Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2703▼ 615 respecto a la semana anterior
Críticas / altas1293▼ 208 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)291▼ 219 respecto a la semana anterior
–

168 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)0.87%—Nokia 1350 Optical Management System13/9/202217/6/2026
In NOKIA 1350 OMS R14.2, multiple SQL Injection vulnerabilities occurs. Exploitation requires an authenticated attacker. Through the injection of arbitrary SQL statements, a potential authenticated attacker can modify query syntax and perform unauthorized (and unexpected) operations against the remote database.
ModificadaMedia (6.5)0.63%—Nokia 1350 Optical Management System13/9/202217/6/2026
In NOKIA 1350 OMS R14.2, Insufficiently Protected Credentials (cleartext administrator password) occur in the edit configuration page. Exploitation requires an authenticated attacker.
ModificadaCrítica (9.8)2.2%—Nokia 1350 Optical Management System13/9/202217/6/2026
In NOKIA 1350 OMS R14.2, multiple OS Command Injection vulnerabilities occurs. This vulnerability allow unauthenticated users to execute commands on the operating system.
ModificadaMedia (6.1)0.45%—Nokia 1350 Optical Management System13/9/202217/6/2026
In NOKIA 1350 OMS R14.2, an Open Redirect vulnerability occurs is the login page via next HTTP GET parameter.
ModificadaCrítica (9.8)1.8%—Nokia Vitalsuite16/6/202217/6/2026
NOKIA VitalSuite SPM 2020 is affected by SQL injection through UserName'.
ModificadaMedia (4.8)0.56%—Nokia G-2425g-a Firmware14/6/202217/6/2026
Nokia "G-2425G-A" Bharti Airtel Routers Hardware version "3FE48299DEAA" Software Version "3FE49362IJHK42" is vulnerable to Cross-Site Scripting (XSS) via the admin->Maintenance>Device Management.
ModificadaMedia (6.5)1.0%—Nokia Broadcast Message Center25/5/202217/6/2026
Nokia Broadcast Message Center through 11.1.0 allows an authenticated user to perform a Boolean Blind SQL Injection attack on the endpoint /owui/block/send-receive-updates (for the Manage Alerts page) via the extIdentifier HTTP POST parameter. This allows an attacker to obtain the database user, database name, and…
ModificadaCrítica (9.8)22%—Nokia BTS TRS WEB Console11/2/202217/6/2026
Nokia BTS TRS web console FTM_W20_FP2_2019.08.16_0010 allows Authentication Bypass. A malicious unauthenticated user can get access to all the functionalities exposed via the web panel, circumventing the authentication process, by using URL encoding for the . (dot) character.
ModificadaAlta (8.8)1.6%—Nokia Fastmile Firmware27/12/202117/6/2026
Nokia FastMile 3TG00118ABAD52 devices allow privilege escalation by an authenticated user via is_ctc_admin=1 to login_web_app.cgi and use of Import Config File.
ModificadaMedia (5.5)0.64%—Nokia Heif20/9/202117/6/2026
An issue was discovered in heif through through v3.6.2. A NULL pointer dereference exists in the function convertByteStreamToRBSP() located in nalutil.cpp. It allows an attacker to cause Denial of Service.
ModificadaAlta (7.8)1.1%—Nokia Heif20/9/202117/6/2026
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicHeight() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
ModificadaAlta (7.8)1.1%—Nokia Heif20/9/202117/6/2026
An issue was discovered in heif through v3.6.2. A global-buffer-overflow exists in the function HevcDecoderConfigurationRecord::getPicWidth() located in hevcdecoderconfigrecord.cpp. It allows an attacker to cause code Execution.
ModificadaMedia (4.8)0.61%—Nokia G-120w-f Firmware2/4/202117/6/2026
An issue was discovered on Nokia G-120W-F 3FE46606AGAB91 devices. There is Stored XSS in the administrative interface via urlfilter.cgi?add url_address.
ModificadaMedia (6.5)1.4%—Nokia Netact25/3/202117/6/2026
An issue was discovered in Nokia NetAct 18A. A remote user, authenticated to the NOKIA NetAct Web Page, can visit the Site Configuration Tool web site section and arbitrarily upload potentially dangerous files without restrictions via the /netact/sct dir parameter in conjunction with the operation=upload value.
ModificadaMedia (5.4)0.74%—Nokia Netact25/3/202117/6/2026
An issue was discovered in Nokia NetAct 18A. A malicious user can change a filename of an uploaded file to include JavaScript code, which is then stored and executed by a victim's web browser. The most common mechanism for delivering malicious content is to include it as a parameter in a URL that is posted publicly or…
ModificadaMedia (6.1)0.91%—Nokia 1830 Photonic Service Switch-4 FirmwareNokia 1830 Photonic Service Switch-16 FirmwareNokia 1830 Photonic Service Switch-32 Firmware31/1/202017/6/2026
Cross-site scripting (XSS) vulnerability in the management interface in Alcatel-Lucent 1830 Photonic Service Switch (PSS) 6.0 and earlier allows remote attackers to inject arbitrary web script or HTML via the myurl parameter to menu/pop.html.
ModificadaMedia (5.3)1.1%—Nokia Impact25/11/201917/6/2026
Nokia IMPACT < 18A has path traversal that may lead to RCE if chained with CVE-2019-1743
ModificadaMedia (6.1)0.71%—Nokia Impact25/11/201917/6/2026
Nokia IMPACT < 18A: has Reflected self XSS
ModificadaMedia (4.3)0.97%—Nokia Impact25/11/201917/6/2026
Nokia IMPACT < 18A: allows full path disclosure
ModificadaAlta (8.8)2.5%—Nokia Impact25/11/201917/6/2026
Nokia IMPACT < 18A: An unrestricted File Upload vulnerability was found that may lead to Remote Code Execution.
ModificadaMedia (6.5)3.7%—Kaiostech KaiosNokia 8810 4G Firmware21/3/201917/6/2026
A Denial of Service issue has been discovered in the Gecko component of KaiOS 2.5 10.05 (platform 48.0.a2) on Nokia 8810 4G devices. When a crafted web page is visited with the internal browser, the Gecko process crashes with a segfault. Successful exploitation could lead to the remote code execution on the device.
ModificadaCrítica (9.8)5.2%—Nokia I-240w-q Gpon ONT Firmware5/3/201917/6/2026
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, unauthenticated attacker to /GponForm/fsetup_Form. An attacker can leverage this vulnerability to potentially execute arbitrary code.
ModificadaAlta (8.8)18%💥 ExploitNokia I-240w-q Gpon ONT Firmware5/3/201917/6/2026
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to a stack buffer overflow via crafted HTTP POST request sent by a remote, authenticated attacker to /GponForm/usb_Form?script/. An attacker can leverage this vulnerability to potentially execute arbitrary code.
ModificadaAlta (8.8)3.9%—Nokia I-240w-q Gpon ONT Firmware5/3/201917/6/2026
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to authenticated command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/device_Form?script/.
ModificadaAlta (8.8)3.9%—Nokia I-240w-q Gpon ONT Firmware5/3/201917/6/2026
The Alcatel Lucent I-240W-Q GPON ONT using firmware version 3FE54567BOZJ19 is vulnerable to command injection via crafted HTTP request sent by a remote, authenticated attacker to /GponForm/usb_restore_Form?script/.
Orbitaley — Vulnerabilidades