Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

36 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)2.5%—Tenda It7-lcs FirmwareTenda It7-pcs FirmwareTenda It7-prs FirmwareTenda CP3 Firmware+127/2/202317/6/2026
Certain Tenda products are vulnerable to command injection. This affects Tenda CP7 Tenda CP7<=V11.10.00.2211041403 and Tenda CP3 v.10 Tenda CP3 v.10<=V20220906024_2025 and Tenda IT7-PCS Tenda IT7-PCS<=V2209020914 and Tenda IT7-LCS Tenda IT7-LCS<=V2209020914 and Tenda IT7-PRS Tenda IT7-PRS<=V2209020908.
ModificadaAlta (8.8)0.49%—Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Aviotec FirmwareBosch Cpp7 Firmware+35/8/202117/6/2026
A vulnerability in the web-based interface allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (CSRF - Cross Site Request Forgery). This requires the victim to be tricked into clicking a malicious link or opening a malicious website while being logged in into…
ModificadaMedia (6.1)0.56%—Bosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 FirmwareBosch Cpp13 Firmware9/6/202117/6/2026
An error in the handling of a page parameter in Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. This issue only affects versions 7.7x and 7.6x. All other versions are not affected.
ModificadaCrítica (9.8)0.86%—Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+19/6/202117/6/2026
In Bosch IP cameras, improper validation of the HTTP header allows an attacker to inject arbitrary HTTP headers through crafted URLs.
ModificadaMedia (4.9)0.83%—Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+19/6/202117/6/2026
An authenticated attacker with administrator rights Bosch IP cameras can call an URL with an invalid parameter that causes the camera to become unresponsive for a few seconds and cause a Denial of Service (DoS).
ModificadaMedia (6.1)0.56%—Bosch Cpp4 FirmwareBosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware+19/6/202117/6/2026
An error in the URL handler Bosch IP cameras may lead to a reflected cross site scripting (XSS) in the web-based interface. An attacker with knowledge of the camera address can send a crafted link to a user, which will execute javascript code in the context of the user.
ModificadaCrítica (9.1)1.4%—Bosch Cpp6 FirmwareBosch Cpp7 FirmwareBosch Cpp7.3 Firmware9/6/202117/6/2026
A Missing Authentication in Critical Function in Bosch IP cameras allows an unauthenticated remote attacker to extract sensitive information or change settings of the camera by sending crafted requests to the device. Only devices of the CPP6, CPP7 and CPP7.3 family with firmware 7.70, 7.72, and 7.80 prior to B128 are…
ModificadaMedia (5.5)0.21%—Huawei P7 FirmwareHuawei P8 Ale-ul00 Firmware13/4/201717/6/2026
Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B85, and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) by leveraging camera permissions and via crafted input to the camera driver.
ModificadaMedia (5.5)0.21%—Huawei P7 FirmwareHuawei P8 Ale-ul00 Firmware13/4/201717/6/2026
Huawei P7 before P7-L00C17B851, P7-L05C00B851, and P7-L09C92B851 and P8 ALE-UL00 before ALE-UL00B211 allows local users to cause a denial of service (OS crash) via vectors involving an application that passes crafted input to the GPU driver.
ModificadaAlta (7.8)1.4%—Huawei P7 Firmware13/4/201617/6/2026
Integer overflow in Huawei P7 phones with software before P7-L07 V100R001C01B606 allows remote attackers to gain privileges via a crafted application with the system or camera permission.
ModificadaMedia (5.5)0.56%—Huawei P7 Firmware7/4/201617/6/2026
Huawei Sophia-L10 smartphones with software before P7-L10C900B852 allow attackers to cause a denial of service (system panic) via a crafted application with the system or camera privilege.