Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 69 respecto a la semana anterior
Críticas / altas1424▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

156 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.4)0.55%—Promotion Slider Project Promotion Slider15/6/202217/6/2026
Multiple Authenticated (contributor or higher user role) Stored Cross-Site Scripting (XSS) vulnerabilities in Promotion Slider plugin <= 3.3.4 at WordPress.
ModificadaAlta (7.5)1.1%—Rice Open Motion Planning Library3/5/202217/6/2026
OMPL v1.5.2 contains a memory leak in VFRRT.cpp
ModificadaAlta (7.5)0.90%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior transmits or stores authentication credentials, but it uses an insecure method susceptible to unauthorized interception and/or retrieval.
ModificadaAlta (7.5)0.64%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior transmits sensitive or security-critical data in cleartext in a communication channel that can be sniffed by unauthorized actors.
ModificadaAlta (7.5)0.63%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior uses a cryptographic key or password past its expiration date, which diminishes its safety significantly by increasing the timing window for cracking attacks against that key.
ModificadaAlta (7.5)0.56%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
The use of a broken or risky cryptographic algorithm in Philips Vue PACS versions 12.2.x.x and prior is an unnecessary risk that may result in the exposure of sensitive information.
ModificadaCrítica (9.8)0.92%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior does not follow certain coding rules for development, which can lead to resultant weaknesses or increase the severity of the associated vulnerabilities.
ModificadaCrítica (9.8)0.85%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior does not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.
ModificadaMedia (6.5)0.68%—Philips MyvuePhilips SpeechPhilips VUE MotionPhilips VUE Pacs1/4/202217/6/2026
Philips Vue PACS versions 12.2.x.x and prior does not ensure or incorrectly ensures structured messages or data are well formed and that certain security properties are met before being read from an upstream component or sent to a downstream component.
ModificadaAlta (7.5)6.9%—Motioneye Project Motioneye24/3/202217/6/2026
MotionEye v0.42.1 and below allows attackers to access sensitive information via a GET request to /config/list. To exploit this vulnerability, a regular user password must be unconfigured.
ModificadaCrítica (9.8)1.3%—Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+4211/2/202217/6/2026
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
ModificadaAlta (7.2)3.1%—Motioneye Project MotioneyeMotioneyeos Project Motioneyeos31/1/202217/6/2026
Authenticated remote code execution in MotionEye <= 0.42.1 and MotioneEyeOS <= 20200606 allows a remote attacker to upload a configuration backup file containing a malicious python pickle file which will execute arbitrary code on the server.
ModificadaAlta (7.5)1.2%—Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+84/10/202117/6/2026
Information disclosure: The main configuration, including users and their hashed passwords, is exposed by an unprotected web server resource and can be accessed without authentication. Additionally, device details are exposed which include the serial number and the firmware version by another unprotected web server…
ModificadaCrítica (9.8)1.2%—Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 FirmwareBosch Rexroth Indramotion MLC L25 FirmwareBosch Rexroth Indramotion MLC L45 Firmware+84/10/202117/6/2026
Login with hash: The login routine allows the client to log in to the system not by using the password, but by using the hash of the password. Combined with CVE-2021-23858, this allows an attacker to subsequently login to the system.
ModificadaMedia (6.1)0.63%—Bosch Rexroth Indramotion MLC L20 FirmwareBosch Rexroth Indramotion MLC L40 Firmware4/10/202117/6/2026
The web server is vulnerable to reflected XSS and therefore an attacker might be able to execute scripts on a client’s computer by sending the client a manipulated URL.
ModificadaAlta (7.5)0.60%—Bosch Rexroth Indramotion XLC FirmwareBosch Rexroth Indramotion MLC Firmware4/10/202117/6/2026
The user and password data base is exposed by an unprotected web server resource. Passwords are hashed with a weak hashing algorithm and therefore allow an attacker to determine the password by using rainbow tables.
ModificadaMedia (6.8)0.58%—Netmotionsoftware Mobility16/9/202117/6/2026
The access controls on the Mobility read-write API improperly validate user access permissions; this API is disabled by default. If the API is manually enabled, attackers with both network access to the API and valid credentials can read and write data to it; regardless of access control group membership settings.…
ModificadaMedia (5.3)0.58%—Netmotionsoftware Mobility16/9/202117/6/2026
The access controls on the Mobility read-only API improperly validate user access permissions. Attackers with both network access to the API and valid credentials can read data from it; regardless of access control group membership settings. This vulnerability is fixed in Mobility v11.76 and Mobility v12.14.
ModificadaAlta (7.5)0.68%—Magicsmotion Flamingo 2 Firmware15/7/202117/6/2026
The MagicMotion Flamingo 2 application for Android stores data on an sdcard under com.vt.magicmotion/files/Pictures, whence it can be read by other applications.
ModificadaMedia (5.3)0.20%—Magicsmotion Flamingo 2 Firmware15/7/202117/6/2026
MagicMotion Flamingo 2 lacks BLE encryption, enabling data sniffing and packet forgery.
ModificadaMedia (4.6)0.26%—Magicsmotion Flamingo 2 Firmware15/7/202117/6/2026
MagicMotion Flamingo 2 has a lack of access control for reading from device descriptors.
ModificadaAlta (7.8)0.23%—Samsung Slow Motion Editor25/3/202117/6/2026
Using unsafe PendingIntent in Slow Motion Editor prior to version 3.5.18.5 allows local attackers unauthorized action without permission via hijacking the PendingIntent.
ModificadaMedia (5.3)1.1%—Genymobile Genymotion Desktop22/2/202117/6/2026
Genymotion Desktop through 3.2.0 leaks the host's clipboard data to the Android application by default. NOTE: the vendor's position is that this is intended behavior that can be changed through the Settings > Device screen
ModificadaAlta (8.1)42%—Netmotionsoftware Netmotion Mobility8/2/202117/6/2026
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in webrepdb StatusServlet.
ModificadaAlta (8.1)78%—Netmotionsoftware Netmotion Mobility8/2/202117/6/2026
NetMotion Mobility before 11.73 and 12.x before 12.02 allows unauthenticated remote attackers to execute arbitrary code as SYSTEM because of Java deserialization in MvcUtil valueStringToObject.