Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
156 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 0.55% | — | Promotion Slider Project Promotion Slider | 15/6/2022 | 17/6/2026 | Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Promotion Slider plugin <= 3.3.4 at WordPress. | |
| Modificada | Alta (7.5) | 1.1% | — | Rice Open Motion Planning Library | 3/5/2022 | 17/6/2026 | OMPL v1.5.2 contains a memory leak in VFRRT.cpp | |
| Modificada | Alta (7.5) | 0.90% | — | Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs | 1/4/2022 | 17/6/2026 | Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval. | |
| Modificada | Alta (7.5) | 0.64% | — | Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs | 1/4/2022 | 17/6/2026 | Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors. | |
| Modificada | Alta (7.5) | 0.63% | — | Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs | 1/4/2022 | 17/6/2026 | Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key. | |
| Modificada | Alta (7.5) | 0.56% | — | Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs | 1/4/2022 | 17/6/2026 | The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive information. | |
| Modificada | Crítica (9.8) | 0.92% | — | Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs | 1/4/2022 | 17/6/2026 | Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities. | |
| Modificada | Crítica (9.8) | 0.85% | — | Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs | 1/4/2022 | 17/6/2026 | Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product. | |
| Modificada | Media (6.5) | 0.68% | — | Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs | 1/4/2022 | 17/6/2026 | Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component. | |
| Modificada | Alta (7.5) | 6.9% | — | Motioneye Project Motioneye | 24/3/2022 | 17/6/2026 | MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured. | |
| Modificada | Crítica (9.8) | 1.3% | — | Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+42 | 11/2/2022 | 17/6/2026 | Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition. | |
| Modificada | Alta (7.2) | 3.1% | — | Motioneye Project MotioneyeMotioneyeos Project Motioneyeos | 31/1/2022 | 17/6/2026 | Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server. | |
| Modificada | Alta (7.5) | 1.2% | — | Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+8 | 4/10/2021 | 17/6/2026 | Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server… | |
| Modificada | Crítica (9.8) | 1.2% | — | Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+8 | 4/10/2021 | 17/6/2026 | Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system. | |
| Modificada | Media (6.1) | 0.63% | — | Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 Firmware | 4/10/2021 | 17/6/2026 | The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL. | |
| Modificada | Alta (7.5) | 0.60% | — | Bosch Rexroth Indramotion XLC FirmwareBosch Rexroth Indramotion MLC Firmware | 4/10/2021 | 17/6/2026 | The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables. | |
| Modificada | Media (6.8) | 0.58% | — | Netmotionsoftware Mobility | 16/9/2021 | 17/6/2026 | The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings.… | |
| Modificada | Media (5.3) | 0.58% | — | Netmotionsoftware Mobility | 16/9/2021 | 17/6/2026 | The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14. | |
| Modificada | Alta (7.5) | 0.68% | — | Magicsmotion Flamingo 2 Firmware | 15/7/2021 | 17/6/2026 | The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications. | |
| Modificada | Media (5.3) | 0.20% | — | Magicsmotion Flamingo 2 Firmware | 15/7/2021 | 17/6/2026 | MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery. | |
| Modificada | Media (4.6) | 0.26% | — | Magicsmotion Flamingo 2 Firmware | 15/7/2021 | 17/6/2026 | MagicMotion Flamingo 2 has a lack of access control for reading from device descriptors. | |
| Modificada | Alta (7.8) | 0.23% | — | Samsung Slow Motion Editor | 25/3/2021 | 17/6/2026 | Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent. | |
| Modificada | Media (5.3) | 1.1% | — | Genymobile Genymotion Desktop | 22/2/2021 | 17/6/2026 | Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device screen | |
| Modificada | Alta (8.1) | 42% | — | Netmotionsoftware Netmotion Mobility | 8/2/2021 | 17/6/2026 | NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet. | |
| Modificada | Alta (8.1) | 78% | — | Netmotionsoftware Netmotion Mobility | 8/2/2021 | 17/6/2026 | NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject. |