Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1412▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)385▼ 125 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.65% | — | Sielco Polyeco500 FirmwareSielco Polyeco300 FirmwareSielco Polyeco1000 Firmware | 26/10/2023 | 17/6/2026 | Sielco PolyEco1000 is vulnerable to an authentication bypass vulnerability due to an attacker modifying passwords in a POST request and gain unauthorized access to the affected device with administrative privileges. | |
| Modificada | Crítica (9.1) | 0.50% | — | Sielco Polyeco500 FirmwareSielco Polyeco300 FirmwareSielco Polyeco1000 Firmware | 26/10/2023 | 17/6/2026 | Sielco PolyEco1000 is vulnerable to an improper access control vulnerability when the application provides direct access to objects based on user-supplied input. As a result of this vulnerability attackers can bypass authorization and access resources behind protected pages. | |
| Modificada | Alta (8.1) | 0.44% | — | Sielco Polyeco500 FirmwareSielco Polyeco300 FirmwareSielco Polyeco1000 Firmware | 26/10/2023 | 17/6/2026 | Sielco PolyEco1000 is vulnerable to an attacker bypassing authorization and accessing resources behind protected pages. The application interface allows users to perform certain actions via HTTP requests without performing any validity checks to verify the requests. | |
| Modificada | Crítica (9.8) | 0.49% | — | Sielco Polyeco500 FirmwareSielco Polyeco300 FirmwareSielco Polyeco1000 Firmware | 26/10/2023 | 17/6/2026 | Sielco PolyEco1000 uses a weak set of default administrative credentials that can be easily guessed in remote password attacks and gain full control of the system. | |
| Modificada | Alta (7.5) | 0.58% | — | Sielco Polyeco500 FirmwareSielco Polyeco300 FirmwareSielco Polyeco1000 Firmware | 26/10/2023 | 17/6/2026 | Sielco PolyEco1000 is vulnerable to an information disclosure vulnerability due to improper access control enforcement. An unauthenticated remote attacker can exploit this via a specially crafted request to gain access to sensitive information. | |
| Modificada | Crítica (9.8) | 0.54% | — | Sielco Polyeco500 FirmwareSielco Polyeco300 FirmwareSielco Polyeco1000 Firmware | 26/10/2023 | 17/6/2026 | Sielco PolyEco1000 is vulnerable to an attacker escalating their privileges by modifying passwords in POST requests. | |
| Modificada | Crítica (9.8) | 0.47% | — | Sielco Polyeco500 FirmwareSielco Polyeco300 FirmwareSielco Polyeco1000 Firmware | 26/10/2023 | 17/6/2026 | Sielco PolyEco1000 is vulnerable to a session hijack vulnerability due to the cookie being vulnerable to a brute force attack, lack of SSL, and the session being visible in requests. | |
| Modificada | Alta (8.8) | 0.52% | — | Debian LinuxBabeljs BabelBabeljs Babel-helper-define-polyfill-providerBabeljs Babel-plugin-polyfill-corejs2+5 | 12/10/2023 | 17/6/2026 | Babel is a compiler for writingJavaScript. In `@babel/traverse` prior to versions 7.23.2 and 8.0.0-alpha.4 and all versions of `babel-traverse`, using Babel to compile code that was specifically crafted by an attacker can lead to arbitrary code execution during compilation, when using plugins that rely on the… | |
| Modificada | Media (6.5) | 1.2% | — | Jenkins Mathworks Polyspace | 12/7/2023 | 17/6/2026 | Jenkins MathWorks Polyspace Plugin 1.0.5 and earlier allows attackers with Item/Configure permission to send emails with arbitrary files from the Jenkins controller file systems. | |
| Modificada | Alta (7.5) | 0.53% | — | Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom+5 | 30/6/2023 | 17/6/2026 | Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. | |
| Modificada | Alta (7.1) | 0.56% | — | Polymc | 4/4/2023 | 17/6/2026 | PolyMC Launcher <= 1.4.3 is vulnerable to Directory Traversal. A mrpack file can be maliciously crafted to create arbitrary files outside of the installation directory. | |
| Modificada | Alta (7.5) | 1.0% | — | Unpoly-rails | 30/3/2023 | 17/6/2026 | Unpoly is a JavaScript framework for server-side web applications. There is a possible Denial of Service (DoS) vulnerability in the `unpoly-rails` gem that implements the Unpoly server protocol for Rails applications. This issues affects Rails applications that operate as an upstream of a load balancer's that uses… | |
