Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3006▼ 69 respecto a la semana anterior
Críticas / altas1420▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
61 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.86% | — | Microfocus Voltage Securemail | 4/2/2022 | 17/6/2026 | A potential Information leakage vulnerability has been identified in versions of Micro Focus Voltage SecureMail Mail Relay prior to 7.3.0.1. The vulnerability could be exploited to create an information leakage attack. | |
| Modificada | Alta (7.5) | 8.8% | — | Geneko Gwr352 3G Router FirmwareGeneko Gwr352wv Wide Voltage 3G Router FirmwareGeneko Gwr252 Edge Router FirmwareGeneko Gwr202 Gprs Router Firmware | 19/7/2017 | 17/6/2026 | Geneko GWR routers allow directory traversal sequences starting with a /../ substring, as demonstrated by unauthenticated read access to the configuration file. | |
| Modificada | Media (6.4) | 1.5% | — | Beckwithelectric M-2001d Digital Tapchanger ControlBeckwithelectric M-6200 Digital Voltage Regulator ControlBeckwithelectric M-6200a Digital Voltage Regulator ControlBeckwithelectric M-6280 Digital Capacitor Bank Control+8 | 5/6/2015 | 17/6/2026 | Beckwith Electric M-6200 Digital Voltage Regulator Control with firmware before D-0198V04.07.00, M-6200A Digital Voltage Regulator Control with firmware before D-0228V02.01.07, M-2001D Digital Tapchanger Control with firmware before D-0214V01.10.04, M-6283A Three Phase Digital Capacitor Bank Control with firmware… | |
| Modificada | Media (5.4) | 0.27% | — | Wegoi Re-volt 2 \ | 9/9/2014 | 17/6/2026 | The RE-VOLT 2 : MULTIPLAYER (aka com.wegoi.revolt2multiplayer) application 1.1.4 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Wegoi Re-volt 2 \ | 9/9/2014 | 17/6/2026 | The RE-VOLT 2 : Best RC 3D Racing (aka com.wego.revolt2_global) application 1.2.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Alta (10) | 1.5% | — | Carlosgavazzi Eos-box Photovoltaic Monitoring System FirmwareCarlosgavazzi Eos-box Photovoltaic Monitoring System | 23/12/2012 | 16/6/2026 | The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access. | |
| Modificada | Alta (7.5) | 1.3% | — | Carlosgavazzi Eos-box Photovoltaic Monitoring System FirmwareCarlosgavazzi Eos-box Photovoltaic Monitoring System | 23/12/2012 | 16/6/2026 | The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality. | |
| Modificada | Alta (10) | 4.9% | — | Sinapsitech Sinapsi FirmwareSinapsitech Esolar DUO Photovoltaic System MonitorSinapsitech Esolar Light Photovoltaic System MonitorSinapsitech Esolar Photovoltaic System Monitor | 23/11/2012 | 16/6/2026 | These Sinapsi devices do not check if users that visit pages within the device have properly authenticated. By directly visiting the pages within the device, attackers can gain unauthorized access with administrative privileges. | |
| Modificada | Alta (10) | 25% | — | Sinapsitech Sinapsi FirmwareSinapsitech Esolar DUO Photovoltaic System MonitorSinapsitech Esolar Light Photovoltaic System MonitorSinapsitech Esolar Photovoltaic System Monitor | 23/11/2012 | 16/6/2026 | These Sinapsi devices do not check for special elements in commands sent to the system. By accessing certain pages with administrative privileges that do not require authentication within the device, attackers can execute arbitrary, unexpected, or dangerous commands directly onto the operating system. | |
| Modificada | Alta (10) | 12% | — | Sinapsitech Sinapsi FirmwareSinapsitech Esolar DUO Photovoltaic System MonitorSinapsitech Esolar Light Photovoltaic System MonitorSinapsitech Esolar Photovoltaic System Monitor | 23/11/2012 | 16/6/2026 | These Sinapsi devices store hard-coded passwords in the PHP file of the device. By using the hard-coded passwords in the device, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access. | |
| Modificada | Alta (7.5) | 4.2% | — | Sinapsitech Sinapsi FirmwareSinapsitech Esolar DUO Photovoltaic System MonitorSinapsitech Esolar Light Photovoltaic System MonitorSinapsitech Esolar Photovoltaic System Monitor | 23/11/2012 | 16/6/2026 | These Sinapsi devices do not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication within the device, attackers can leak information from the device. This could allow the attacker to compromise confidentiality. |