Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2659▼ 692 respecto a la semana anterior
Críticas / altas1261▼ 300 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)250▼ 252 respecto a la semana anterior
699 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.5% | — | Ecos Secure Boot Stick Firmware | 17/6/2018 | 17/6/2026 | Undocumented Factory Backdoor in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows the vendor to extract confidential information via remote root SSH access. | |
| Modificada | Alta (7.5) | 0.57% | — | Ecos Secure Boot Stick Firmware | 17/6/2018 | 17/6/2026 | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a virtualization attack. | |
| Modificada | Alta (8.1) | 0.43% | — | Ecos Secure Boot Stick Firmware | 17/6/2018 | 17/6/2026 | Insufficient Verification of Data Authenticity vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to manipulate security relevant configurations and execute malicious code. | |
| Modificada | Media (4.2) | 0.18% | — | Ecos Secure Boot Stick Firmware | 17/6/2018 | 17/6/2026 | Incomplete Cleanup vulnerability in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via a compromised host PC after a reset. | |
| Modificada | Alta (8.1) | 0.80% | — | Ecos Secure Boot Stick Firmware | 17/6/2018 | 17/6/2026 | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows an attacker to compromise authentication and encryption keys via compromised firmware. | |
| Modificada | Media (5.9) | 0.89% | — | Ecos Secure Boot Stick Firmware | 17/6/2018 | 17/6/2026 | Protection Mechanism Failure in ECOS Secure Boot Stick (aka SBS) 5.6.5 allows a local attacker to duplicate an authentication factor via cloning. | |
| Modificada | Crítica (9.8) | 1.1% | — | Pbootcms | 22/5/2018 | 17/6/2026 | An issue was discovered in PbootCMS v1.0.9. There is a SQL Injection that can get important information from the database via the \apps\home\controller\ParserController.php scode parameter. | |
| Modificada | Alta (8.8) | 0.60% | — | Pbootcms | 13/5/2018 | 17/6/2026 | An issue was discovered in PbootCMS v1.0.7. Cross-site request forgery (CSRF) vulnerability in apps/admin/controller/system/RoleController.php allows remote attackers to add administrator accounts via admin.php/role/add.html. | |
| Modificada | Media (6.8) | 2.7% | 💥 PoC | Nvidia Tegra Bootrom RCM | 1/5/2018 | 17/6/2026 | Some NVIDIA Tegra mobile processors released prior to 2016 contain a buffer overflow vulnerability in BootROM Recovery Mode (RCM). An attacker with physical access to the device's USB and the ability to force the device to reboot into RCM could exploit the vulnerability to execute unverified code. | |
| Modificada | Crítica (9.8) | 1.4% | — | Pbootcms | 16/4/2018 | 17/6/2026 | PbootCMS v0.9.8 allows PHP code injection via an IF label in index.php/About/6.html or admin.php/Site/index.html, related to the parserIfLabel function in \apps\home\controller\ParserController.php. | |
| Modificada | Alta (8.8) | 0.51% | — | Pbootcms | 16/4/2018 | 17/6/2026 | PbootCMS v0.9.8 has CSRF via an admin.php/Message/mod/id/19.html?backurl=/index.php request, resulting in PHP code injection in the recontent parameter. | |
| Modificada | Media (5.9) | 1.2% | — | Vmware Spring Boot | 19/3/2018 | 17/6/2026 | Spring Boot supports an embedded launch script that can be used to easily run the application as a systemd or init.d linux service. The script included with Spring Boot 1.5.9 and earlier and 2.0.0.M1 through 2.0.0.M7 is susceptible to a symlink attack which allows the "run_user" to overwrite and take ownership of any… | |
| Modificada | Alta (8.8) | 0.73% | — | Boot2docker | 6/2/2018 | 17/6/2026 | boot2docker 1.2 and earlier allows attackers to conduct cross-site request forgery (CSRF) attacks by leveraging Docker daemons enabling TCP connections without TLS authentication. | |
