/2020 | 17/6/2026 | A non-persistent XSS (cross-site scripting) vulnerability exists in eWON Flexy and Cosy (all firmware versions prior to 14.1s0). An attacker could send a specially crafted URL to initiate a password change for the device. The target must introduce the credentials to the gateway before the attack can be successful. |