Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 1.6% | 💥 Exploit | Trilexnet LetodmsDebian Linux | 13/11/2019 | 16/6/2026 | letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar | |
| Modificada | Alta (7.4) | 1.4% | — | Silextechnology Sd-320an FirmwareSilextechnology Geh-sd-320an Firmware | 9/5/2018 | 17/6/2026 | Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly sanitized, which may allow remote code execution. | |
| Modificada | Media (6.5) | 1.1% | — | Silextechnology Sd-320an FirmwareSilextechnology Geh-sd-320an FirmwareSilextechnology Geh-500 FirmwareSilextechnology Sx-500 Firmware | 9/5/2018 | 17/6/2026 | In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings. | |
| Modificada | Media (5) | 1.2% | — | Silex Sx-2000wg Firmware | 2/7/2014 | 17/6/2026 | silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via a crafted IP packet, a different vulnerability than CVE-2014-3889. | |
| Modificada | Media (5) | 1.2% | — | Silex Sx-2000wg Firmware | 2/7/2014 | 17/6/2026 | silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via crafted data in the Options field of a TCP header, a different vulnerability than CVE-2014-3890. | |
| Modificada | Media (4.3) | 1.2% | — | Silexlabs Silex | 20/3/2014 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Silex before 2.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.8) | 2.2% | — | C3-ilex Eoscada | 13/11/2012 | 16/6/2026 | eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 12000. | |
| Modificada | Media (5) | 1.7% | — | C3-ilex Eoscada | 13/11/2012 | 16/6/2026 | eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP port 12000. | |
| Modificada | Alta (7.8) | 2.2% | — | C3-ilex Eoscada | 13/11/2012 | 16/6/2026 | EOSDataServer.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 24006. | |
| Modificada | Media (5) | 1.9% | — | C3-ilex Eoscada | 13/11/2012 | 16/6/2026 | EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP port (1) 5050 or (2) 24004. | |
| Modificada | Media (5) | 2.5% | 💥 Exploit | Philex | 27/3/2007 | 16/6/2026 | download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter. | |
| Modificada | Alta (10) | 73% | 💥 Exploit | Philex | 27/3/2007 | 16/6/2026 | PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter. |