Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2730▼ 572 respecto a la semana anterior
Críticas / altas1301▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)295▼ 215 respecto a la semana anterior
101 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.3) | 0.32% | — | Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+43 | 27/4/2020 | 17/6/2026 | There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2… | |
| Modificada | Media (5.3) | 0.32% | — | Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+43 | 27/4/2020 | 17/6/2026 | There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1… | |
| Modificada | Media (5.3) | 0.92% | — | Huawei Alp-al00b FirmwareHuawei Alp-tl00b FirmwareHuawei Bla-al00b FirmwareHuawei Bla-tl00b Firmware+46 | 14/12/2019 | 17/6/2026 | Some Huawei smart phones have a null pointer dereference vulnerability. An attacker crafts specific packets and sends to the affected product to exploit this vulnerability. Successful exploitation may cause the affected phone to be abnormal. | |
| Modificada | Alta (8.1) | 2.7% | 💥 PoC | Google AndroidApple Iphone OSApple MAC OS XApple Tvos+143 | 14/8/2019 | 17/6/2026 | The Bluetooth BR/EDR specification up to and including version 5.1 permits sufficiently low encryption key length and does not prevent an attacker from influencing the key length negotiation. This allows practical brute-force attacks (aka "KNOB") that can decrypt traffic and inject arbitrary ciphertext without the… | |
| Modificada | Crítica (9.8) | 1.8% | — | Arlo Vmb3010 FirmwareArlo Vmb4000 FirmwareArlo Vmb3500 FirmwareArlo Vmb4500 Firmware+1 | 9/7/2019 | 17/6/2026 | Arlo Basestation firmware 1.12.0.1_27940 and prior contain a hardcoded username and password combination that allows root access to the device when an onboard serial interface is connected to. | |
| Modificada | Crítica (9.8) | 1.2% | — | Arlo Vmb3010 FirmwareArlo Vmb4000 FirmwareArlo Vmb3500 FirmwareArlo Vmb4500 Firmware+1 | 9/7/2019 | 17/6/2026 | Arlo Basestation firmware 1.12.0.1_27940 and prior firmware contain a networking misconfiguration that allows access to restricted network interfaces. This could allow an attacker to upload or download arbitrary files and possibly execute malicious code on the device. | |
| Modificada | Media (4.6) | 0.24% | — | Huawei Alp-al00b FirmwareHuawei Alp-al00b-rsc FirmwareHuawei Bla-tl00b FirmwareHuawei Charlotte-al00a Firmware+1 | 23/10/2018 | 17/6/2026 | Some Huawei smart phones ALP-AL00B 8.0.0.106(C00), 8.0.0.113(SP2C00), 8.0.0.113(SP3C00), 8.0.0.113(SP7C00), 8.0.0.118(C00), 8.0.0.120(SP2C00), 8.0.0.125(SP1C00), 8.0.0.125(SP3C00), 8.0.0.126(SP2C00), 8.0.0.126(SP5C00), 8.0.0.127(SP1C00), 8.0.0.128(SP2C00), ALP-AL00B-RSC 1.0.0.2, BLA-TL00B 8.0.0.113(SP7C01),… | |
| Modificada | Crítica (9.8) | 3.0% | 💥 Exploit | Beauty Parlour Booking Script Project Beauty Parlour Booking Script | 13/12/2017 | 17/6/2026 | Beauty Parlour Booking Script 1.0 has SQL Injection via the /list gender or city parameter. | |
| Modificada | Alta (7.5) | 9.3% | — | Carlosgavazzi Vmu-c EM FirmwareCarlosgavazzi Vmu-c PV Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Sensitive information is stored in clear-text. | |
| Modificada | Crítica (10) | 1.2% | — | Carlosgavazzi Vmu-c EM FirmwareCarlosgavazzi Vmu-c PV Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. Successful exploitation of this CROSS-SITE REQUEST FORGERY (CSRF) vulnerability can allow execution of unauthorized actions on the device such as configuration parameter changes, and saving… | |
| Modificada | Crítica (9.8) | 2.4% | — | Carlosgavazzi Vmu-c EM FirmwareCarlosgavazzi Vmu-c PV Firmware | 13/2/2017 | 17/6/2026 | An issue was discovered in Carlo Gavazzi VMU-C EM prior to firmware Version A11_U05, and VMU-C PV prior to firmware Version A17. The access control flaw allows access to most application functions without authentication. | |
| Modificada | Alta (8.1) | 4.1% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier use a pattern of adjective, noun, and three-digit number for the customized password, which makes it easier for remote attackers to obtain… | |
