Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2722▼ 518 respecto a la semana anterior
Críticas / altas1296▼ 206 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)226▼ 276 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.4)0.18%—Motorola Mbts Base Radio Firmware29/8/202317/6/2026
Motorola MBTS Base Radio accepts hard-coded backdoor password. The Motorola MBTS Base Radio Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.
ModificadaCrítica (9.8)0.54%—Motorola Mbts Site Controller Firmware29/8/202317/6/2026
Motorola MBTS Site Controller accepts hard-coded backdoor password. The Motorola MBTS Site Controller Man Machine Interface (MMI), allowing for service technicians to diagnose and configure the device, accepts a hard-coded backdoor password that cannot be changed or disabled.
ModificadaAlta (8.8)0.25%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing25/5/202317/6/2026
Cross-Site Request Forgery (CSRF) vulnerability in StylemixThemes Motors – Car Dealer, Classifieds & Listing plugin <= 1.4.4 versions.
ModificadaAlta (8.8)2.2%—Motorola Cx2l Firmware11/5/202317/6/2026
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the tomography_ping_number parameter.
ModificadaAlta (8.8)2.4%—Motorola Cx2l Firmware11/5/202317/6/2026
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the smartqos_priority_devices parameter.
ModificadaAlta (8.8)2.2%—Motorola Cx2l Firmware11/5/202317/6/2026
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the system_time_timezone parameter.
ModificadaAlta (8.8)2.2%—Motorola Cx2l Firmware11/5/202317/6/2026
Motorola CX2L Router 1.0.1 was discovered to contain a command injection vulnerability via the staticroute_list parameter.
ModificadaMedia (4.8)0.37%—Motor Racing League Project Motor Racing League23/4/202317/6/2026
Auth. (admin+) Cross-Site Scripting (XSS) vulnerability in Ian Haycox Motor Racing League plugin <= 1.9.9 versions.
ModificadaMedia (6.7)0.49%—Motorola Mr2600 Firmware30/1/202317/6/2026
An improper input sanitization vulnerability in the Motorola MR2600 router could allow a local user with elevated permissions to execute arbitrary code.
ModificadaMedia (5.5)0.18%—Motorola Moto E20 Firmware14/12/202217/6/2026
Improper access control of bootloader function was discovered in Motorola Mobility Motorola e20 prior to version RONS31.267-38-8 allows attacker with local access to read partition or RAM data.
ModificadaAlta (8.8)1.1%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing12/12/202217/6/2026
The Motors WordPress plugin before 1.4.4 does not properly validate uploaded files for dangerous file types (such as .php) in an AJAX action, allowing an attacker to sign up on a victim's WordPress instance, upload a malicious PHP file and attempt to launch a brute-force attack to discover the uploaded payload.
ModificadaCrítica (9.8)1.1%—Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+951/12/202217/6/2026
In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability.
ModificadaAlta (7.5)0.82%—Motorola Moscad IP Gateway FirmwareMotorola ACE IP Gateway (4600) Firmware26/7/202217/6/2026
The Motorola MOSCAD and ACE line of RTUs through 2022-05-02 omit an authentication requirement. They feature IP Gateway modules which allow for interfacing between Motorola Data Link Communication (MDLC) networks (potentially over a variety of serial, RF and/or Ethernet links) and TCP/IP networks. Communication with…
ModificadaCrítica (9.8)0.64%—Motorola Ace1000 Firmware26/7/202217/6/2026
The Motorola ACE1000 RTU through 2022-05-02 uses ECB encryption unsafely. It can communicate with an XRT LAN-to-radio gateway by means of an embedded client. Credentials for accessing this gateway are stored after being encrypted with the Tiny Encryption Algorithm (TEA) in ECB mode using a hardcoded key. Similarly,…
ModificadaAlta (7.2)0.45%—Motorola Ace1000 Firmware26/7/202217/6/2026
The Motorola ACE1000 RTU through 2022-05-02 mishandles firmware integrity. It utilizes either the STS software suite or ACE1000 Easy Configurator for performing firmware updates. In case of the Easy Configurator, firmware updates are performed through access to the Web UI where file system, kernel, package, bundle, or…
ModificadaCrítica (9.8)1.0%—Motorola Ace1000 Firmware26/7/202217/6/2026
The Motorola ACE1000 RTU through 2022-05-02 ships with a hardcoded SSH private key and initialization scripts (such as /etc/init.d/sshd_service) only generate a new key if no private-key file exists. Thus, this hardcoded key is likely to be used by default.
