Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3026▼ 51 respecto a la semana anterior
Críticas / altas1414▲ 60 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)381▼ 129 respecto a la semana anterior
121 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.4% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Crítica (9.8) | 1.6% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | Several stack-based buffer overflow vulnerabilities exist in the DetranCLI command parsing functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network packet can lead to arbitrary command execution. An attacker can send a sequence of requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (8.8) | 5.8% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | An os command injection vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.1) | 2.6% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | A directory traversal vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file deletion. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Crítica (9.8) | 4.3% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | An OS command injection vulnerability exists in the m2m DELETE_FILE cmd functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 4.1% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | An OS command injection vulnerability exists in the httpd txt/restore.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted network request can lead to arbitrary command execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.7% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | A file write vulnerability exists in the httpd upload.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file upload. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.7% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | A leftover debug code vulnerability exists in the httpd shell.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.9% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Media (6.5) | 2.3% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | A directory traversal vulnerability exists in the httpd downfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to arbitrary file read. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 7.1% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | An OS command injection vulnerability exists in the httpd SNMP functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP response can lead to arbitrary command execution. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Alta (8.8) | 3.2% | — | Siretta Quartz-gold Firmware | 26/1/2023 | 17/6/2026 | A stack-based buffer overflow vulnerability exists in the httpd delfile.cgi functionality of Siretta QUARTZ-GOLD G5.0.1.5-210720-141020. A specially-crafted HTTP request can lead to remote code execution. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 0.64% | — | Intel Quartus Prime | 11/11/2022 | 17/6/2026 | XML injection in the Quartus(R) Prime Programmer included in the Intel(R) Quartus Prime Pro and Standard edition software may allow an unauthenticated user to potentially enable information disclosure via network access. | |
| Modificada | Alta (7.8) | 0.17% | — | Intel Quartus Prime | 11/11/2022 | 17/6/2026 | Uncontrolled search path element in the Intel(R) Quartus Prime Standard edition software before version 21.1 Patch 0.02std may allow an authenticated user to potentially enable escalation of privilege via local access. | |
| Modificada | Crítica (9.8) | 1.6% | — | Simple Student Quarterly Result/grade System Project Simple Student Quarterly Result/grade System | 20/5/2022 | 17/6/2026 | Simple Student Quarterly Result/Grade System v1.0 was discovered to contain a SQL injection vulnerability via /sqgs/Actions.php. | |
| Modificada | Alta (7.8) | 0.24% | — | Intel Quartus Prime | 9/2/2022 | 17/6/2026 | Improper restriction of XML external entity for Intel(R) Quartus(R) Prime Pro Edition before version 21.3 may allow an authenticated user to potentially enable escalation of privilege via local access. |