Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
168 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8.8) | 0.87% | — | Nokia 1350 Optical Management System | 13/9/2022 | 17/6/2026 | In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database. | |
| Modificada | Media (6.5) | 0.63% | — | Nokia 1350 Optical Management System | 13/9/2022 | 17/6/2026 | In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker. | |
| Modificada | Crítica (9.8) | 2.2% | — | Nokia 1350 Optical Management System | 13/9/2022 | 17/6/2026 | In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system. | |
| Modificada | Media (6.1) | 0.45% | — | Nokia 1350 Optical Management System | 13/9/2022 | 17/6/2026 | In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter. | |
| Modificada | Crítica (9.8) | 1.8% | — | Nokia Vitalsuite | 16/6/2022 | 17/6/2026 | NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'. | |
| Modificada | Media (4.8) | 0.56% | — | Nokia G-2425g-a Firmware | 14/6/2022 | 17/6/2026 | Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management. | |
| Modificada | Media (6.5) | 1.0% | — | Nokia Broadcast Message Center | 25/5/2022 | 17/6/2026 | Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and… | |
| Modificada | Crítica (9.8) | 22% | — | Nokia BTS TRS WEB Console | 11/2/2022 | 17/6/2026 | Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character. | |
| Modificada | Alta (8.8) | 1.6% | — | Nokia Fastmile Firmware | 27/12/2021 | 17/6/2026 | Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File. | |
| Modificada | Media (5.5) | 0.64% | — | Nokia Heif | 20/9/2021 | 17/6/2026 | An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in nalutil.cpp. It allows an attacker to cause Denial of Service. | |
| Modificada | Alta (7.8) | 1.1% | — | Nokia Heif | 20/9/2021 | 17/6/2026 | An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution. | |
| Modificada | Alta (7.8) | 1.1% | — | Nokia Heif | 20/9/2021 | 17/6/2026 | An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution. | |
| Modificada | Media (4.8) | 0.61% | — | Nokia G-120w-f Firmware | 2/4/2021 | 17/6/2026 | An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address. | |
| Modificada | Media (6.5) | 1.4% | — | Nokia Netact | 25/3/2021 | 17/6/2026 | An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value. | |
| Modificada | Media (5.4) | 0.74% | — | Nokia Netact | 25/3/2021 | 17/6/2026 | An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or… | |
| Modificada | Media (6.1) | 0.91% | — | Nokia 1830 Photonic Service Switch-4 FirmwareNokia 1830 Photonic Service Switch-16 FirmwareNokia 1830 Photonic Service Switch-32 Firmware | 31/1/2020 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html. | |
| Modificada | Media (5.3) | 1.1% | — | Nokia Impact | 25/11/2019 | 17/6/2026 | Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743 | |
| Modificada | Media (6.1) | 0.71% | — | Nokia Impact | 25/11/2019 | 17/6/2026 | Nokia IMPACT < 18A: has Reflected self XSS | |
| Modificada | Media (4.3) | 0.97% | — | Nokia Impact | 25/11/2019 | 17/6/2026 | Nokia IMPACT < 18A: allows full path disclosure | |
| Modificada | Alta (8.8) | 2.5% | — | Nokia Impact | 25/11/2019 | 17/6/2026 | Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution. | |
| Modificada | Media (6.5) | 3.7% | — | Kaiostech KaiosNokia 8810 4G Firmware | 21/3/2019 | 17/6/2026 | A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code execution on the device. | |
| Modificada | Crítica (9.8) | 5.2% | — | Nokia I-240w-q Gpon ONT Firmware | 5/3/2019 | 17/6/2026 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, unauthenticated attacker to /GponForm/fsetup_Form. An attacker can leverage this vulnerability to potentially execute arbitrary code. | |
| Modificada | Alta (8.8) | 18% | 💥 Exploit | Nokia I-240w-q Gpon ONT Firmware | 5/3/2019 | 17/6/2026 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated attacker to /GponForm/usb_Form?script/. An attacker can leverage this vulnerability to potentially execute arbitrary code. | |
| Modificada | Alta (8.8) | 3.9% | — | Nokia I-240w-q Gpon ONT Firmware | 5/3/2019 | 17/6/2026 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/device_Form?script/. | |
| Modificada | Alta (8.8) | 3.9% | — | Nokia I-240w-q Gpon ONT Firmware | 5/3/2019 | 17/6/2026 | The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/usb_restore_Form?script/. |