ModificadaCrítica (9.8)0.90%—Motorola Ace1000 Firmware26/7/202217/6/2026
The Motorola ACE1000 RTU through 2022-05-02 has default credentials. It exposes an SSH interface on port 22/TCP. This interface is used for remote maintenance and for SFTP file-transfer operations that are part of engineering software functionality. Access to this interface is controlled by 5 preconfigured accounts…
ModificadaAlta (8.8)0.46%—Motorola Ace1000 Firmware26/7/202217/6/2026
Motorola ACE1000 RTUs through 2022-05-02 mishandle application integrity. They allow for custom application installation via either STS software, the C toolkit, or the ACE1000 Easy Configurator. In the case of the Easy Configurator, application images (as PLX/DAT/APP/CRC files) are uploaded via the Web UI. In case of…
ModificadaAlta (7.5)0.59%—Motorolasolutions Mdlc26/7/202217/6/2026
The Motorola MOSCAD Toolbox software through 2022-05-02 relies on a cleartext password. It utilizes an MDLC driver to communicate with MOSCAD/ACE RTUs for engineering purposes. Access to these communications is protected by a password stored in cleartext in the wmdlcdrv.ini driver configuration file. In addition, this…
ModificadaCrítica (9.8)0.43%—Motorolasolutions Mdlc26/7/202217/6/2026
The Motorola MDLC protocol through 2022-05-02 mishandles message integrity. It supports three security modes: Plain, Legacy Encryption, and New Encryption. In Legacy Encryption mode, traffic is encrypted via the Tiny Encryption Algorithm (TEA) block-cipher in ECB mode. This mode of operation does not offer message…
ModificadaMedia (6.8)1.4%—Getmotoradmin Motor Admin22/6/202217/6/2026
In motor-admin versions 0.0.1 through 0.2.56 are vulnerable to host header injection in the password reset functionality where malicious actor can send fake password reset email to arbitrary victim.
ModificadaCrítica (9.8)0.85%—Mitsubishielectric CPU Module Logging Configuration ToolMitsubishielectric CW ConfiguratorMitsubishielectric Data TransferMitsubishielectric EM Configurator+2519/5/202217/6/2026
Successful exploitation of this vulnerability for multiple Mitsubishi Electric Factory Automation Engineering Software Products of various versions could allow an attacker to escalate privilege and execute malicious programs, which could cause a denial-of-service condition, and allow information to be disclosed,…
ModificadaMedia (6.5)0.46%—Motorola Device HelpMotorola Ready FOR22/4/202217/6/2026
Versions of Motorola Ready For and Motorola Device Help Android applications prior to 2021-04-08 do not properly verify the server certificate which could lead to the communication channel being accessible by an attacker.
ModificadaCrítica (9.8)1.3%—Mitsubishielectric C Controller Interface Module UtilityMitsubishielectric C Controller Module Setting AND Monitoring ToolMitsubishielectric Cc-link IE Control Network Data CollectorMitsubishielectric Cc-link IE Field Network Data Collector+4211/2/202217/6/2026
Multiple Mitsubishi Electric Factory Automation engineering software products have a malicious code execution vulnerability. A malicious attacker could use this vulnerability to obtain information, modify information, and cause a denial-of-service condition.
ModificadaCrítica (9.8)1.8%—Online Motorcycle (bike) Rental System Project Online Motorcycle (bike) Rental System28/1/202217/6/2026
Online Motorcycle (Bike) Rental System 1.0 is vulnerable to a Blind Time-Based SQL Injection attack within the login portal. This can lead attackers to remotely dump MySQL database credentials.
Orbitaley — Vulnerabilidades