Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

139 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.2)1.4%—Enphase IQ Gateway Firmware12/8/202417/6/2026
Improper Neutralization of Special Elements used in a Command ('Command Injection') vulnerability in Enphase IQ Gateway (formerly known as Envoy) allows OS Command Injection. This vulnerability is present in an internal script.This issue affects Envoy: from 4.x up to and including 8.x and is currently unpatched.
AnalizadaCrítica (9.2)0.79%—Enphase IQ Gateway Firmware12/8/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability through a url parameter in Enphase IQ Gateway (formerly known as Envoy) allows File Manipulation. The endpoint requires authentication.This issue affects Envoy: from 4.x to 8.0 and < 8.2.4225.
AnalizadaCrítica (9.3)0.80%—Enphase IQ Gateway Firmware12/8/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability via a URL parameter in Enphase IQ Gateway (formerly known as Envoy) allows an unautheticated attacker to access or create arbitratry files.This issue affects Envoy: from 4.x to 8.x and < 8.2.4225.
AnalizadaCrítica (10)0.54%—Intrado 911 Emergency Gateway Firmware26/6/202417/6/2026
Intrado 911 Emergency Gateway login form is vulnerable to an unauthenticated blind time-based SQL injection, which may allow an unauthenticated remote attacker to execute malicious code, exfiltrate data, or manipulate the database.
AnalizadaAlta (8.6)100%⚠ Explotación activa💥 ExploitCheckpoint Quantum Spark FirmwareCheckpoint Quantum Security Gateway FirmwareCheckpoint Cloudguard Network Security28/5/20245/8/2026
Potentially allowing an attacker to read certain information on Check Point Security Gateways once connected to the internet and enabled with remote Access VPN or Mobile Access Software Blades. A Security fix that mitigates this vulnerability is available.
AnalizadaAlta (7.8)0.33%—Netentsec Application Security Gateway Firmware21/3/202417/6/2026
SQL Injection vulnerability in Netcome NS-ASG Application Security Gateway v.6.3.1 allows a local attacker to execute arbitrary code and obtain sensitive information via a crafted script to the loginid parameter of the /singlelogin.php component.
ModificadaAlta (8.8)0.86%—Mokosmart Mkgw1 Gateway Firmware16/1/202417/6/2026
An issue in MOKO TECHNOLOGY LTD MOKOSmart MKGW1 BLE Gateway v.1.1.1 and before allows a remote attacker to escalate privileges via the session management component of the administrative web interface.
ModificadaCrítica (9.8)0.71%💥 PoCCisco Ironport Email Security ApplianceCisco Secure Email Gateway Firmware10/1/202417/6/2026
Hyland Perceptive Filters releases before 2023-12-08 (e.g., 11.4.0.2647), as used in Cisco IronPort Email Security Appliance Software, Cisco Secure Email Gateway, and various non-Cisco products, allow attackers to trigger a segmentation fault and execute arbitrary code via a crafted document.
ModificadaCrítica (9.8)0.67%—Netentsec Application Security Gateway Firmware29/12/202317/6/2026
A vulnerability classified as critical has been found in Netentsec NS-ASG Application Security Gateway 6.3.1. This affects an unknown part of the file index.php?para=index of the component Login. The manipulation of the argument check_VirtualSiteId leads to sql injection. It is possible to initiate the attack…
ModificadaMedia (5.9)94%💥 ExploitOpenbsd OpensshPuttyFilezilla-project Filezilla ClientPanic Transmit 5+6418/12/202317/6/2026
The SSH transport protocol with certain OpenSSH extensions, found in OpenSSH before 9.6 and other products, allows remote attackers to bypass integrity checks such that some packets are omitted (from the extension negotiation message), and a client and server may consequently end up with a connection for which some…
ModificadaCrítica (9.8)1.2%—Digitalcomtech Syrus 4G IOT Telematics Gateway Firmware21/11/202317/6/2026
The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks the location, video and diagnostic data from each connected device. An attacker…
ModificadaCrítica (9.8)0.96%—Thorntech Sftp Gateway Firmware31/10/202317/6/2026
Thorn SFTP gateway 3.4.x before 3.4.4 uses Pivotal Spring Framework for Java deserialization of untrusted data, which is not supported by Pivotal, a related issue to CVE-2016-1000027. Also, within the specific context of Thorn SFTP gateway, this leads to remote code execution.
ModificadaCrítica (9.8)2.6%—Chinamobile Intelligent Home Gateway Firmware14/9/202317/6/2026
Command Execution vulnerability in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the shortcut_telnet.cg component.
ModificadaCrítica (9.8)1.5%—Chinamobile Intelligent Home Gateway Firmware5/9/202317/6/2026
An issue in China Mobile Communications China Mobile Intelligent Home Gateway v.HG6543C4 allows a remote attacker to execute arbitrary code via the authentication mechanism.
ModificadaAlta (8.8)0.66%—Schneider-electric Insighthome FirmwareSchneider-electric Insightfacility FirmwareSchneider-electric Conext Gateway Firmware18/4/202317/6/2026
A CWE-20: Improper Input Validation vulnerability exists that could allow an authenticated attacker to gain the same privilege as the application on the server when a malicious payload is provided over HTTP for the server to execute.
AnalizadaCrítica (9.8)6.7%⚠ Explotación activa💥 PoCCitrix Application Delivery Controller FirmwareCitrix Gateway Firmware13/12/202217/6/2026
Unauthenticated remote arbitrary code execution
ModificadaAlta (7.5)0.82%—Motorola Moscad IP Gateway FirmwareMotorola ACE IP Gateway (4600) Firmware26/7/202217/6/2026
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with…
ModificadaAlta (8.8)1.5%—Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware22/10/202117/6/2026
The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.
ModificadaAlta (8.8)1.0%—Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware22/10/202117/6/2026
The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.
ModificadaAlta (8.8)0.79%—Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware22/10/202117/6/2026
The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change.
ModificadaAlta (8.8)0.98%—Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware22/10/202117/6/2026
The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input.
ModificadaMedia (6.5)0.94%—Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware22/10/202117/6/2026
The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.
ModificadaAlta (8.8)0.93%—Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1410d Gateway FirmwareEmerson Wireless 1420 Gateway Firmware22/10/202117/6/2026
The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk.
ModificadaCrítica (10)1.1%—Emerson Wireless 1410 Gateway FirmwareEmerson Wireless 1420 Gateway FirmwareEmerson Wireless 1552wu Gateway Firmware29/9/202117/6/2026
There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.
ModificadaCrítica (9.8)10%💥 ExploitTieline IP Audtio Gateway Firmware1/7/202117/6/2026
Tieline IP Audio Gateway 2.6.4.8 and below is affected by Incorrect Access Control. A vulnerability in the Tieline Web Administrative Interface could allow an unauthenticated user to access a sensitive part of the system with a high privileged account.
Orbitaley — Vulnerabilidades