Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

196 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.60%—Fortinet Forticlient Emergency Management Server15/3/202017/6/2026
An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory.
ModificadaMedia (5.3)0.98%—Ready Wireless Emergency Alerts2/11/201917/6/2026
The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are…
ModificadaAlta (7.5)1.5%—IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics5/9/201917/6/2026
IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operations for Waternamics V5.1.0 - V5.2.1.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user…
ModificadaMedia (6.2)0.39%—IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics20/8/201917/6/2026
IBM Intelligent Operations Center V5.1.0 through V5.2.0 could disclose detailed error messages, revealing sensitive information that could aid in further attacks against the system. IBM X-Force ID: 162738.
ModificadaAlta (8.2)2.4%—IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics20/8/201917/6/2026
IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162737.
ModificadaAlta (8.8)20%—Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow Privilege Escalation.
ModificadaCrítica (10)70%💥 ExploitNortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow Unrestricted File Upload.
AnalizadaCrítica (9.8)97%⚠ Explotación activa💥 ExploitNortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow Command Injections.
ModificadaMedia (6.1)56%💥 ExploitNortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow XSS.
ModificadaAlta (7.5)82%💥 ExploitNortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow File Inclusion.
ModificadaCrítica (9.8)3.0%—Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow Directory Traversal.
ModificadaCrítica (9.8)4.9%—Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices have Default Credentials.
ModificadaAlta (8.8)16%💥 ExploitNortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF).
ModificadaCrítica (9.8)5.5%—Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices have Hard-coded Credentials.
ModificadaCrítica (9.8)6.6%—Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices have Cleartext Credentials in a Database.
ModificadaAlta (8.8)13%—Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure.
ModificadaAlta (8.8)1.1%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
ModificadaCrítica (9.8)40%💥 ExploitNortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
ModificadaCrítica (10)6.5%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
ModificadaCrítica (9.8)21%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Cookie Path Traversal.
ModificadaCrítica (9.8)4.6%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Authentication Bypass.
ModificadaCrítica (9.8)23%💥 ExploitNortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH).
ModificadaCrítica (9.8)2.2%—Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform.
ModificadaCrítica (9.8)1.8%—Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware2/7/201917/6/2026
Linear eMerge E3-Series devices have a Version Control Failure.
ModificadaCrítica (9.8)3.6%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware1/7/201917/6/2026
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
Orbitaley — Vulnerabilidades