Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

83 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.55%—Northern.tech Cfengine26/4/202317/6/2026
Northern.tech CFEngine Enterprise before 3.21.1 allows a subset of authenticated users to leverage the Scheduled Reports feature to read arbitrary files and potentially discover credentials.
ModificadaMedia (5.5)0.36%—Northern.tech Cfengine10/3/202217/6/2026
Northern.tech CFEngine Enterprise before 3.15.5 and 3.18.x before 3.18.1 has Insecure Permissions that may allow unauthorized local users to access the Apache and Mission Portal log files.
ModificadaMedia (5.5)0.35%—Northern.tech Cfengine10/3/202217/6/2026
Northern.tech CFEngine Enterprise 3.15.4 before 3.15.5 has Insecure Permissions that may allow unauthorized local users to have an unspecified impact.
ModificadaMedia (5.5)0.21%—Northern.tech Cfengine27/10/202117/6/2026
The Hub in CFEngine Enterprise 3.6.7 through 3.18.0 has Insecure Permissions that allow local Information Disclosure.
ModificadaMedia (6.5)0.42%—Northern.tech Cfengine27/10/202117/6/2026
CFEngine Enterprise 3.15.0 through 3.15.4 has Missing SSL Certificate Validation.
ModificadaMedia (6.1)0.64%—Northern.tech Cfengine16/4/202017/6/2026
Northern.tech CFEngine Enterprise before 3.10.7, 3.11.x and 3.12.x before 3.12.3, 3.13.x, and 3.14.x allows XSS. This is fixed in 3.10.7, 3.12.3, and 3.15.0.
ModificadaAlta (8.8)2.0%—Northern Cfengine6/6/201917/6/2026
Northern.tech CFEngine Enterprise 3.12.1 has Insecure Permissions.
ModificadaCrítica (9.8)8.1%💥 ExploitFengoffice Feng Office7/3/201917/6/2026
Feng Office 3.7.0.5 allows remote attackers to execute arbitrary code via "<!--#exec cmd=" in a .shtml file to ck_upload_handler.php.
ModificadaMedia (4.9)1.4%—Lfdycms LEI Feng TV CMS30/12/201817/6/2026
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows Directory Traversal via crafted use of ..* in Template/edit/path URIs, as demonstrated by the admin.php?s=/Template/edit/path/*web*..*..*..*..*1.txt.html URI to read the 1.txt file.
ModificadaAlta (8.8)0.53%—Lfdycms LEI Feng TV CMS30/12/201817/6/2026
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows admin.php?s=/Member/add.html CSRF.
ModificadaAlta (7.5)1.3%—Lfdycms LEI Feng TV CMS30/12/201817/6/2026
Lei Feng TV CMS (aka LFCMS) 3.8.6 allows full path disclosure via the /install.php?s=/1 URI.
ModificadaAlta (8)0.81%—Xunfeng Project Xunfeng12/9/201817/6/2026
xunfeng 0.2.0 allows command execution via CSRF because masscan.py mishandles backquote characters, a related issue to CVE-2018-16832.
ModificadaMedia (6.5)0.56%—Xunfeng Project Xunfeng11/9/201817/6/2026
CSRF in the anti-csrf decorator in xunfeng 0.2.0 allows an attacker to modify the configuration via a Flash file because views/lib/AntiCSRF.py can overwrite the request.host value with the content of the X-Forwarded-Host HTTP header.
ModificadaMedia (5.9)5.3%—Fiberhome Fengine S5800 Firmware23/1/201717/6/2026
An issue was discovered on FiberHome Fengine S5800 switches V210R240. An unauthorized attacker can access the device's SSH service, using a password cracking tool to establish SSH connections quickly. This will trigger an increase in the SSH login timeout (each of the login attempts will occupy a connection slot for a…
ModificadaMedia (4.3)1.9%—Fengoffice Feng Office19/8/201417/6/2026
Cross-site scripting (XSS) vulnerability in Feng Office allows remote attackers to inject arbitrary web script or HTML via a client Name field.
ModificadaMedia (4.3)0.96%—Fengoffice Feng Office28/10/201316/6/2026
Cross-site scripting (XSS) vulnerability in Feng Office 2.3.2-rc and earlier allows remote attackers to inject arbitrary web script or HTML via an arbitrary ref_XXX parameter.
ModificadaMedia (5)1.3%—Fengoffice Feng Office23/9/201116/6/2026
Feng Office 1.7.2 allows remote attackers to obtain sensitive information via a direct request to a .php file, which reveals the installation path in an error message, as demonstrated by public/upgrade/templates/layout.php and certain other files.
ModificadaAlta (9.3)5.6%💥 ExploitBaofeng Storm27/7/200916/6/2026
Stack-based buffer overflow in medialib.dll in BaoFeng Storm 3.9.62 allows remote attackers to execute arbitrary code via a long pathname in the source attribute of an item element in a .smpl playlist file.
ModificadaAlta (9.3)7.5%💥 ExploitBaofeng Storm28/5/200916/6/2026
Unspecified vulnerability in Config.dll in Baofeng products 3.09.04.17 and earlier allows remote attackers to execute arbitrary code by calling the SetAttributeValue method, as exploited in the wild in April and May 2009.
ModificadaAlta (9.3)33%💥 ExploitBaofeng Storm11/5/200916/6/2026
Stack-based buffer overflow in the MPS.StormPlayer.1 ActiveX control in mps.dll 3.9.4.27 in Baofeng Storm allows remote attackers to execute arbitrary code via a long argument to the OnBeforeVideoDownload method, as exploited in the wild in April and May 2009. NOTE: some of these details are obtained from third party…
ModificadaMedia (5)1.8%—Feng4/1/200816/6/2026
Interpretation conflict in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a User-Agent header line that contains a carriage-return character, which is considered a line delimiter when the header is split into individual lines, but not when…
ModificadaAlta (7.5)4.1%—Feng4/1/200816/6/2026
Multiple buffer overflows in the RTSP_valid_response_msg function in RTSP_state_machine.c in LScube Feng 0.1.15 and earlier allow remote attackers to execute arbitrary code via (1) a long first line of a response, as demonstrated by a long VER line; or (2) a long second line of a response, as demonstrated by a message…
ModificadaMedia (5)3.4%💥 ExploitFeng4/1/200816/6/2026
The Url_init function in utils/url.c in Netembryo 0.0.4, when used by LScube Feng, allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via a malformed URI containing a "/:" sequence, as demonstrated by a "DESCRIBE /: RTSP/1.0" request.
ModificadaAlta (7.5)3.8%—Feng4/1/200816/6/2026
Integer overflow in the RTSP_remove_msg function in RTSP_lowlevel.c in LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (crash) and possibly execute arbitrary code via an RTP packet with a size value of 0xffff.
ModificadaMedia (5)2.1%—Feng4/1/200816/6/2026
LScube Feng 0.1.15 and earlier allows remote attackers to cause a denial of service (NULL dereference and daemon crash) via (1) a malformed Transport header, which triggers misparsing in parse_transport_header in RTSP_setup.c, as demonstrated by a Transport header that contains only a "RTP/AVP;unicast;client_port"…
Orbitaley — Vulnerabilidades