Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2855▼ 333 respecto a la semana anterior
Críticas / altas1381▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)296▼ 213 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.2% | — | Iodata LAN Disk Connect Firmware | 13/11/2017 | 17/6/2026 | I-O DATA DEVICE LAN DISK Connect Ver2.02 and earlier allows an attacker to cause a denial of service in the application via unspecified vectors. | |
| Modificada | Alta (8) | 0.63% | — | Iodata Wn-g300r3 Firmware | 2/8/2017 | 17/6/2026 | WN-G300R3 firmware version 1.0.2 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device. | |
| Modificada | Media (6.8) | 0.66% | — | Iodata Wn-ax1167gr Firmware | 2/8/2017 | 17/6/2026 | Buffer overflow in WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.84% | — | Iodata Wn-ax1167gr Firmware | 2/8/2017 | 17/6/2026 | WN-AX1167GR firmware version 3.00 and earlier allows an attacker to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.84% | — | Iodata Wn-ax1167gr Firmware | 2/8/2017 | 17/6/2026 | WN-AX1167GR firmware version 3.00 and earlier uses hardcoded credentials which may allow an attacker that can access the device to execute arbitrary code on the device. | |
| Modificada | Alta (8.8) | 0.91% | — | Iodata Ts-wptcam Camera FirmwareIodata Ts-ptcam Camera FirmwareIodata Ts-ptcam/poe Camera FirmwareIodata Ts-wlc2 Camera Firmware+3 | 7/7/2017 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in TS-WPTCAM, TS-PTCAM, TS-PTCAM/POE, TS-WLC2, TS-WLCE, TS-WRLC firmware version 1.19 and earlier and TS-WPTCAM2 firmware version 1.01 and earlier allows remote attackers to hijack the authentication of administrators via unspecified vectors. | |
| Modificada | Alta (7.2) | 3.3% | — | Iodata Ts-wrlp FirmwareIodata Ts-wrla Firmware | 9/6/2017 | 17/6/2026 | Buffer overflow in I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to cause a denial-of-service (DoS) or execute arbitrary code via unspecified vectors. | |
| Modificada | Alta (7.2) | 2.2% | — | Iodata Ts-wrlp FirmwareIodata Ts-wrla Firmware | 9/6/2017 | 17/6/2026 | I-O DATA DEVICE TS-WRLP firmware version 1.01.02 and earlier and TS-WRLA firmware version 1.01.02 and earlier allows an attacker with administrator rights to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.7% | — | Iodata Ts-wrlp FirmwareIodata Ts-wrla Firmware | 9/6/2017 | 17/6/2026 | I-O DATA DEVICE TS-WRLP firmware version 1.00.01 and earlier and TS-WRLA firmware version 1.00.01 and earlier allow remote attackers to obtain authentication credentials via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Iodata Wfs-sr01 Firmware | 9/6/2017 | 17/6/2026 | I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to bypass access restriction to access data on storage devices inserted into the product via unspecified vectors. | |
| Modificada | Crítica (9.8) | 4.0% | — | Iodata Wfs-sr01 Firmware | 9/6/2017 | 17/6/2026 | I-O DATA DEVICE WFS-SR01 firmware version 1.10 and earlier allow remote attackers to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Media (5.4) | 0.89% | — | Iodata Wn-ac1167gr Firmware | 28/4/2017 | 17/6/2026 | Cross-site scripting vulnerability in WN-AC1167GR firmware version 1.04 and earlier allows remote authenticated attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Crítica (9.8) | 3.1% | — | Iodata Wn-g300r3 Firmware | 28/4/2017 | 17/6/2026 | Buffer overflow in WN-G300R3 firmware Ver.1.03 and earlier allows remote attackers to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (7.2) | 1.6% | — | Iodata Wn-g300r3 Firmware | 28/4/2017 | 17/6/2026 | WN-G300R3 firmware 1.03 and earlier allows attackers with administrator rights to execute arbitrary OS commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.6% | — | Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+3 | 28/4/2017 | 17/6/2026 | Buffer overflow in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier… | |
| Modificada | Alta (8.8) | 1.7% | — | Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+3 | 28/4/2017 | 17/6/2026 | TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware version 1.18 and earlier allows remote… | |
| Modificada | Media (6.1) | 1.2% | — | Iodata Ts-ptcam/poe FirmwareIodata Ts-ptcam FirmwareIodata Ts-wrlc FirmwareIodata Ts-wlc2 Firmware+3 | 28/4/2017 | 17/6/2026 | HTTP header injection vulnerability in TS-WPTCAM firmware version 1.18 and earlier, TS-WPTCAM2 firmware version 1.00, TS-WLCE firmware version 1.18 and earlier, TS-WLC2 firmware version 1.18 and earlier, TS-WRLC firmware version 1.17 and earlier, TS-PTCAM firmware version 1.18 and earlier, TS-PTCAM/POE firmware… | |
| Modificada | Media (5.4) | 0.64% | — | Iodata Rockdisk Firmware | 13/4/2017 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in I-O DATA DEVICE RockDisk with firmware before 1.05e1-2.0.5 allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. NOTE: This vulnerability exists because of an incomplete fix for CVE-2013-4713. | |
| Modificada | Alta (8.8) | 2.4% | 💥 PoC | Iodata Hvl-a2.0 FirmwareIodata Hvl-a3.0 FirmwareIodata Hvl-a4.0 FirmwareIodata Hvl-at1.0s Firmware+6 | 24/9/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE HVL-A2.0, HVL-A3.0, HVL-A4.0, HVL-AT1.0S, HVL-AT2.0, HVL-AT3.0, HVL-AT4.0, HVL-AT2.0A, HVL-AT3.0A, and HVL-AT4.0A devices with firmware before 2.04 allows remote attackers to hijack the authentication of arbitrary users for requests that delete content. | |
| Modificada | Media (5.3) | 1.6% | — | Iodata Etx-r Firmware | 19/6/2016 | 17/6/2026 | I-O DATA DEVICE ETX-R devices allow remote attackers to cause a denial of service (web-server crash) via unspecified vectors. | |
| Modificada | Alta (8.8) | 0.63% | — | Iodata Etx-r Firmware | 19/6/2016 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability on I-O DATA DEVICE ETX-R devices allows remote attackers to hijack the authentication of arbitrary users. | |
| Modificada | Media (5.4) | 0.80% | — | Iodata Wn-g300r2 FirmwareIodata Wn-g300r3 FirmwareIodata Wn-g300r Firmware | 14/5/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 devices with firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 0.63% | — | Iodata Wn-gdn/r3 Firmware | 14/5/2016 | 17/6/2026 | The WPS implementation on I-O DATA DEVICE WN-GDN/R3, WN-GDN/R3-C, WN-GDN/R3-S, and WN-GDN/R3-U devices does not limit PIN guesses, which allows remote attackers to obtain network access via a brute-force attack. | |
| Modificada | Media (5) | 1.6% | — | Iodata Wn-g54/r2 Firmware | 22/8/2015 | 17/6/2026 | I-O DATA DEVICE WN-G54/R2 routers with firmware before 1.03 and NP-BBRS routers allow remote attackers to cause a denial of service (SSDP reflection) via UPnP requests. | |
| Modificada | Media (5) | 2.1% | — | Redhat Jboss Data VirtualizationOdata4j Project Odata4j | 15/1/2015 | 17/6/2026 | XML external entity (XXE) vulnerability in StaxXMLFactoryProvider2 in Odata4j, as used in Red Hat JBoss Data Virtualization before 6.0.0 patch 4, allows remote attackers to read arbitrary files via a crafted request to a REST endpoint. |