Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2768▼ 546 respecto a la semana anterior
Críticas / altas1325▼ 174 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)268▼ 241 respecto a la semana anterior
–

138 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.35%—Bosch Video Client25/3/202117/6/2026
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Client installer up to and including version 1.7.6.079 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same directory where the…
ModificadaAlta (7.8)0.35%—Bosch Video Recording Manager25/3/202117/6/2026
Loading a DLL through an Uncontrolled Search Path Element in the Bosch Video Recording Manager installer up to and including version 3.82.0055 for 3.82, up to and including version 3.81.0064 for 3.81 and 3.71 and older potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is…
ModificadaAlta (7.8)0.33%—Bosch Video Management SystemBosch Video Management System Viewer25/3/202117/6/2026
Loading a DLL through an Uncontrolled Search Path Element in Bosch BVMS and BVMS Viewer in versions 10.1.0, 10.0.1, 10.0.0 and 9.0.0 and older potentially allows an attacker to execute arbitrary code on a victim's system. This affects both the installer as well as the installed application. This also affects Bosch…
ModificadaAlta (7.8)0.35%—Bosch IP Helper25/3/202117/6/2026
Loading a DLL through an Uncontrolled Search Path Element in Bosch IP Helper up to and including version 1.00.0008 potentially allows an attacker to execute arbitrary code on a victim's system. A prerequisite is that the victim is tricked into placing a malicious DLL in the same application directory as the portable…
ModificadaCrítica (9.8)0.98%—Bosch Video Recording ManagerBosch Divar IP 5000 FirmwareBosch Video Management System26/2/202117/6/2026
Improper Access Control in the RCP+ server of the Bosch Video Recording Manager (VRM) component allows arbitrary and unauthenticated access to a limited subset of certificates, stored in the underlying Microsoft Windows operating system. The fixed versions implement modified authentication checks. Prior releases of…
ModificadaMedia (4.9)0.56%—Bosch Fsm-2500 FirmwareBosch Fsm-5000 Firmware26/1/202117/6/2026
Use of Password Hash With Insufficient Computational Effort in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows a remote attacker with admin privileges to dump the credentials of other users and possibly recover their plain-text passwords by brute-forcing the MD5…
ModificadaCrítica (10)3.7%—Bosch Fsm-2500 FirmwareBosch Fsm-5000 Firmware26/1/202117/6/2026
Use of Hard-coded Credentials in the database of Bosch FSM-2500 server and Bosch FSM-5000 server up to and including version 5.2 allows an unauthenticated remote attacker to log into the database with admin-privileges. This may result in complete compromise of the confidentiality and integrity of the stored data as…
ModificadaMedia (4.8)0.61%—Bosch Praesideo FirmwareBosch Praesensa Firmware14/1/202117/6/2026
A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an authenticated remote attacker with admin privileges to mount a stored Cross-Site-Scripting (XSS) attack against another user. When the victim logs…
ModificadaAlta (8.8)0.55%—Bosch Praesideo FirmwareBosch Praesensa Firmware14/1/202117/6/2026
A vulnerability in the web-based management interface of Bosch PRAESIDEO until and including version 4.41 and Bosch PRAESENSA until and including version 1.10 allows an unauthenticated remote attacker to trigger actions on an affected system on behalf of another user (Cross-Site Request Forgery). This requires the…
ModificadaAlta (7.4)0.45%—Bosch Smart Home16/9/202017/6/2026
Improper certificate validation for certain connections in the Bosch Smart Home System App for iOS prior to version 9.17.1 potentially allows to intercept video contents by performing a man-in-the-middle attack.
ModificadaAlta (8.8)0.28%—Bosch Recording Station Firmware27/5/202017/6/2026
Improper Access Control in the Kiosk Mode functionality of Bosch Recording Station allows a local unauthenticated attacker to escape from the Kiosk Mode and access the underlying operating system.
ModificadaCrítica (9.8)5.3%💥 ExploitBoschsecurity Nbn-498 Dinion2x Day/night IP Cameras Firmware18/2/202017/6/2026
The web interface in Bosch Security Systems NBN-498 Dinion2X Day/Night IP Cameras with H.264 Firmware 4.54.0026 allows remote attackers to conduct XML injection attacks via the idstring parameter to rcp.xml.