| Modificada | Crítica (9.8) | 5.2% | — | Netgear Arlo Base Station FirmwareNetgear Arlo Q Camera FirmwareNetgear Arlo Q Plus Camera Firmware | 4/1/2017 | 17/6/2026 | NETGEAR Arlo base stations with firmware 1.7.5_6178 and earlier, Arlo Q devices with firmware 1.8.0_5551 and earlier, and Arlo Q Plus devices with firmware 1.8.1_6094 and earlier have a default password of 12345678, which makes it easier for remote attackers to obtain access after a factory reset or in a factory… | |
| Modificada | Alta (10) | 1.5% | — | Carlosgavazzi Eos-box Photovoltaic Monitoring System FirmwareCarlosgavazzi Eos-box Photovoltaic Monitoring System | 23/12/2012 | 16/6/2026 | The Carlo Gavazzi EOS-Box stores hard-coded passwords in the PHP file of the device. By using the hard-coded passwords, attackers can log into the device with administrative privileges. This could allow the attacker to have unauthorized access. | |
| Modificada | Alta (7.5) | 1.3% | — | Carlosgavazzi Eos-box Photovoltaic Monitoring System FirmwareCarlosgavazzi Eos-box Photovoltaic Monitoring System | 23/12/2012 | 16/6/2026 | The Carlo Gavazzi EOS-Box does not check the validity of the data before executing queries. By accessing the SQL table of certain pages that do not require authentication, attackers can leak information from the device. This could allow the attacker to compromise confidentiality. | |
| Modificada | Alta (7.5) | 1.1% | — | Carlos Carvalhar Time Spent | 3/12/2012 | 16/6/2026 | SQL injection vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to execute arbitrary SQL commands via unspecified vectors. | |
| Modificada | Media (6.8) | 0.57% | — | Carlos Carvalhar Time Spent | 3/12/2012 | 16/6/2026 | Cross-site request forgery (CSRF) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to hijack the authentication of unspecified victims via unknown vectors. | |
| Modificada | Media (4.3) | 0.93% | — | Carlos Carvalhar Time Spent | 3/12/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Time Spent module 6.x and 7.x for Drupal allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Carlos Eduardo Sotelo Pinto 0.1.0 | 6/5/2010 | 16/6/2026 | PHP remote file inclusion vulnerability in core/includes/gfw_smarty.php in Gallo 0.1.0, when magic_quotes_gpc is disabled, allows remote attackers to execute arbitrary PHP code via a URL in the config[gfwroot] parameter. | |
| Modificada | Media (6.9) | 0.36% | — | Jose Carlos Medeiros Maildirsync | 18/11/2008 | 16/6/2026 | sample.sh in maildirsync 1.1 allows local users to append data to arbitrary files via a symlink attack on a /tmp/maildirsync-*.#####.log temporary file. | |
| Modificada | Media (4.3) | 3.6% | 💥 Exploit | Carlos Desseno Youtube Blog | 25/7/2008 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in mensaje.php in C. Desseno YouTube Blog (ytb) 0.1 allows remote attackers to inject arbitrary web script or HTML via the m parameter. | |
| Modificada | Media (6.8) | 2.0% | 💥 Exploit | Carlos Desseno Youtube Blog | 25/7/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in cuenta/cuerpo.php in C. Desseno YouTube Blog (ytb) 0.1, when register_globals is enabled, allows remote attackers to execute arbitrary PHP code via a URL in the base_archivo parameter. | |
| Modificada | Media (6.8) | 1.9% | — | Enemies OF Carlotta | 14/12/2006 | 16/6/2026 | eoc.py in Enemies of Carlotta (EoC) before 1.2.4 allows remote attackers to execute arbitrary commands via shell metacharacters in an "SMTP level e-mail address". | |
| Modificada | Alta (7.5) | 4.4% | 💥 Exploit | Carlos Sanchez Valle MynewsgroupsPHP Layers Menu | 1/8/2006 | 16/6/2026 | PHP remote file inclusion vulnerability in /lib/tree/layersmenu.inc.php in the PHP Layers Menu 2.3.5 package for MyNewsGroups :) 0.6b and earlier allows remote attackers to execute arbitrary PHP code via a URL in the myng_root parameter. | |
| Modificada | Alta (7.5) | 1.3% | — | Carlos Sanchez Valle Mynewsgroups | 3/7/2006 | 16/6/2026 | SQL injection vulnerability in tree.php in MyNewsGroups 0.6 allows remote attackers to execute arbitrary SQL commands via the grp_id parameter. |