Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
–

96 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)1.3%—Milesight Ur32l Firmware6/7/202317/6/2026
A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability.
ModificadaAlta (8.1)0.56%—Milesight Ur32l Firmware6/7/202317/6/2026
A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability.
ModificadaCrítica (9.8)0.76%—Milesightvpn6/7/202317/6/2026
An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability.
ModificadaAlta (7.2)3.7%—Milesight Ur32l Firmware6/7/202317/6/2026
An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (8.8)5.8%—Milesight Ur32l Firmware6/7/202317/6/2026
An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An authenticated attacker can send an HTTP request to trigger this vulnerability.
ModificadaAlta (8.1)3.4%—Milesightvpn6/7/202317/6/2026
An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to command execution. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaAlta (7.2)2.2%—Milesight Ur32l Firmware6/7/202317/6/2026
An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted set of network packets can lead to command execution. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9.8)0.90%—Milesightvpn6/7/202317/6/2026
A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability.
ModificadaAlta (7.2)3.6%—Milesight Ur32l Firmware6/7/202317/6/2026
An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability.
ModificadaAlta (8.8)3.6%—Milesight Ur32l Firmware6/7/202317/6/2026
An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability.
ModificadaCrítica (9.8)0.60%—Milesight Ncr/camera Firmware12/6/202317/6/2026
Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method.
ModificadaAlta (7.5)0.57%—Milesight Ncr/camera Firmware8/5/202317/6/2026
Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request.
ModificadaAlta (7.5)0.50%—Milesight Ncr/camera Firmware8/5/202317/6/2026
Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request.
ModificadaCrítica (9.8)1.1%—Milesight Ms-n5008-uc FirmwareMilesight Ms-n1008-unc FirmwareMilesight Ms-n1008-uc FirmwareMilesight Ms-n1004-uc Firmware+1728/4/202317/6/2026
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests…
ModificadaCrítica (9.8)1.1%—Milesight Ms-n5008-uc FirmwareMilesight Ms-n1008-unc FirmwareMilesight Ms-n1008-uc FirmwareMilesight Ms-n1004-uc Firmware+1728/4/202317/6/2026
This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http…
ModificadaAlta (7.5)1.4%—Milesight Video Management Systems Firmware15/9/202217/6/2026
This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera.…
ModificadaCrítica (9.8)2.1%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations.
ModificadaCrítica (9.8)3.1%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource.
ModificadaCrítica (9.8)2.1%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts.
ModificadaCrítica (9.8)2.1%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory.
ModificadaCrítica (9.8)3.2%—Milesight IP Security Camera Firmware25/10/201917/6/2026
Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password.
Orbitaley — Vulnerabilidades