Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2696▼ 543 respecto a la semana anterior
Críticas / altas1264▼ 228 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)262▼ 241 respecto a la semana anterior
138 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8) | 0.45% | — | Bosch Smart Home Controller Firmware | 29/5/2019 | 17/6/2026 | A potential incorrect privilege assignment vulnerability exists in the app permission update API of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in a restricted app obtaining default app permissions. In order to exploit the vulnerability, the adversary needs to have successfully paired an app… | |
| Modificada | Alta (8) | 1.0% | — | Bosch Smart Home Controller Firmware | 29/5/2019 | 17/6/2026 | A potential improper access control vulnerability exists in the JSON-RPC interface of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in reading or modification of the SHC's configuration or triggering and restoring backups. In order to exploit the vulnerability, the adversary needs to have… | |
| Modificada | Alta (8) | 0.54% | — | Bosch Smart Home Controller Firmware | 29/5/2019 | 17/6/2026 | A potential incorrect privilege assignment vulnerability exists in the app pairing mechanism of the Bosch Smart Home Controller (SHC) before 9.8.905 that may result in elevated privileges of the adversary's choosing. In order to exploit the vulnerability, the adversary needs physical access to the SHC during the… | |
| Modificada | Crítica (9.1) | 1.5% | — | Bosch Access Professional EditionBosch Video ClientBosch Video Management SystemBosch Building Integration System+7 | 29/5/2019 | 17/6/2026 | A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition (APE), Access Easy Controller (AEC), Bosch Video Client (BVC)… | |
| Modificada | Crítica (9.8) | 2.0% | — | Bosch Access Professional EditionBosch Video ClientBosch Video Management SystemBosch Building Integration System+9 | 29/5/2019 | 17/6/2026 | A recently discovered security vulnerability affects all Bosch Video Management System (BVMS) versions 9.0 and below, DIVAR IP 2000, 3000, 5000 and 7000, Video Recording Manager (VRM), Video Streaming Gateway (VSG), Configuration Manager, Building Integration System (BIS) with Video Engine, Access Professional Edition… | |
| Modificada | Media (6.5) | 1.4% | — | Bosch Divar IP 2000 FirmwareBosch Divar IP 5000 FirmwareBosch Video Management SystemBosch Video Recording Manager | 13/5/2019 | 17/6/2026 | A Path Traversal vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote authorized user to access arbitrary files on the system via the network interface. Affected hardware products: Bosch DIVAR IP 2000 (vulnerable versions: 3.10;… | |
| Modificada | Media (6.1) | 1.1% | — | Bosch Divar IP 2000 FirmwareBosch Divar IP 5000 FirmwareBosch Video Management SystemBosch Video Recording Manager | 13/5/2019 | 17/6/2026 | An Open Redirect vulnerability located in the webserver affects several Bosch hardware and software products. The vulnerability potentially allows a remote attacker to redirect users to an arbitrary URL. Affected hardware products: Bosch DIVAR IP 2000 (vulnerable versions: 3.10; 3.20; 3.21; 3.50; 3.51; 3.55; 3.60;… | |
| Modificada | Baja (3.3) | 0.27% | — | Bosch Smart Camera | 22/2/2019 | 17/6/2026 | An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to setting of insecure permissions, a malicious app could potentially succeed in retrieving video clips or still images that have been cached for clip sharing. (The Bosch Smart Home App is not affected. iOS Apps are not affected.) | |
| Modificada | Alta (7.5) | 0.48% | — | Bosch Smart Camera | 22/2/2019 | 17/6/2026 | An issue was discovered in the Bosch Smart Camera App before 1.3.1 for Android. Due to improperly implemented TLS certificate checks, a malicious actor could potentially succeed in executing a man-in-the-middle attack for some connections. (The Bosch Smart Home App is not affected. iOS Apps are not affected.) | |
| Modificada | Crítica (9.8) | 1.9% | — | Bosch 360-indoor Camera FirmwareBosch Eyes Outdoor Camera Firmware | 19/12/2018 | 17/6/2026 | An issue was discovered in several Bosch Smart Home cameras (360 degree indoor camera and Eyes outdoor camera) with firmware before 6.52.4. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface, because there is a buffer overflow in the RCP+ parser… | |
| Modificada | Crítica (9.8) | 2.4% | — | Bosch Common Product Platform 4 FirmwareBosch Common Product Platform 6 FirmwareBosch Common Product Platform 7 FirmwareBosch Common Product Platform 7.3 Firmware | 17/12/2018 | 17/6/2026 | An issue was discovered in several Bosch IP cameras for firmware versions 6.32 and higher. A malicious client could potentially succeed in the unauthorized execution of code on the device via the network interface. | |
| Modificada | Media (6.1) | 0.95% | — | Bosch Bladecontrol-webvis | 6/7/2016 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (6.4) | 0.88% | — | Bosch Bladecontrol-webvis | 6/7/2016 | 17/6/2026 | SQL injection vulnerability in Rexroth Bosch BLADEcontrol-WebVIS 3.0.2 and earlier allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |