Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2980▼ 83 respecto a la semana anterior
Críticas / altas1452▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)353▼ 157 respecto a la semana anterior
123 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Alta (8.8) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.85% | — | Insteon HUB Firmware | 11/1/2023 | 17/6/2026 | Multiple exploitable buffer overflow vulnerabilities exist in the PubNub message handler for the "cc" channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker should send an… | |
| Modificada | Crítica (9.9) | 0.93% | — | Dell EMC Integrated System FOR Microsoft Azure Stack HUB Firmware | 9/2/2022 | 17/6/2026 | All Dell EMC Integrated System for Microsoft Azure Stack Hub versions contain a privilege escalation vulnerability. A remote malicious user with standard level JEA credentials may potentially exploit this vulnerability to elevate privileges and take over the system. | |
| Modificada | Crítica (9.8) | 2.4% | — | Dell EMC Integrated System FOR Microsoft Azure Stack HUB Firmware | 6/5/2021 | 17/6/2026 | Dell EMC Integrated System for Microsoft Azure Stack Hub, versions 1906 – 2011, contain an undocumented default iDRAC account. A remote unauthenticated attacker, with the knowledge of the default credentials, could potentially exploit this to log in to the system to gain root privileges. | |
| Modificada | Alta (7.5) | 1.3% | — | Peplink Balance 20X FirmwarePeplink Balance 310x FirmwarePeplink MBX FirmwarePeplink EPX Firmware+51 | 7/10/2020 | 17/6/2026 | Peplink Balance before 8.1.0rc1 allows an unauthenticated attacker to download PHP configuration files (/filemanager/php/connector.php) from Web Admin. | |
| Modificada | Media (6.8) | 0.86% | — | Microsoft Surface HUB Firmware | 11/2/2020 | 17/6/2026 | A security feature bypass vulnerability exists in Surface Hub when prompting for credentials, aka 'Surface Hub Security Feature Bypass Vulnerability'. | |
| Modificada | Alta (8.1) | 7.0% | 💥 Exploit | Insteon HUB Firmware | 27/12/2019 | 16/6/2026 | INSTEON Hub 2242-222 lacks Web and API authentication | |
| Modificada | Alta (8.1) | 1.2% | — | Insteon HUB Firmware | 21/3/2019 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP request at At… | |
| Modificada | Alta (8.1) | 1.2% | — | Insteon HUB Firmware | 21/3/2019 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data. An attacker can send an authenticated HTTP request at 0x9d014e4c… | |
| Modificada | Alta (8.1) | 1.1% | — | Insteon HUB Firmware | 21/3/2019 | 17/6/2026 | An exploitable buffer overflow vulnerability exists in the PubNub message handler Insteon Hub 2245-222 - Firmware version 1012 for the cc channel of Insteon Hub running firmware version 1012. Specially crafted commands sent through the PubNub service can cause a stack-based buffer overflow overwriting arbitrary data.… | |
| Modificada | Crítica (9.8) | 3.7% | — | Logitech Harmony HUB Firmware | 20/12/2018 | 17/6/2026 | The Logitech Harmony Hub before version 4.15.206 is vulnerable to application level command injection via crafted HTTP request. An unauthenticated remote attacker can leverage this vulnerability to execute application defined commands (e.g. harmony.system?systeminfo). | |
| Modificada | Alta (8.1) | 1.6% | — | Logitech Harmony HUB Firmware | 20/12/2018 | 17/6/2026 | The Logitech Harmony Hub before version 4.15.206 is vulnerable to OS command injection via the time update request. A remote server or man in the middle can inject OS commands with a properly formatted response. | |
| Modificada | Crítica (9.8) | 1.8% | — | Logitech Harmony HUB Firmware | 20/12/2018 | 17/6/2026 | The XMPP server in Logitech Harmony Hub before version 4.15.206 is vulnerable to authentication bypass via a crafted XMPP request. Remote attackers can use this vulnerability to gain access to the local API. | |
| Modificada | Crítica (9.8) | 1.5% | — | Logitech Harmony HUB Firmware | 20/12/2018 | 17/6/2026 | Logitech Harmony Hub before version 4.15.206 contained two hard-coded accounts in the XMPP server that gave remote users access to the local API. | |
| Modificada | Alta (8.8) | 0.71% | — | Roche Accu-chek Inform II FirmwareRoche Cobas H 232 FirmwareRoche Coaguchek FirmwareRoche Base Unit HUB Firmware | 20/11/2018 | 17/6/2026 | An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Weak access credentials may enable attackers in the adjacent network to gain unauthorized service access via a service interface. | |
| Modificada | Alta (8) | 0.67% | — | Roche Accu-chek Inform II FirmwareRoche Cobas H 232 FirmwareRoche Coaguchek FirmwareRoche Base Unit HUB Firmware | 20/11/2018 | 17/6/2026 | An issue was discovered in Roche Accu-Chek Inform II Base Unit / Base Unit Hub before 03.01.04 and CoaguChek / cobas h232 Handheld Base Unit before 03.01.04. Insecure permissions in a service interface may allow authenticated attackers in the adjacent network to execute arbitrary commands on the operating system. |