Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2861▲ 226 respecto a la semana anterior
Críticas / altas1331▼ 99 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)237▲ 223 respecto a la semana anterior
150 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.2) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the ys_thirdparty user_delete functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Media (6.5) | 1.3% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 0.56% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.76% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 3.7% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 5.8% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An authenticated attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 3.4% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to command execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 2.2% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted set of network packets can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.90% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.60% | — | Milesight Ncr/camera Firmware | 12/6/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method. | |
| Modificada | Alta (7.5) | 0.57% | — | Milesight Ncr/camera Firmware | 8/5/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request. | |
| Modificada | Alta (7.5) | 0.50% | — | Milesight Ncr/camera Firmware | 8/5/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request. | |
| Modificada | Crítica (9.8) | 1.1% | — | Milesight Ms-n5008-uc FirmwareMilesight Ms-n1008-unc FirmwareMilesight Ms-n1008-uc FirmwareMilesight Ms-n1004-uc Firmware+17 | 28/4/2023 | 17/6/2026 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests… | |
| Modificada | Crítica (9.8) | 1.1% | — | Milesight Ms-n5008-uc FirmwareMilesight Ms-n1008-unc FirmwareMilesight Ms-n1008-uc FirmwareMilesight Ms-n1004-uc Firmware+17 | 28/4/2023 | 17/6/2026 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http… | |
| Modificada | Alta (8) | 0.85% | — | Foresightsports GC3 Launch Monitor FirmwareBushnellgolf Launch PRO Firmware | 13/10/2022 | 17/6/2026 | Foresight GC3 Launch Monitor versión 1.3.15.68, es enviado con un servicio Target Communication Framework (TCF) habilitado. Este servicio escucha en un puerto TCP en todas las interfaces y permite una depuración de procesos, la modificación del sistema de archivos y el acceso al terminal como usuario root. Junto con… | |
| Modificada | Alta (7.5) | 1.4% | — | Milesight Video Management Systems Firmware | 15/9/2022 | 17/6/2026 | Esta vulnerabilidad se presenta en Milesight Video Management Systems (VMS), en todas las versiones de firmware anteriores a 40.7.0.79-r1, debido a un manejo inapropiado de las entradas en la interfaz de administración basada en web de la cámara. Un atacante remoto podría explotar esta vulnerabilidad mediante el envío… | |
| Modificada | Alta (8.8) | 0.87% | — | Tibco Foresight Archive AND Retrieval SystemTibco Foresight Operational MonitorTibco Foresight Transaction Insight | 20/10/2020 | 17/6/2026 | El componente de reporte Transaction Insight de TIBCO Foresight Archive and Retrieval System, TIBCO Foresight Archive and Retrieval System Healthcare Edition, TIBCO Foresight Operational Monitor, TIBCO Foresight Operational Monitor Healthcare Edition, TIBCO Foresight Transaction Insight y TIBCO Foresight Transaction… | |
| Modificada | Crítica (9.8) | 4.5% | — | IBM IOT MessagesightIBM Watson IOT Platform - Message Gateway | 28/1/2020 | 17/6/2026 | IBM Watson IoT Message Gateway versiones 2.0.0.x, 5.0.0.0, 5.0.0.1 y 5.0.0.2, es vulnerable a un desbordamiento del búfer, causado por una comprobación de límites inapropiada cuando se maneja una petición HTTP fallida con contenido específico en los encabezados. Mediante el envío de una petición HTTP especialmente… | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Las cámaras de seguridad IP de Milesight hasta el 14-11-2016, presentan una contraseña root predeterminada en el directorio /etc/shadow que es la misma en las diferentes instalaciones de los clientes. | |
| Modificada | Crítica (9.8) | 3.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Las cámaras de seguridad IP de Milesight hasta el 14-11-2016, permiten a atacantes remotos omitir la autenticación y acceder a un recurso protegido al realizar simultáneamente una petición para el recurso vb.htm desprotegido. | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Las cámaras de seguridad IP de Milesight hasta el 14-11-2016, presentan un conjunto predeterminado de 10 cuentas privilegiadas con credenciales embebidas. Estas son accesibles si el cliente no ha configurado 10 cuentas de usuario reales. | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Las cámaras de seguridad IP de Milesight hasta el 14-11-2016, presentan una clave privada SSL embebida en el directorio /etc/config. | |
| Modificada | Crítica (9.8) | 3.2% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Las cámaras de seguridad IP de Milesight hasta el 14-11-2016, presentan un desbordamiento de búfer en una aplicación web por medio de un nombre de usuario o contraseña de gran tamaño. |