Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
196 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.8) | 0.60% | — | Fortinet Forticlient Emergency Management Server | 15/3/2020 | 17/6/2026 | An Unsafe Search Path vulnerability in FortiClient EMS online installer 6.2.1 and below may allow a local attacker with control over the directory in which FortiClientEMSOnlineInstaller.exe resides to execute arbitrary code on the system via uploading malicious Filter Library DLL files in that directory. | |
| Modificada | Media (5.3) | 0.98% | — | Ready Wireless Emergency Alerts | 2/11/2019 | 17/6/2026 | The Wireless Emergency Alerts (WEA) protocol allows remote attackers to spoof a Presidential Alert because cryptographic authentication is not used, as demonstrated by MessageIdentifier 4370 in LTE System Information Block 12 (aka SIB12). NOTE: testing inside an RF-isolated shield box suggested that all LTE phones are… | |
| Modificada | Alta (7.5) | 1.5% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 5/9/2019 | 17/6/2026 | IBM Intelligent Operations Center V5.1.0 - V5.2.0, IBM Intelligent Operations Center for Emergency Management V5.1.0 - V5.1.0.6, and IBM Water Operations for Waternamics V5.1.0 - V5.2.1.1 does not require that users should have strong passwords by default, which makes it easier for attackers to compromise user… | |
| Modificada | Media (6.2) | 0.39% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 20/8/2019 | 17/6/2026 | IBM Intelligent Operations Center V5.1.0 through V5.2.0 could disclose detailed error messages, revealing sensitive information that could aid in further attacks against the system. IBM X-Force ID: 162738. | |
| Modificada | Alta (8.2) | 2.4% | — | IBM Intelligent Operations CenterIBM Intelligent Operations Center FOR Emergency ManagementIBM Water Operations FOR Waternamics | 20/8/2019 | 17/6/2026 | IBM Intelligent Operations Center V5.1.0 through V5.2.0 is vulnerable to an XML External Entity Injection (XXE) attack when processing XML data. A remote attacker could exploit this vulnerability to expose sensitive information or consume memory resources. IBM X-Force ID: 162737. | |
| Modificada | Alta (8.8) | 20% | — | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow Privilege Escalation. | |
| Modificada | Crítica (10) | 70% | 💥 Exploit | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow Unrestricted File Upload. | |
| Analizada | Crítica (9.8) | 97% | ⚠ Explotación activa💥 Exploit | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow Command Injections. | |
| Modificada | Media (6.1) | 56% | 💥 Exploit | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow XSS. | |
| Modificada | Alta (7.5) | 82% | 💥 Exploit | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow File Inclusion. | |
| Modificada | Crítica (9.8) | 3.0% | — | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow Directory Traversal. | |
| Modificada | Crítica (9.8) | 4.9% | — | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices have Default Credentials. | |
| Modificada | Alta (8.8) | 16% | 💥 Exploit | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow Cross-Site Request Forgery (CSRF). | |
| Modificada | Crítica (9.8) | 5.5% | — | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices have Hard-coded Credentials. | |
| Modificada | Crítica (9.8) | 6.6% | — | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices have Cleartext Credentials in a Database. | |
| Modificada | Alta (8.8) | 13% | — | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow Authorization Bypass with Information Disclosure. | |
| Modificada | Alta (8.8) | 1.1% | — | Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF). | |
| Modificada | Crítica (9.8) | 40% | 💥 Exploit | Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution. | |
| Modificada | Crítica (10) | 6.5% | — | Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge 50P/5000P devices allow Unauthenticated File Upload. | |
| Modificada | Crítica (9.8) | 21% | — | Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge 50P/5000P devices allow Cookie Path Traversal. | |
| Modificada | Crítica (9.8) | 4.6% | — | Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge 50P/5000P devices allow Authentication Bypass. | |
| Modificada | Crítica (9.8) | 23% | 💥 Exploit | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow Remote Code Execution (root access over SSH). | |
| Modificada | Crítica (9.8) | 2.2% | — | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices allow a Stack-based Buffer Overflow on the ARM platform. | |
| Modificada | Crítica (9.8) | 1.8% | — | Nortekcontrol Linear Emerge Essential FirmwareNortekcontrol Linear Emerge Elite Firmware | 2/7/2019 | 17/6/2026 | Linear eMerge E3-Series devices have a Version Control Failure. | |
| Modificada | Crítica (9.8) | 3.6% | — | Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware | 1/7/2019 | 17/6/2026 | Nortek Linear eMerge 50P/5000P devices have Default Credentials. |