ModificadaCrítica (9.8)3.6%—Bosch Video Management System Mobile Video ServiceBosch Divar IP 3000 FirmwareBosch Divar IP 7000 Firmware7/2/202017/6/2026
Deserialization of Untrusted Data in the BVMS Mobile Video Service (BVMS MVS) allows an unauthenticated remote attacker to execute arbitrary code on the system. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.0.329 and 7.5 and older. This affects Bosch DIVAR IP 3000 and DIVAR IP 7000…
ModificadaAlta (7.5)1.7%—Bosch Video Management System ViewerBosch Video Management System7/2/202017/6/2026
A path traversal vulnerability in the Bosch Video Management System (BVMS) NoTouch deployment allows an unauthenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS…
ModificadaCrítica (9.1)2.2%—Bosch Video Streaming GatewayBosch Divar IP 2000 FirmwareBosch Divar IP 5000 Firmware7/2/202017/6/2026
Missing Authentication for Critical Function in the Bosch Video Streaming Gateway (VSG) allows an unauthenticated remote attacker to retrieve and set arbitrary configuration data of the Video Streaming Gateway. A successful attack can impact the confidentiality and availability of live and recorded video data of all…
ModificadaMedia (6.5)1.3%—Bosch Video Management System ViewerBosch Video Management System6/2/202017/6/2026
A path traversal vulnerability in the Bosch Video Management System (BVMS) FileTransferService allows an authenticated remote attacker to read arbitrary files from the Central Server. This affects Bosch BVMS versions 10.0 <= 10.0.0.1225, 9.0 <= 9.0.0.827, 8.0 <= 8.0.329 and 7.5 and older. This affects Bosch BVMS…
ModificadaAlta (7.5)1.1%—Bosch Access12/9/201917/6/2026
An unauthenticated attacker can achieve unauthorized access to sensitive data by exploiting Windows SMB protocol on a client installation. With Bosch Access Professional Edition (APE) 3.8, client installations need to be authorized by the APE administrator.
ModificadaCrítica (9.9)1.1%—Bosch Access12/9/201917/6/2026
Unauthorized APE administration privileges can be achieved by reverse engineering one of the APE service tools. The service tool is discontinued with Bosch Access Professional Edition (APE) 3.8.
ModificadaAlta (7.5)2.4%—Bosch IOT Gateway SoftwareBosch Prosyst MBS SDK21/8/201917/6/2026
A HTTP Traversal Attack in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.0.2 allows remote attackers to read files outside the http root.
ModificadaMedia (5.3)1.1%—Bosch IOT Gateway SoftwareBosch Prosyst MBS SDK21/8/201917/6/2026
Leakage of stack traces in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to gather information about the file system structure.
ModificadaAlta (7.5)2.7%—Bosch IOT Gateway SoftwareBosch Prosyst MBS SDK21/8/201917/6/2026
A directory traversal vulnerability in remote access to backup & restore in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.2.0 allows remote attackers to write or delete files at any location.
ModificadaAlta (8.6)1.8%—Bosch IOT Gateway SoftwareBosch Prosyst MBS SDK21/8/201917/6/2026
A Server-Side Request Forgery (SSRF) vulnerability in the backup & restore functionality in earlier versions than ProSyst mBS SDK 8.2.6 and Bosch IoT Gateway Software 9.3.0 allows a remote attacker to forge GET requests to arbitrary URLs. In addition, this could potentially allow an attacker to read sensitive zip…
ModificadaAlta (7.1)0.67%—Bosch Smart Home Controller Firmware29/5/201917/6/2026
A potential incorrect privilege assignment vulnerability exists in the 3rd party pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.907 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an…
ModificadaMedia (5.3)0.98%—Bosch Smart Home Controller Firmware29/5/201917/6/2026
A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a successful denial of service of the SHC and connected sensors and actuators. In order to exploit the vulnerability, the adversary needs to have successfully…
ModificadaMedia (5.7)0.50%—Bosch Smart Home Controller Firmware29/5/201917/6/2026
A potential improper access control vulnerability exists in the backup mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in unauthorized download of a backup. In order to exploit the vulnerability, the adversary needs to download the backup directly after a backup triggered by a…
Orbitaley — Vulnerabilidades