Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

37 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.1)1.6%💥 ExploitTrilexnet LetodmsDebian Linux13/11/201916/6/2026
letodms has multiple XSS issues: Reflected XSS in Login Page, Stored XSS in Document Owner/User name, Stored XSS in Calendar
ModificadaAlta (7.4)1.4%—Silextechnology Sd-320an FirmwareSilextechnology Geh-sd-320an Firmware9/5/201817/6/2026
Silex SD-320AN version 2.01 and prior and GE MobileLink(GEH-SD-320AN) version GEH-1.1 and prior have a system call parameter that is not properly sanitized, which may allow remote code execution.
ModificadaMedia (6.5)1.1%—Silextechnology Sd-320an FirmwareSilextechnology Geh-sd-320an FirmwareSilextechnology Geh-500 FirmwareSilextechnology Sx-500 Firmware9/5/201817/6/2026
In Silex SX-500 all versions and GE MobileLink(GEH-500) version 1.54 and prior, authentication is not verified when making certain POST requests, which may allow attackers to modify system settings.
ModificadaMedia (5)1.2%—Silex Sx-2000wg Firmware2/7/201417/6/2026
silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via a crafted IP packet, a different vulnerability than CVE-2014-3889.
ModificadaMedia (5)1.2%—Silex Sx-2000wg Firmware2/7/201417/6/2026
silex SX-2000WG devices with firmware before 1.5.4 allow remote attackers to cause a denial of service (connectivity outage) via crafted data in the Options field of a TCP header, a different vulnerability than CVE-2014-3890.
ModificadaMedia (4.3)1.2%—Silexlabs Silex20/3/201417/6/2026
Cross-site scripting (XSS) vulnerability in Silex before 2.0.0 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.8)2.2%—C3-ilex Eoscada13/11/201216/6/2026
eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 12000.
ModificadaMedia (5)1.7%—C3-ilex Eoscada13/11/201216/6/2026
eosfailoverservice.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to obtain sensitive cleartext information via a session on TCP port 12000.
ModificadaAlta (7.8)2.2%—C3-ilex Eoscada13/11/201216/6/2026
EOSDataServer.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service by sending a large amount of data to TCP port 24006.
ModificadaMedia (5)1.9%—C3-ilex Eoscada13/11/201216/6/2026
EOSCoreScada.exe in C3-ilex EOScada before 11.0.19.2 allows remote attackers to cause a denial of service (daemon restart) by sending data to TCP port (1) 5050 or (2) 24004.
ModificadaMedia (5)2.5%💥 ExploitPhilex27/3/200716/6/2026
download.php in Philex 0.2.3 and earlier allows remote attackers to read arbitrary files and source code, and obtain sensitive information via the file parameter.
ModificadaAlta (10)73%💥 ExploitPhilex27/3/200716/6/2026
PHP remote file inclusion vulnerability in header.inc.php in Philex 0.2.3 and earlier allows remote attackers to execute arbitrary PHP code via a URL in the CssFile parameter.
Orbitaley — Vulnerabilidades