Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
1222 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Identity parameter under Local endpoint settings at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the IPsec Tunnel Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Hostname parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Password parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the DDNS Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Password parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Username parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the SMTP Server Name parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Contact Email Address parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the URL parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Description parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 3 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 2 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Time Server 1 parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the… | |
| Modificada | Media (5.4) | 0.36% | — | Skyworthdigital Cm5100 Firmware | 17/1/2024 | 17/6/2026 | This vulnerability exist in Skyworth Router CM5100, version 4.1.1.24, due to insufficient validation of user supplied input for the Traceroute parameter at its web interface. A remote attacker could exploit this vulnerability by supplying specially crafted input to the parameter at the web interface of the vulnerable… | |
| Modificada | Media (4.8) | 0.47% | — | Indigitall Iurny | 16/1/2024 | 17/6/2026 | The IURNY by INDIGITALL WordPress plugin before 3.2.3 does not sanitise and escape some of its settings, which could allow high privilege users such as admin to perform Stored Cross-Site Scripting attacks even when the unfiltered_html capability is disallowed (for example in multisite setup) | |
| Modificada | Crítica (9.8) | 1.2% | — | Aditaas Allied Digital Integrated Tool-as-a-service | 18/12/2023 | 17/6/2026 | The vulnerability exists in ADiTaaS (Allied Digital Integrated Tool-as-a-Service) version 5.1 due to an improper authentication vulnerability in the ADiTaaS backend API. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable platform. Successful… | |
| Modificada | Alta (8.8) | 0.27% | — | Digital Publications BY Supsystic | 9/12/2023 | 17/6/2026 | The Digital Publications by Supsystic plugin for WordPress is vulnerable to Cross-Site Request Forgery in versions up to, and including, 1.7.6. This is due to missing or incorrect nonce validation on the AJAX action handler. This makes it possible for unauthenticated attackers to execute AJAX actions via a forged… | |
| Modificada | Media (6) | 0.31% | — | Fortra Digital Guardian Agent | 22/11/2023 | 17/6/2026 | A saved encryption key in the Uninstaller in Digital Guardian's Agent before version 7.9.4 allows a local attacker to retrieve the uninstall key and remove the software by extracting the uninstaller key from the memory of the uninstaller file. | |
| Modificada | Crítica (9.8) | 1.2% | — | Digitalcomtech Syrus 4G IOT Telematics Gateway Firmware | 21/11/2023 | 17/6/2026 | The Syrus4 IoT gateway utilizes an unsecured MQTT server to download and execute arbitrary commands, allowing a remote unauthenticated attacker to execute code on any Syrus4 device connected to the cloud service. The MQTT server also leaks the location, video and diagnostic data from each connected device. An attacker… | |
| Modificada | Alta (7.8) | 0.25% | — | Westerndigital Sandisk Security Installer | 15/11/2023 | 17/6/2026 | Multiple DLL Search Order Hijack vulnerabilities were addressed in the SanDisk Security Installer for Windows that could allow attackers with local access to execute arbitrary code by executing the installer in the same folder as the malicious DLL. This can lead to the execution of arbitrary code with the privileges… | |
| Modificada | Media (6.1) | 0.21% | — | Starkdigital Category Post List Widget | 13/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Stark Digital Category Post List Widget allows Stored XSS.This issue affects Category Post List Widget: from n/a through 2.0. | |
| Modificada | Alta (8.8) | 0.31% | — | Digitalinspiration Google XML Sitemap FOR Images | 12/11/2023 | 17/6/2026 | Cross-Site Request Forgery (CSRF) vulnerability in Amit Agarwal Google XML Sitemap for Images plugin <= 2.1.3 versions. | |
| Modificada | Media (6.1) | 0.70% | — | Digitaldruid Hoteldruid | 10/11/2023 | 17/6/2026 | Cross-site scripting vulnerability in HOTELDRUID 3.0.5 and earlier allows a remote unauthenticated attacker to execute an arbitrary script on the web browser of the user who is logging in to the product. | |
| Modificada | Media (5.4) | 0.43% | — | Spreendigital QR Code TAG | 7/11/2023 | 17/6/2026 | The QR Code Tag plugin for WordPress is vulnerable to Stored Cross-Site Scripting via 'qrcodetag' shortcode in versions up to, and including, 1.0 due to insufficient input sanitization and output escaping on user supplied attributes. This makes it possible for authenticated attackers with contributor-level and above… |