Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2729▼ 513 respecto a la semana anterior
Críticas / altas1298▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
–

195 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (4.8)0.45%—Motorola T008 FirmwareMotorola T100 FirmwareMotorola T101 FirmwareMotorola T102 Firmware+615/12/202117/6/2026
Certain Motorola Solutions Avigilon devices allow XSS in the administrative UI. This affects T200/201 before 4.10.0.68; T290 before 4.4.0.80; T008 before 2.2.0.86; T205 before 4.12.0.62; T204 before 3.28.0.166; and T100, T101, T102, and T103 before 2.6.0.180.
ModificadaMedia (6.8)0.29%—Motorola Mm1000 Firmware17/8/202117/6/2026
A privilege escalation vulnerability was reported in the MM1000 device configuration web server, which could allow privileged shell access and/or arbitrary privileged commands to be executed on the adapter.
ModificadaMedia (4.6)0.24%—Motorola Mm1000 Firmware17/8/202117/6/2026
The Motorola MM1000 device configuration portal can be accessed without authentication, which could allow adapter settings to be modified.
ModificadaCrítica (9.8)4.8%—Motorola CX2 Firmware21/7/202117/6/2026
An command injection vulnerability in HNAP1/SetWLanApcliSettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary system commands.
ModificadaMedia (5.3)1.3%—Motorola CX2 Firmware21/7/202117/6/2026
An issue in HNAP1/GetMultipleHNAPs of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to access the components GetStationSettings, GetWebsiteFilterSettings and GetNetworkSettings without authentication.
ModificadaCrítica (9.8)4.4%—Motorola CX2 Firmware21/7/202117/6/2026
A command injection vulnerability in HNAP1/GetNetworkTomographySettings of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to execute arbitrary code.
ModificadaAlta (7.5)1.6%—Motorola CX2 Firmware21/7/202117/6/2026
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where authentication to download the Syslog could be bypassed.
ModificadaAlta (7.5)1.5%—Motorola CX2 Firmware21/7/202117/6/2026
An issue was discovered in Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n where the admin password and private key could be found in the log tar package.
ModificadaMedia (5.3)1.3%—Motorola CX2 Firmware21/7/202117/6/2026
A vulnerability in /Login.html of Motorola CX2 router CX 1.0.2 Build 20190508 Rel.97360n allows attackers to bypass login and obtain a partially authorized token and uid.
ModificadaCrítica (9.8)2.6%—Stockware Motor6/7/202117/6/2026
Lack of authentication or validation in motor_load_more, motor_gallery_load_more, motor_quick_view and motor_project_quick_view AJAX handlers of the Motor WordPress theme before 3.1.0 allows an unauthenticated attacker access to arbitrary files in the server file system, and to execute arbitrary php scripts found on…
ModificadaCrítica (9.8)0.56%—Motorola Mh702x Firmware13/4/202117/6/2026
The Motorola MH702x devices, prior to version 2.0.0.301, do not properly verify the server certificate during communication with the support server which could lead to the communication channel being accessible by an attacker.
ModificadaAlta (7.5)1.4%—Motorola Fx9500-41324d41-us FirmwareMotorola Fx9500-41324d41-ww FirmwareMotorola Fx9500-81324d41-us FirmwareMotorola Fx9500-81324d41-ww Firmware23/3/202017/6/2026
Motorola FX9500 devices allow remote attackers to read database files.
ModificadaMedia (6.1)1.4%—Stylemixthemes Motors - CAR Dealer, Classifieds & Listing24/2/202017/6/2026
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress has multiple stored XSS issues.
ModificadaMedia (6.5)1.2%💥 ExploitStylemixthemes Motors - CAR Dealer, Classifieds & Listing24/2/202017/6/2026
includes/options.php in the motors-car-dealership-classified-listings (aka Motors - Car Dealer & Classified Ads) plugin through 1.4.0 for WordPress allows unauthenticated options changes.
ModificadaCrítica (9.8)2.1%—Motorola Firmware12/9/201917/6/2026
Some Motorola devices include the SIMalliance Toolbox Browser (aka S@T Browser) on the UICC, which might allow remote attackers to retrieve location and IMEI information, or retrieve other data or execute certain commands, via SIM Toolkit (STK) instructions in an SMS message, aka Simjacker.
ModificadaAlta (7.5)1.7%—Openwrt LibuciMotorola Cx2l Mwr04l FirmwareMotorola C1 Mwr03 Firmware23/8/201917/6/2026
An issue was discovered in OpenWrt libuci (aka Library for the Unified Configuration Interface) before 15.05.1 as used on Motorola CX2L MWR04L 1.01 and C1 MWR03 1.01 devices. /tmp/.uci/network locking is mishandled after reception of a long SetWanSettings command, leading to a device hang.
ModificadaAlta (7.5)1.4%—Motorola Cx2l Mwr04l Firmware1/7/201917/6/2026
On the Motorola router CX2L MWR04L 1.01, there is a stack consumption (infinite recursion) issue in scopd via TCP port 8010 and UDP port 8080. It is caused by snprintf and inappropriate length handling.
ModificadaCrítica (9.8)1.7%—Motorola CX2 FirmwareMotorola M2 Firmware23/5/201917/6/2026
An issue was discovered in scopd on Motorola routers CX2 1.01 and M2 1.01. There is a Use of an Externally Controlled Format String, reachable via TCP port 8010 or UDP port 8080.
ModificadaCrítica (9.8)3.9%—Motorola CX2 FirmwareMotorola M2 Firmware18/4/201917/6/2026
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function startRmtAssist in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
ModificadaMedia (5.3)1.3%—Motorola CX2 FirmwareMotorola M2 Firmware18/4/201917/6/2026
An issue was discovered in Motorola CX2 1.01 and M2 1.01. The router opens TCP port 8010. Users can send hnap requests to this port without authentication to obtain information such as the MAC addresses of connected client devices.
ModificadaCrítica (9.8)1.7%—Motorola CX2 FirmwareMotorola M2 Firmware18/4/201917/6/2026
In Motorola CX2 1.01 and M2 1.01, users can access the router's /priv_mgt.html web page to launch telnetd, as demonstrated by the 192.168.51.1 address.
ModificadaCrítica (9.8)3.9%—Motorola CX2 FirmwareMotorola M2 Firmware18/4/201917/6/2026
An issue was discovered in Motorola CX2 1.01 and M2 1.01. There is a command injection in the function downloadFirmware in hnap, which leads to remote code execution via shell metacharacters in a JSON value.
ModificadaCrítica (9.8)4.1%—Motorola M2 FirmwareMotorola C1 Firmware7/3/201917/6/2026
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST…
ModificadaCrítica (9.8)6.2%—Motorola M2 FirmwareMotorola C1 Firmware7/3/201917/6/2026
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST…
ModificadaCrítica (9.8)6.2%—Motorola M2 FirmwareMotorola C1 Firmware7/3/201917/6/2026
An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST…
Orbitaley — Vulnerabilidades