| Modificada | Media (5.4) | 0.50% | — | Poly Trio 8800 Firmware | 8/3/2023 | 9/7/2026 | An arbitrary file upload vulnerability in Poly Trio 8800 7.2.2.1094 allows attackers to execute arbitrary code via a crafted ringtone file. | |
| Modificada | Media (6.7) | 0.23% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Ideacentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+283 | 30/1/2023 | 17/6/2026 | A buffer overflow in the WMI SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to execute arbitrary code. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+143 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in SMI Handler used to configure platform settings over WMI in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (4.4) | 0.20% | — | Lenovo Ideacentre C5-14imb05 FirmwareLenovo Thinkcentre E96z FirmwareLenovo Ideacentre 3 07iab7 FirmwareLenovo Ideacentre 3-07imb05 Firmware+132 | 30/1/2023 | 17/6/2026 | An information leak vulnerability in the Smart USB Protection SMI Handler in some Lenovo models may allow an attacker with local access and elevated privileges to read SMM memory. | |
| Modificada | Media (5.3) | 0.72% | — | Theme AND Plugin Translation FOR Polylang Project Theme AND Plugin Translation FOR Polylang | 28/11/2022 | 17/6/2026 | The Theme and plugin translation for Polylang is vulnerable to authorization bypass in versions up to, and including, 3.2.16 due to missing capability checks in the process_polylang_theme_translation_wp_loaded() function. This makes it possible for unauthenticated attackers to update plugin and theme translation… | |
| Modificada | Alta (7.2) | 23% | — | Poly Eagleeye Director II Firmware | 17/7/2022 | 17/6/2026 | An issue was discovered in Poly EagleEye Director II before 2.2.2.1. os.system command injection can be achieved by an admin. | |
| Modificada | Alta (8.8) | 1.5% | — | Poly Studio X30 FirmwarePoly Studio X70 FirmwarePoly G7500 FirmwarePoly Studio X50 Firmware | 17/7/2022 | 17/6/2026 | An issue was discovered in Poly Studio before 3.7.0. Command Injection can occur via the CN field of a Create Certificate Signing Request (CSR) action. | |
| Modificada | Crítica (9.8) | 2.1% | — | Poly Eagleeye Director II Firmware | 17/7/2022 | 17/6/2026 | An issue was discovered in Poly EagleEye Director II before 2.2.2.1. Existence of a certain file (which can be created via an rsync backdoor) causes all API calls to execute as admin without authentication. | |
| Modificada | Alta (8.8) | 2.7% | — | Poly Trio 8800 Firmware | 28/12/2021 | 17/6/2026 | A remote code execution issue in the ping command on Poly Trio 8800 5.7.1.4145 devices allows remote authenticated users to execute commands via unspecified vectors. | |
| Modificada | Alta (8.8) | 1.7% | — | Polycom VVX 400 FirmwarePolycom VVX 410 Firmware | 4/10/2021 | 17/6/2026 | Poly VVX 400/410 5.3.1 allows low-privileged users to change the Admin password by modifying a POST parameter to 120 during the password reset process. | |
| Modificada | Alta (7.2) | 2.0% | — | Poly Cx5500 FirmwarePoly Cx5100 Firmware | 7/9/2021 | 17/6/2026 | A command-injection vulnerability in an authenticated Telnet connection in Poly (formerly Polycom) CX5500 and CX5100 1.3.5 leads an attacker to Privilege Escalation and Remote Code Execution capability. NOTE: This vulnerability only affects products that are no longer supported by the maintainer | |
| Modificada | Media (5.9) | 1.1% | — | Nonpolynomial Buttplug | 26/1/2021 | 17/6/2026 | An issue was discovered in the buttplug crate before 1.0.4 for Rust. ButtplugFutureStateShared does not properly consider (!Send|!Sync) objects, leading to a data race. | |
| Modificada | Alta (7.2) | 1.1% | — | Polycom HDX System Software | 12/3/2020 | 17/6/2026 | An issue was discovered in Poly (formerly Polycom) HDX 3.1.13. A feature exists that allows the creation of a server / client certificate, or the upload of the user certificate, on the administrator's page. The value received from the user is the factor value of a shell script on the equipment. By entering a special… |