Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2736▼ 485 respecto a la semana anterior
Críticas / altas1304▼ 186 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5) | 0.14% | — | Motorola Services MainAI | 3/5/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Services Main application that could allow a local attacker to write to a local database. | |
| Aplazada | Alta (7.5) | 0.75% | — | TVS Motor Company Limited TVS ConnetAI | 30/4/2024 | 17/6/2026 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to obtain sensitive information via an insecure API endpoint. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence repository. | |
| Aplazada | Crítica (9.1) | 0.65% | — | TVS Motor Company Limited TVS ConnetAIGoogle AndroidAIApple IOSAI | 30/4/2024 | 17/6/2026 | An issue in TVS Motor Company Limited TVS Connet Android v.4.5.1 and iOS v.5.0.0 allows a remote attacker to escalate privileges via the Emergency Contact Feature. NOTE: this is disputed as discussed in the msn-official/CVE-Evidence repository. | |
| Aplazada | Baja (3.4) | 0.16% | — | BLU View 2AIBoost Mobile Celero 5GAISharp Rouvo VAIMotorola Moto G PureAI+3 | 22/4/2024 | 17/6/2026 | An issue was discovered in a third-party component related to vendor.gsm.serial, shipped on devices from multiple device manufacturers. Various software builds for the BLU View 2, Boost Mobile Celero 5G, Sharp Rouvo V, Motorola Moto G Pure, Motorola Moto G Power, T-Mobile Revvl 6 Pro 5G, and T-Mobile Revvl V+ 5G… | |
| Aplazada | Alta (7.1) | 0.15% | — | TCL A3XAITCL 10LAIMotorola Moto G PureAIMotorola Moto G PowerAI | 22/4/2024 | 17/6/2026 | An issue was discovered in a third-party component related to ro.boot.wifimacaddr, shipped on devices from multiple device manufacturers. Various software builds for the following TCL devices (30Z and 10L) and Motorola devices (Moto G Pure and Moto G Power) leak the Wi-Fi MAC address to a system property that can be… | |
| Aplazada | Media (5) | 0.15% | — | Motorola Carrier ServicesAI | 4/3/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola Carrier Services application that could allow a malicious, local application to read files without authorization. | |
| Aplazada | Media (5.1) | 0.16% | — | Motorola OTA Update ApplicationAI | 4/3/2024 | 17/6/2026 | An improper export vulnerability was reported in the Motorola OTA update application, that could allow a malicious, local application to inject an HTML-based message on screen UI. | |
| Modificada | Media (5.3) | 0.38% | — | Motorola Cx2l Firmware | 12/2/2024 | 17/6/2026 | A hidden interface in Motorola CX2L Router firmware v1.0.1 leaks information regarding the SystemWizardStatus component via sending a crafted request to device_web_ip. | |
| Modificada | Alta (8.8) | 1.5% | — | Motorola Mr2600 Firmware | 26/1/2024 | 17/6/2026 | An arbitrary firmware upload vulnerability exists in the Motorola MR2600. An attacker can exploit this vulnerability to achieve code execution on the device. Authentication is required, however can be bypassed. | |
| Modificada | Alta (7.5) | 1.1% | — | Motorola Mr2600 Firmware | 26/1/2024 | 17/6/2026 | An authentication bypass vulnerability exists in the web component of the Motorola MR2600. An attacker can exploit this vulnerability to access protected URLs and retrieve sensitive information. | |
| Modificada | Alta (8.8) | 3.2% | — | Motorola Mr2600 Firmware | 26/1/2024 | 17/6/2026 | A command injection vulnerability exists in the 'SaveStaticRouteIPv6Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. | |
| Modificada | Alta (8.8) | 3.5% | — | Motorola Mr2600 Firmware | 26/1/2024 | 17/6/2026 | A command injection vulnerability exists in the 'SaveStaticRouteIPv4Params' parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. | |
| Modificada | Alta (8.8) | 3.5% | — | Motorola Mr2600 Firmware | 26/1/2024 | 17/6/2026 | A command injection vulnerability exists in the ‘SaveSysLogParams’ parameter of the Motorola MR2600. A remote attacker can exploit this vulnerability to achieve command execution. Authentication is required, however can be bypassed. | |
| Modificada | Alta (7.5) | 0.51% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 13/11/2023 | 17/6/2026 | Server-Side Request Forgery (SSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing.This issue affects Motors – Car Dealer, Classifieds & Listing: from n/a through 1.4.6. | |
