Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

44 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.1)0.29%—Hidglobal Easylobby Solo21/3/201917/6/2026
EasyLobby Solo is vulnerable to a denial of service. By visiting the kiosk and accessing the task manager, a local attacker could exploit this vulnerability to kill the process or launch new processes at will.
ModificadaMedia (5.5)0.21%—Hidglobal Easylobby Solo21/3/201917/6/2026
EasyLobby Solo could allow a local attacker to obtain sensitive information, caused by the storing of the social security number in plaintext. By visiting the kiosk and viewing the Visitor table of the database, an attacker could exploit this vulnerability to view stored social security numbers.
ModificadaMedia (4.8)0.76%—B3log Solo10/9/201817/6/2026
In b3log Solo 2.9.3, XSS in the Input page under the Publish Articles menu, with an ID of linkAddress stored in the link JSON field, allows remote attackers to inject arbitrary Web scripts or HTML via a crafted site name provided by an administrator.
ModificadaAlta (7.5)1.1%—Sexhdsolo Project Sexhdsolo9/7/201817/6/2026
The mintToken function of a smart contract implementation for sexhdsolo, an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (7.5)1.1%—Hentaisolo Project Hentaisolo5/7/201817/6/2026
The mintToken function of a smart contract implementation for hentaisolo (HAO), an Ethereum token, has an integer overflow that allows the owner of the contract to set the balance of an arbitrary user to any value.
ModificadaAlta (8.8)2.3%—Ruckuswireless Solo Access Point FirmwareRuckuswireless Smartzone Managed Access Point Firmware14/2/201817/6/2026
Ruckus Networks Solo APs firmware releases R110.x or before and Ruckus Networks SZ managed APs firmware releases R5.x or before contain authenticated Root Command Injection in the web-GUI that could allow authenticated valid users to execute privileged commands on the respective systems.
ModificadaAlta (7.8)1.1%—Automationdirect Click PLC FirmwareAutomationdirect C-more PLC FirmwareAutomationdirect C-more Micro FirmwareAutomationdirect GS Drives Fimware+113/11/201717/6/2026
In AutomationDirect CLICK Programming Software (Part Number C0-PGMSW) Versions 2.10 and prior; C-More Programming Software (Part Number EA9-PGMSW) Versions 6.30 and prior; C-More Micro (Part Number EA-PGMSW) Versions 4.20.01.0 and prior; Do-more Designer Software (Part Number DM-PGMSW) Versions 2.0.3 and prior; GS…
ModificadaMedia (6.3)0.34%—NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+237/8/201717/6/2026
A stack-based buffer overflow issue was discovered in NXP i.MX 50, i.MX 53, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, i.MX 6QuadPlus, Vybrid VF3xx, Vybrid VF5xx, and Vybrid VF6xx. When the device is configured in security enabled…
ModificadaMedia (6)0.26%—NXP Vybrid Mvf30nn151cku26 FirmwareNXP Vybrid Mvf30ns151cku26 FirmwareNXP Vybrid Mvf50nn151cmk40 FirmwareNXP Vybrid Mvf50nn151cmk50 Firmware+267/8/201717/6/2026
An improper certificate validation issue was discovered in NXP i.MX 28 i.MX 50, i.MX 53, i.MX 7Solo i.MX 7Dual Vybrid VF3xx, Vybrid VF5xx, Vybrid VF6xx, i.MX 6ULL, i.MX 6UltraLite, i.MX 6SoloLite, i.MX 6Solo, i.MX 6DualLite, i.MX 6SoloX, i.MX 6Dual, i.MX 6Quad, i.MX 6DualPlus, and i.MX 6QuadPlus. When the device is…
ModificadaCrítica (9.8)8.7%💥 ExploitNuuo Nvrmini 2Nuuo Nvrsolo31/8/201617/6/2026
NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors.
ModificadaAlta (7.5)12%💥 ExploitNetgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo31/8/201617/6/2026
NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request.
ModificadaAlta (7.5)54%💥 ExploitNetgear Readynas SurveillanceNuuo NvrsoloNuuo Nvrmini 231/8/201617/6/2026
cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action.
ModificadaCrítica (9.8)71%💥 ExploitNetgear Readynas SurveillanceNuuo CrystalNuuo NvrsoloNuuo Nvrmini 231/8/201617/6/2026
handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter.
ModificadaCrítica (9.8)95%💥 ExploitNetgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo31/8/201617/6/2026
__debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter.
ModificadaMedia (5)1.8%—E-post Corporation Mail ServerE-post Corporation Spa-pro Mail Atsolomon27/1/200616/6/2026
Early termination vulnerability in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allows remote attackers to cause a denial of service (infinite loop) by sending an APPEND command and disconnecting before the expected amount of data is sent.
ModificadaAlta (7.5)4.6%—E-post Corporation Mail ServerE-post Corporation Smtp ServerE-post Corporation Spa-pro Mail Atsolomon27/1/200616/6/2026
Multiple buffer overflows in E-Post Mail Server 4.10 and SPA-PRO Mail @Solomon 4.00 allow remote attackers to execute arbitrary code via a long username to the (1) AUTH PLAIN or (2) AUTH LOGIN SMTP commands, which is not properly handled by (a) EPSTRS.EXE or (b) SPA-RS.EXE; (3) a long username in the APOP POP3…
ModificadaAlta (7.5)2.1%—E-post Corporation Mail ServerE-post Corporation Spa-pro Mail Atsolomon27/1/200616/6/2026
Multiple directory traversal vulnerabilities in (1) EPSTIMAP4S.EXE and (2) SPA-IMAP4S.EXE in the IMAP service in E-Post Mail 4.05 and SPA-PRO Mail 4.05 allow remote attackers to (a) list arbitrary directories or cause a denial of service via the LIST command; or create arbitrary files via the (b) APPEND, (c) COPY, or…
ModificadaBaja (3.6)3.6%—E-post Corporation Spa-pro Mail Atsolomon9/6/200516/6/2026
Directory traversal vulnerability in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to read other users' mail and perform operations on arbitrary directories via .. sequences in the (1) SELECT, (2) CREATE, (3) DELETE, and (4) RENAME commands.
ModificadaBaja (2.1)7.0%💥 ExploitSolomon Spa-pro MailAI2/6/200516/6/2026
Buffer overflow in the IMAP service for SPA-PRO Mail @Solomon 4.00 allows remote authenticated users to execute arbitrary code via a long CREATE command.
Orbitaley — Vulnerabilidades