| Modificada | Alta (8.8) | 2.8% | — | Boot2docker | 6/2/2018 | 17/6/2026 | The Docker daemon managed by boot2docker 1.2 and earlier improperly enables unauthenticated TCP connections by default, which makes it easier for remote attackers to gain privileges or execute arbitrary code from children containers. | |
| Modificada | Crítica (9.8) | 75% | 💥 Exploit | Vmware Spring BootPivotal Software Spring Data RestVmware Spring Data Rest | 4/1/2018 | 26/6/2026 | Malicious PATCH requests submitted to servers using Spring Data REST versions prior to 2.6.9 (Ingalls SR9), versions prior to 3.0.1 (Kay SR1) and Spring Boot versions prior to 1.5.9, 2.0 M6 can use specially crafted JSON data to run arbitrary Java code. | |
| Modificada | Alta (7.8) | 0.41% | — | Trusted Boot Project Trusted Boot | 16/11/2017 | 17/6/2026 | Certain function pointers in Trusted Boot (tboot) through 1.9.6 are not validated and can cause arbitrary code execution, which allows local users to overwrite dynamic PCRs of Trusted Platform Module (TPM) by hooking these function pointers. | |
| Modificada | Alta (7.8) | 0.40% | — | Amazon WEB Services Cloudformation Bootstrap | 30/10/2017 | 17/6/2026 | The Amazon Web Services (AWS) CloudFormation bootstrap tools package (aka aws-cfn-bootstrap) before 1.4-19.10 allows local users to execute arbitrary code with root privileges by leveraging the ability to create files in an unspecified directory. | |
| Modificada | Alta (7.5) | 1.7% | — | Grml-debootstrap | 7/8/2017 | 17/6/2026 | cmdlineopts.clp in grml-debootstrap in Debian 0.54, 0.68.x before 0.68.1, 0.7x before 0.78 is sourced without checking that the local directory is writable by non-root users. | |
| Modificada | Crítica (9.8) | 1.6% | — | Oneplus Primary Bootloader | 3/8/2017 | 17/6/2026 | The OnePlus 2 Primary Bootloader (PBL) does not validate the SBL1 partition before executing it, although it contains a certificate. This allows attackers with write access to that partition to disable signature validation. | |
| Modificada | Media (5.4) | 0.51% | — | Netcomm 4gt101w SoftwareNetcomm 4gt101w Bootloader | 28/7/2017 | 17/6/2026 | NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to stored cross-site scripting attacks. Creating an SSID with an XSS payload results in successful exploitation. | |
| Modificada | Alta (8.8) | 0.45% | — | Netcomm 4gt101w SoftwareNetcomm 4gt101w Bootloader | 28/7/2017 | 17/6/2026 | NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 are vulnerable to CSRF attacks, as demonstrated by using administration.html to disable the firewall. They does not contain any token that can mitigate CSRF vulnerabilities within the device. | |
| Modificada | Crítica (9.8) | 1.3% | — | Netcomm 4gt101w SoftwareNetcomm 4gt101w Bootloader | 28/7/2017 | 17/6/2026 | NetComm Wireless 4GT101W routers with Hardware: 0.01 / Software: V1.1.8.8 / Bootloader: 1.1.3 do not require authentication for logfile.html, status.html, or system_config.html. | |
| Modificada | Crítica (9.8) | 1.6% | — | Dataprobe Ibootbar Firmware | 7/4/2017 | 16/6/2026 | Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCCOOKIE cookie. | |
| Modificada | Crítica (9.8) | 1.6% | — | Dataprobe Ibootbar Firmware | 7/4/2017 | 16/6/2026 | Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCRABBIT cookie. | |
| Modificada | Alta (8.4) | 18% | 💥 Exploit | Symantec Norton SecuritySymantec Protection EngineSymantec Advanced Threat ProtectionSymantec Norton Bootable Removal Tool+14 | 30/6/2016 | 17/6/2026 | The AntiVirus Decomposer engine in Symantec Advanced Threat Protection (ATP); Symantec Data Center Security:Server (SDCS:S) 6.x through 6.6 MP1; Symantec Web Gateway; Symantec Endpoint Protection (SEP) before 12.1 RU6 MP5; Symantec Endpoint Protection (SEP) for Mac; Symantec Endpoint Protection (SEP) for Linux before… |