| Modificada | Media (6.1) | 0.33% | — | Stylemixthemes Motors - CAR Dealer, Classifieds & Listing | 27/10/2023 | 17/6/2026 | Unauth. Reflected Cross-Site Scripting (XSS) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.6 versions. | |
| Modificada | Media (6.5) | 0.24% | — | Motorola Mr2600 | 27/10/2023 | 17/6/2026 | A vulnerability has been identified in the MR2600 router v1.0.18 and earlier that could allow an attacker within range of the wireless network to successfully brute force the WPS pin, potentially allowing them unauthorized access to a wireless network. | |
| Modificada | Alta (8.2) | 0.19% | — | Motorola Mtm5500 FirmwareMotorola Mtm5400 Firmware | 19/10/2023 | 17/6/2026 | Motorola MTM5000 series firmwares lack properly configured memory protection of pages shared between the OMAP-L138 ARM and DSP cores. The SoC provides two memory protection units, MPU1 and MPU2, to enforce the trust boundary between the two cores. Since both units are left unconfigured by the firmwares, an adversary… | |
| Modificada | Alta (8.8) | 0.35% | — | Motorola Mtm5500 FirmwareMotorola Mtm5400 Firmware | 19/10/2023 | 17/6/2026 | The Motorola MTM5000 series firmwares generate TETRA authentication challenges using a PRNG using a tick count register as its sole entropy source. Low boottime entropy and limited re-seeding of the pool renders the authentication challenge vulnerable to two attacks. First, due to the limited boottime pool entropy, an… | |
| Modificada | Alta (8.2) | 0.21% | — | Motorola Mtm5500 FirmwareMotorola Mtm5400 Firmware | 19/10/2023 | 17/6/2026 | The Motorola MTM5000 series firmwares lack pointer validation on arguments passed to trusted execution environment (TEE) modules. Two modules are used, one responsible for KVL key management and the other for TETRA cryptographic functionality. In both modules, an adversary with non-secure supervisor level code… | |
| Modificada | Alta (8.8) | 0.36% | — | Motorola Mtm5500 FirmwareMotorola Mtm5400 Firmware | 19/10/2023 | 17/6/2026 | A format string vulnerability exists in Motorola MTM5000 series firmware AT command handler for the AT+CTGL command. An attacker-controllable string is improperly handled, allowing for a write-anything-anywhere scenario. This can be leveraged to obtain arbitrary code execution inside the teds_app binary, which runs… | |
| Modificada | Media (6.1) | 0.31% | — | Oretnom23 Online Motorcycle (bike) Rental System | 15/10/2023 | 17/6/2026 | A vulnerability was found in SourceCodester Online Motorcycle Rental System 1.0. It has been declared as problematic. This vulnerability affects unknown code of the file /admin/?page=bike of the component Bike List. The manipulation of the argument Model with the input "><script>confirm (document.cookie)</script>… | |
| Modificada | Media (4.3) | 0.24% | — | Motorola Smartphone Firmware | 1/9/2023 | 17/6/2026 | I some cases, when the device is USB-tethered to a host PC, and the device is sharing its mobile network connection with the host PC, if the user originates a call on the device, then the device's modem may reset and cause the phone call to not succeed. This may block the user from dialing emergency services. This… | |
| Modificada | Alta (8.4) | 0.21% | — | Motorola Ebts Site Controller FirmwareMotorola Mbts Site Controller Firmware | 29/8/2023 | 17/6/2026 | Motorola EBTS/MBTS Site Controller drops to debug prompt on unhandled exception. The Motorola MBTS Site Controller exposes a debug prompt on the device's serial port in case of an unhandled exception. This allows an attacker with physical access that is able to trigger such an exception to extract secret key material… | |
| Modificada | Alta (8.8) | 0.46% | — | Motorola Ebts Base Radio FirmwareMotorola Mbts Base Radio Firmware | 29/8/2023 | 17/6/2026 | Motorola EBTS/MBTS Base Radio fails to check firmware authenticity. The Motorola MBTS Base Radio lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the device. | |
| Modificada | Alta (8.8) | 0.46% | — | Motorola Mbts Site Controller Firmware | 29/8/2023 | 17/6/2026 | Motorola MBTS Site Controller fails to check firmware update authenticity. The Motorola MBTS Site Controller lacks cryptographic signature validation for firmware update packages, allowing an authenticated attacker to gain arbitrary code execution, extract secret key material, and/or leave a persistent implant on the… |