Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

229 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.1)0.65%—Phoenixcontact FL Switch 2008f FirmwarePhoenixcontact FL Switch 2016 FirmwarePhoenixcontact FL Switch 2105 FirmwarePhoenixcontact FL Switch 2108 Firmware+659/12/202530/9/2026
An XSS vulnerability in port_util.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as…
AnalizadaAlta (7.1)9.8%—Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+659/12/202530/9/2026
An XSS vulnerability in pxc_Dot1xCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to click on the link provided by the attacker in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as…
AnalizadaAlta (7.1)9.8%—Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+659/12/202530/9/2026
An XSS vulnerability in pxc_vlanIntfCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such…
AnalizadaAlta (7.1)9.8%—Phoenixcontact FL Switch 2406-2sfx PN FirmwarePhoenixcontact FL Switch 2408 FirmwarePhoenixcontact FL Switch 2408 PN FirmwarePhoenixcontact FL Switch 2412-2tc-2sfx Firmware+659/12/202530/9/2026
An XSS vulnerability in pxc_portSecCfg.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such…
AnalizadaAlta (7.1)0.65%—Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+659/12/202530/9/2026
An XSS vulnerability in pxc_portCntr2.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as…
AnalizadaMedia (6.8)0.24%—Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+659/12/202530/9/2026
An attacker can use an undocumented UART port on the PCB as a side-channel to get root access e.g. with the credentials obtained from CVE-2025-41692.
AnalizadaMedia (4.6)0.21%—Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+659/12/202530/9/2026
An attacker can use an undocumented UART port on the PCB as a side-channel with the user hardcoded credentials obtained from CVE-2025-41692 to gain read access to parts of the filesystem of the device.
AnalizadaAlta (7.1)0.66%—Phoenixcontact FL NAT 2008 FirmwarePhoenixcontact FL NAT 2208 FirmwarePhoenixcontact FL NAT 2304-2gc-2sfp FirmwarePhoenixcontact FL Switch 2005 Firmware+659/12/202530/9/2026
An XSS vulnerability in dyn_conn.php can be used by an unauthenticated remote attacker to trick an authenticated user to send a manipulated POST request to the device in order to change parameters available via web based management (WBM). The vulnerability does not provide access to system-level resources such as…
AnalizadaMedia (6.5)0.48%—Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+659/12/202530/9/2026
A low privileged remote attacker can run the webshell with an empty command containing whitespace. The server will then block until it receives more data, resulting in a DoS condition of the websserver.
AnalizadaMedia (4.3)0.52%—Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+659/12/202530/9/2026
A low privileged remote attacker can use the ssh feature to execute commands directly after login. The process stays open and uses resources which leads to a reduced performance of the management functions. Switching functionality is not affected.
AnalizadaMedia (6.8)0.30%—Phoenixcontact FL Switch 2708 PN FirmwarePhoenixcontact FL Switch 2708 FirmwarePhoenixcontact FL Switch 2608 PN FirmwarePhoenixcontact FL Switch 2608 Firmware+659/12/202530/9/2026
A high privileged remote attacker with admin privileges for the webUI can brute-force the "root" and "user" passwords of the underlying OS due to a weak password generation algorithm.
AnalizadaMedia (5.3)0.22%—Phoenix616 Inventorygui27/10/202517/6/2026
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions before 1.6.5 contain a vulnerability where any plugin using a GUI with the GuiStorageElement and allows taking out items out of that element can allow item duplication when the experimental Bundle item feature is enabled on the…
AnalizadaMedia (4.3)0.25%—Phoenix616 Inventorygui27/10/202517/6/2026
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.1-SNAPSHOT and earlier contain a vulnerability where any plugin using the `GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version…
AnalizadaMedia (5.9)0.26%—Phoenix616 Inventorygui27/10/202517/6/2026
InventoryGui is a library for creating chest GUIs for Bukkit/Spigot plugins. Versions 1.6.3-SNAPSHOT and earlier contain a vulnerability where GUIs using GuiStorageElement can allow item duplication when the experimental Bundle item feature is enabled on the server. The vulnerability is resolved in version…
AnalizadaBaja (1.9)0.28%—Modo Legend OF THE Phoenix29/8/202517/6/2026
A security flaw has been discovered in Modo Legend of the Phoenix up to 1.0.5. The affected element is an unknown function of the file AndroidManifest.xml of the component com.duige.hzw.multilingual. The manipulation results in improper export of android application components. The attack needs to be approached…
AplazadaAlta (8.8)0.41%—Phoenixcontact 5032 16pt Digital Configurable ModuleAI14/8/202517/6/2026
A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number increments at an interval that correlates to the last two consecutive sign in session interval, making it predictable.
AplazadaAlta (8.2)0.19%—Gelbphoenix AutocaliwebAI12/8/202517/6/2026
Autocaliweb is a web app that offers an interface for browsing, reading, and downloading eBooks using a valid Calibre database. Prior to version 0.8.3, the debug pack generated by Autocaliweb can expose sensitive configuration data, including API keys. This occurs because the to_dict() method, used to serialize…
AnalizadaMedia (5.9)2.8%—Gelbphoenix AutocaliwebJaneczku Calibre-web24/7/202517/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Calibre Web, Autocaliweb allows Blind OS Command Injection.This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb: from 0.7.0 before 0.7.1.
AplazadaAlta (8.7)0.84%—Calibre WEBAIGelbphoenix AutocaliwebAI24/7/202517/6/2026
ReDoS in strip_whitespaces() function in cps/string_helper.py in Calibre Web and Autocaliweb allows unauthenticated remote attackers to cause denial of service via specially crafted username parameter that triggers catastrophic backtracking during login. This issue affects Calibre Web: 0.6.24 (Nicolette); Autocaliweb:…
AnalizadaAlta (8.8)0.34%—Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware8/7/202517/6/2026
An unauthenticated adjacent attacker is able to configure a new OCPP backend, due to insecure defaults for the configuration interface.
AnalizadaCrítica (9.8)0.73%—Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware8/7/202517/6/2026
An unauthenticated remote attacker can alter the device configuration in a way to get remote code execution as root with specific configurations.
AnalizadaAlta (8.4)0.29%—Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware8/7/202517/6/2026
An unauthenticated local attacker can inject a command that is subsequently executed as root, leading to a privilege escalation.
AnalizadaAlta (8.8)0.35%—Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware8/7/202517/6/2026
An unauthenticated adjacent attacker can modify configuration by sending specific requests to an API-endpoint resulting in read and write access due to missing authentication.
AnalizadaAlta (7.8)0.12%—Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware8/7/202517/6/2026
A low privileged local attacker can leverage insecure permissions via SSH on the affected devices to escalate privileges to root.
AnalizadaAlta (7.8)0.14%—Phoenixcontact Charx Sec-3000 FirmwarePhoenixcontact Charx Sec-3050 FirmwarePhoenixcontact Charx Sec-3100 FirmwarePhoenixcontact Charx Sec-3150 Firmware8/7/202517/6/2026
A local attacker with a local user account can leverage a vulnerable script via SSH to escalate privileges to root due to improper input validation.