Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2764▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 211 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)245▼ 256 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 1.3% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A directory traversal vulnerability exists in the luci2-io file-export mib functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to arbitrary file read. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 0.56% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | A misconfiguration vulnerability exists in the urvpn_client functionality of Milesight UR32L v32.3.0.5. A specially-crafted man-in-the-middle attack can lead to increased privileges. An attacker can perform a man-in-the-middle attack to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.76% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | An authentication bypass vulnerability exists in the requestHandlers.js verifyToken functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 3.7% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An os command injection vulnerability exists in the libzebra.so change_hostname functionality of Milesight UR32L v32.3.0.5. A specially-crafted network packets can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 5.8% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the vtysh_ubus tcpdump_start_cb functionality of Milesight UR32L v32.3.0.5. A specially crafted HTTP request can lead to command execution. An authenticated attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 3.4% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | An os command injection vulnerability exists in the liburvpn.so create_private_key functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to command execution. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 2.2% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the ys_thirdparty check_system_user functionality of Milesight UR32L v32.3.0.5. A specially crafted set of network packets can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.90% | — | Milesightvpn | 6/7/2023 | 17/6/2026 | A sql injection vulnerability exists in the requestHandlers.js LoginAuth functionality of Milesight VPN v2.0.2. A specially-crafted network request can lead to authentication bypass. An attacker can send a malicious packet to trigger this vulnerability. | |
| Modificada | Alta (7.2) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the libzebra.so bridge_group functionality of Milesight UR32L v32.3.0.5. A specially crafted network packet can lead to command execution. An attacker can send a sequence of requests to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.6% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | An OS command injection vulnerability exists in the vtysh_ubus _get_fw_logs functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 0.60% | — | Milesight Ncr/camera Firmware | 12/6/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 allows authentication bypass through an unspecified method. | |
| Modificada | Alta (7.5) | 0.57% | — | Milesight Ncr/camera Firmware | 8/5/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 exposes credentials through an unspecified request. | |
| Modificada | Alta (7.5) | 0.50% | — | Milesight Ncr/camera Firmware | 8/5/2023 | 17/6/2026 | Milesight NCR/camera version 71.8.0.6-r5 discloses sensitive information through an unspecified request. | |
| Modificada | Crítica (9.8) | 1.1% | — | Milesight Ms-n5008-uc FirmwareMilesight Ms-n1008-unc FirmwareMilesight Ms-n1008-uc FirmwareMilesight Ms-n1004-uc Firmware+17 | 28/4/2023 | 17/6/2026 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to improper authorization at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http requests… | |
| Modificada | Crítica (9.8) | 1.1% | — | Milesight Ms-n5008-uc FirmwareMilesight Ms-n1008-unc FirmwareMilesight Ms-n1008-uc FirmwareMilesight Ms-n1004-uc Firmware+17 | 28/4/2023 | 17/6/2026 | This vulnerability exists in Milesight 4K/H.265 Series NVR models (MS-Nxxxx-xxG, MS-Nxxxx-xxE, MS-Nxxxx-xxT, MS-Nxxxx-xxH and MS-Nxxxx-xxC), due to a weak password reset mechanism at the Milesight NVR web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http… | |
| Modificada | Alta (7.5) | 1.4% | — | Milesight Video Management Systems Firmware | 15/9/2022 | 17/6/2026 | This vulnerability exists in Milesight Video Management Systems (VMS), all firmware versions prior to 40.7.0.79-r1, due to improper input handling at camera’s web-based management interface. A remote attacker could exploit this vulnerability by sending a specially crafted http request on the targeted network camera.… | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a default root password in /etc/shadow that is the same across different customers' installations. | |
| Modificada | Crítica (9.8) | 3.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 allow remote attackers to bypass authentication and access a protected resource by simultaneously making a request for the unprotected vb.htm resource. | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a default set of 10 privileged accounts with hardcoded credentials. They are accessible if the customer has not configured 10 actual user accounts. | |
| Modificada | Crítica (9.8) | 2.1% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a hardcoded SSL private key under the /etc/config directory. | |
| Modificada | Crítica (9.8) | 3.2% | — | Milesight IP Security Camera Firmware | 25/10/2019 | 17/6/2026 | Milesight IP security cameras through 2016-11-14 have a buffer overflow in a web application via a long username or password. |