Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

79 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.9)0.37%—Eclipse Threadx Netx DUO16/10/202517/6/2026
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ip_packet_receive() function when received an Ethernet with type set as IP but no IP data.
AnalizadaMedia (6.9)0.37%—Eclipse Threadx Netx DUO16/10/202517/6/2026
In NetX Duo before 6.4.4, the networking support module for Eclipse Foundation ThreadX, there was a potential out of bound read issue in _nx_ipv4_packet_receive() function when received an Ethernet frame with less than 4 bytes of IP packet.
AnalizadaMedia (6.9)0.33%—Eclipse Threadx Netx DUO16/10/202517/6/2026
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check in_nx_secure_tls_proc_clienthello_supported_versions_extension() in the extension version field.
AnalizadaMedia (6.9)0.25%—Eclipse Threadx Netx DUO15/10/202517/6/2026
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was an incorrect bound check resulting it out by two out of bound read.
AnalizadaMedia (6.9)0.25%—Eclipse Threadx Netx DUO15/10/202517/6/2026
In NetX Duo version before 6.4.4, the component of Eclipse Foundation ThreadX, there was a potential out of bound read in _nx_secure_tls_process_clienthello() because of a missing validation of PSK length provided in the user message.
AnalizadaMedia (6.9)0.37%—Eclipse Threadx Netx DUO15/10/202517/6/2026
In Eclipse Foundation NextX Duo before 6.4.4, a module of ThreadX, the _nx_secure_tls_process_clienthello() function was missing length verification of certain SSL/TLS client hello message: the ciphersuite length and compression method length. In case of an attacker-crafted message with values outside of the expected…
AplazadaMedia (6.5)0.33%—R-fx Networks Linux Malware DetectAI6/5/202517/6/2026
An issue in the component /internals/functions of R-fx Networks Linux Malware Detect v1.6.5 allows attackers to escalate privileges and execute arbitrary code via supplying a file that contains a crafted filename.
AnalizadaAlta (7.1)0.95%—Eclipse Threadx Netx DUO6/4/202517/6/2026
In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further file request. Users can work-around the…
AnalizadaMedia (5.3)0.95%—Eclipse Threadx Netx DUO6/4/202517/6/2026
In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one packet smaller than the data request size of the other packet. A…
AnalizadaMedia (5.3)0.95%—Eclipse Threadx Netx DUO6/4/202517/6/2026
In NetX Duo component HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.3, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size. A possible workaround is to…
AnalizadaMedia (5.3)0.76%—Eclipse Threadx Netx DUO21/2/202517/6/2026
In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length smaller than the data request size. A possible workaround is to disable HTTP…
AnalizadaMedia (5.3)0.76%—Eclipse Threadx Netx DUO21/2/202517/6/2026
In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause an integer underflow and a subsequent denial of service by writing a very large file, by specially crafted packets with Content-Length in one packet smaller than the data request size of the other packet. A…
AnalizadaAlta (7.1)0.76%—Eclipse Threadx Netx DUO21/2/202517/6/2026
In NetX HTTP server functionality of Eclipse ThreadX NetX Duo before version 6.4.2, an attacker can cause a denial of service by specially crafted packets. The core issue is missing closing of a file in case of an error condition, resulting in the 404 error for each further file request. Users can work-around the…
AplazadaAlta (7.5)0.79%—Redhat Openstack PlatformAIRedhat Enterprise LinuxAIGolang X NETAI8/5/202417/6/2026
The etcd package distributed with the Red Hat OpenStack platform has an incomplete fix for CVE-2023-39325/CVE-2023-44487, known as Rapid Reset. This issue occurs because the etcd package in the Red Hat OpenStack platform is using http://golang.org/x/net/http2 instead of the one provided by Red Hat Enterprise Linux…
ModificadaCrítica (9.8)0.91%—Eclipse Threadx Netx DUO26/3/202417/6/2026
In Eclipse ThreadX NetX Duo before 6.4.0, if an attacker can control parameters of __portable_aligned_alloc() could cause an integer wrap-around and an allocation smaller than expected. This could cause subsequent heap buffer overflows.
