Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2997▼ 66 respecto a la semana anterior
Críticas / altas1460▲ 109 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)339▼ 171 respecto a la semana anterior
–

78 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)0.40%—Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+1712/11/202117/6/2026
A buffer overflow was reported in the local web server of some Motorola-branded Binatone Hubble Cameras that could allow an unauthenticated attacker on the same network to perform a denial-of-service attack against the device.
ModificadaMedia (4.6)0.09%—Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+1712/11/202117/6/2026
An information disclosure vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access to obtain the encryption key used to decrypt firmware update packages.
ModificadaMedia (6.8)0.24%—Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+1712/11/202117/6/2026
An exposed debug interface was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with physical access unauthorized access to the device.
ModificadaAlta (7.8)0.17%—Binatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+1712/11/202117/6/2026
A vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker with local access to obtain the MQTT credentials that could result in unauthorized access to backend Hubble services.
ModificadaAlta (8.8)60%💥 ExploitBinatoneglobal Halo+ Camera FirmwareBinatoneglobal Comfort 85 Connect FirmwareBinatoneglobal Mbp3855 FirmwareBinatoneglobal Focus 68 Firmware+1712/11/202117/6/2026
An unauthenticated remote code execution vulnerability was reported in some Motorola-branded Binatone Hubble Cameras that could allow an attacker on the same network unauthorized access to the device.
ModificadaAlta (7.5)1.2%—Halo12/7/202117/6/2026
SSRF vulnerability in Halo <=1.3.2 exists in the SMTP configuration, which can detect the server intranet.
ModificadaCrítica (9.1)1.2%—Halo12/7/202117/6/2026
File Deletion vulnerability in Halo 0.4.3 via delBackup.
ModificadaMedia (5.3)0.89%—Halo12/7/202117/6/2026
Incorrect Access Control vulnearbility in Halo 0.4.3, which allows a malicious user to bypass encrption to view encrpted articles via cookies.
ModificadaMedia (5.4)0.57%—Halo12/7/202117/6/2026
Cross Sie Scripting (XSS) vulnerability in Halo 0.4.3 via CommentAuthorUrl.
ModificadaCrítica (9.8)1.5%—Halo12/7/202117/6/2026
Remote Code Executon vulnerability in Halo 0.4.3 via the remoteAddr and themeName parameters.
ModificadaMedia (6.1)0.74%—Halo12/7/202117/6/2026
Cross Siste Scripting (XSS) vulnerablity in Halo 0.4.3 via the X-forwarded-for Header parameter.
ModificadaMedia (6.1)0.81%—Halo20/5/202117/6/2026
Cross Site Scripting (XSS) vulnerability in Halo 1.1.3 via post publish components in the manage panel, which lets a remote malicious user execute arbitrary code.
ModificadaAlta (7.7)1.1%—Halo30/9/202017/6/2026
There is an Arbitrary file deletion vulnerability in halo v1.1.3. A backup function in the background allows a user, when deleting their backup files, to delete any files on the system through directory traversal.
ModificadaCrítica (9.8)1.9%—Halo30/9/202017/6/2026
An Arbitrary file writing vulnerability in halo v1.1.3. In an interface to write files in the background, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.
ModificadaAlta (7.5)1.9%—Halo30/9/202017/6/2026
Halo V1.1.3 is affected by: Arbitrary File reading. In an interface that reads files in halo v1.1.3, a directory traversal check is performed on the input path parameter, but the startsWith function can be used to bypass it.
ModificadaCrítica (9.1)1.5%—Halo30/9/202017/6/2026
There is a XML external entity (XXE) vulnerability in halo v1.1.3, The function of importing other blogs in the background(/api/admin/migrations/wordpress) needs to parse the xml file, but it is not used for security defense, This vulnerability can detect the intranet, read files, enable ddos attacks, etc.…
ModificadaCrítica (9.8)2.6%—Halo30/9/202017/6/2026
—
ModificadaCrítica (9.8)1.5%—Halo30/9/202017/6/2026
An issue was discovered in halo V1.1.3. A Zip Slip Directory Traversal Vulnerability in the backend,the attacker can overwrite some files, such as ftl files, .bashrc files in the user directory, and finally get the permissions of the operating system.
ModificadaMedia (5.4)0.50%—Halo26/8/202017/6/2026
Halo blog 1.2.0 allows users to submit comments on blog posts via /api/content/posts/comments. The javascript code supplied by the attacker will then execute in the victim user's browser.
ModificadaAlta (7.2)1.5%—Halo26/12/201917/6/2026
Halo before 1.2.0-beta.1 allows Server Side Template Injection (SSTI) because TemplateClassResolver.SAFER_RESOLVER is not used in the FreeMarker configuration.
ModificadaMedia (5.4)0.66%—Halo25/9/201917/6/2026
Halo 1.1.0 has XSS via a crafted authorUrl in JSON data to api/content/posts/comments.
ModificadaAlta (7.1)0.41%—Eaton Halo Home22/5/201917/6/2026
The Android mobile application Halo Home before 1.11.0 stores OAuth authentication and refresh access tokens in a clear text file. This file persists until the user logs out of the application and reboots the device. This vulnerability can allow an attacker to impersonate the legitimate user by reusing the stored…
ModificadaMedia (6.1)0.62%—Halo12/5/201817/6/2026
ruibaby Halo 0.0.2 has stored XSS via the loginName and loginPwd parameters in a failed login attempt to AdminController.java.
ModificadaMedia (6.1)0.62%—Halo12/5/201817/6/2026
ruibaby Halo 0.0.2 has stored XSS via the commentAuthor field to FrontCommentController.java.
ModificadaMedia (6.8)0.93%💥 ExploitAnoochit Chalothorn Tiny Blogr28/4/200916/6/2026
SQL injection vulnerability in class.eport.php in Tiny Blogr 1.0.0 rc4, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary SQL commands via the txtUsername parameter (aka the Username field). NOTE: some of these details are obtained from third party information.
Orbitaley — Vulnerabilidades