ModificadaMedia (5.4)0.63%—Michaelschwarz Ajax.net Professional5/12/202317/6/2026
Ajax.NET Professional (AjaxPro) is an AJAX framework for Microsoft ASP.NET which will create proxy JavaScript classes that are used on client-side to invoke methods on the web server. Affected versions of this package are vulnerable cross site scripting attacks. Releases before version 21.12.22.1 are affected. Users…
ModificadaMedia (6.1)0.51%—Ate-mahoroba Maho-pbx Netdevancer FirmwareAte-mahoroba Maho-pbx Netdevancer VSG FirmwareAte-mahoroba Maho-pbx Netdevancer Mobilegate Firmware17/1/202317/6/2026
Reflected cross-site scripting vulnerability in MAHO-PBX NetDevancer series MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allows a remote unauthenticated attacker to inject an…
ModificadaAlta (8.1)0.35%—Ate-mahoroba Maho-pbx Netdevancer FirmwareAte-mahoroba Maho-pbx Netdevancer VSG FirmwareAte-mahoroba Maho-pbx Netdevancer Mobilegate Firmware17/1/202317/6/2026
Cross-site request forgery (CSRF) vulnerability in MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allows a remote unauthenticated attacker to hijack the user authentication and…
ModificadaAlta (7.2)0.97%—Ate-mahoroba Maho-pbx Netdevancer FirmwareAte-mahoroba Maho-pbx Netdevancer VSG FirmwareAte-mahoroba Maho-pbx Netdevancer Mobilegate Firmware17/1/202317/6/2026
MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allow a remote authenticated attacker with an administrative privilege to execute an arbitrary OS command.
ModificadaCrítica (9.8)1.1%—Ate-mahoroba Maho-pbx Netdevancer FirmwareAte-mahoroba Maho-pbx Netdevancer VSG FirmwareAte-mahoroba Maho-pbx Netdevancer Mobilegate Firmware17/1/202317/6/2026
MAHO-PBX NetDevancer Lite/Uni/Pro/Cloud prior to Ver.1.11.00, MAHO-PBX NetDevancer VSG Lite/Uni prior to Ver.1.11.00, and MAHO-PBX NetDevancer MobileGate Home/Office prior to Ver.1.11.00 allow a remote unauthenticated attacker to execute an arbitrary OS command.
ModificadaCrítica (9.8)1.3%—GOK Smartbox 4 LAN FirmwareGOK Smartbox 4 LAN PRO FirmwareTecson Lx-q-net FirmwareTecson Lx-net Firmware+16/5/202217/6/2026
In multiple Tecson Tankspion and GOKs SmartBox 4 products the affected application doesn't properly restrict access to an endpoint that is responsible for saving settings, to a unauthenticated user with limited access rights. Based on the lack of adequately implemented access-control rules, by accessing a specific…
ModificadaMedia (5.4)0.82%—Ajax.net Professional Project Ajax.net Professional22/12/202117/6/2026
Ajax.NET Professional (AjaxPro) is an AJAX framework available for Microsoft ASP.NET. Affected versions of this package are vulnerable to JavaScript object injection which may result in cross site scripting when leveraged by a malicious user. The affected core relates to JavaScript object creation when parsing json…
AnalizadaCrítica (9.8)83%⚠ Explotación activa💥 ExploitAjaxpro.2 Project Ajaxpro.2Michaelschwarz Ajax.net Professional3/12/202127/8/2026
All versions of package ajaxpro.2 are vulnerable to Deserialization of Untrusted Data due to the possibility of deserialization of arbitrary .NET classes, which can be abused to gain remote code execution.
ModificadaCrítica (9.8)1.9%—Linux Network Project3/11/202117/6/2026
Buffer overflow vulnerability in Renleilei1992 Linux_Network_Project 1.0, allows attackers to execute arbitrary code, via the password field.
ModificadaAlta (7.8)0.33%—Cisco Webex Meetings DesktopCisco Webex Meetings OnlineCisco Webex Meetings ServerCisco Webex Network Recording Player+14/6/202117/6/2026
A vulnerability in Cisco Webex Meetings Desktop App for Windows, Cisco Webex Meetings Server, Cisco Webex Network Recording Player for Windows, and Cisco Webex Teams for Windows could allow an authenticated, local attacker to perform a DLL injection attack on an affected device. To exploit this vulnerability, the…