Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

234 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)0.30%—Eginnovations EG AgentEginnovations EG ManagerEginnovations EG RUM CollectorsEginnovations VM Agent2/6/202217/6/2026
eG Agent before 7.2 has weak file permissions that enable escalation of privileges to SYSTEM.
ModificadaCrítica (9.8)3.3%💥 PoCBaicells Nova436q FirmwareBaicells Neutrino 430 Firmware30/3/202217/6/2026
Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.)
ModificadaAlta (7.5)0.89%—SAP Innovation Management28/3/202217/6/2026
Under certain conditions, SAP Innovation management - version 2.0, allows an attacker to access information which could lead to information gathering for further exploits and attacks.
ModificadaMedia (6.1)27%💥 ExploitOpenstack NovaRedhat Openstack Platform2/3/202217/6/2026
A vulnerability was found in openstack-nova's console proxy, noVNC. By crafting a malicious URL, noVNC could be made to redirect to any desired URL.
ModificadaAlta (8.8)0.46%—Starcharge Titan 180 Premium FirmwareStarcharge Nova 360 Cabinet Firmware22/12/20219/7/2026
Certain Starcharge products are affected by Improper Input Validation. The affected products include: Nova 360 Cabinet <= 1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0 and Titan 180 Premium <= 1.3.0.0.6 - Fixed: 1.3.0.0.9.
ModificadaAlta (8.8)1.8%—Starcharge Titan 180 Premium FirmwareStarcharge Nova 360 Cabinet Firmware22/12/20219/7/2026
Certain Starcharge products are vulnerable to Directory Traversal via main.cgi. The affected products include: Nova 360 Cabinet <=1.3.0.0.6 - Fixed: 1.3.0.0.9 and Titan 180 Premium <=1.3.0.0.7b102 - Fixed: Beta1.3.0.1.0.
ModificadaAlta (7.2)1.3%—Merkuryinnovations Geeni Gnc-cw028 FirmwareMerkuryinnovations Geeni Gnc-cw025 FirmwareMerkuryinnovations Merkury Mi-cw024 FirmwareMerkuryinnovations Merkury Mi-cw017 Firmware26/1/202117/6/2026
An issue was discovered on Geeni GNC-CW028 Camera 2.7.2, Geeni GNC-CW025 Doorbell 2.9.5, Merkury MI-CW024 Doorbell 2.9.6, and Merkury MI-CW017 Camera 2.9.6 devices. A vulnerability exists in the RESTful Services API that allows a remote attacker to take full control of the camera with a high-privileged account. The…
ModificadaCrítica (9.8)1.5%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaCrítica (9.8)1.1%—Gehealthcare 3.0t Signa Hdxt FirmwareGehealthcare 3.0t Signa HD 16 FirmwareGehealthcare 3.0t Signa HD 23 FirmwareGehealthcare 1.5t Brivo Mr355 Firmware+10814/12/202017/6/2026
GE Healthcare Imaging and Ultrasound Products may allow specific credentials to be exposed during transport over the network.
ModificadaAlta (7.8)0.26%—Huawei Nova 4 FirmwareHuawei Sydneym-al00 Firmware1/12/202017/6/2026
HUAWEI nova 4 versions earlier than 10.0.0.165(C01E34R2P4) and SydneyM-AL00 versions earlier than 10.0.0.165(C00E66R1P5) have an out-of-bounds read and write vulnerability. An attacker with specific permissions crafts malformed packet with specific parameter and sends the packet to the affected products. Due to…
ModificadaAlta (8.3)1.7%—Openstack Nova26/8/202017/6/2026
An issue was discovered in Guest.migrate in virt/libvirt/guest.py in OpenStack Nova before 19.3.1, 20.x before 20.3.1, and 21.0.0. By performing a soft reboot of an instance that has previously undergone live migration, a user may gain access to destination host devices that share the same paths as host devices…
ModificadaMedia (6.1)2.9%💥 ExploitThemeinprogress Nova Lite12/8/202017/6/2026
search.php in the Nova Lite theme before 1.3.9 for WordPress allows Reflected XSS.
ModificadaMedia (6.8)0.39%—Intel Innovation Engine Firmware15/6/202017/6/2026
Insufficient control flow management in firmware build and signing tool for Intel(R) Innovation Engine before version 1.0.859 may allow an unauthenticated user to potentially enable escalation of privilege via physical access.
ModificadaMedia (4.6)0.21%—Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Anne-al00 Firmware+248/6/202017/6/2026
Huawei smart phones have a Factory Reset Protection (FRP) bypass security vulnerability. When re-configuring the mobile phone using the factory reset protection (FRP) function, an attacker login the Talkback mode and can perform some operations to install a third-Party application. Affected products can be found in…
ModificadaMedia (5.3)0.32%—Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+4327/4/202017/6/2026
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 2…
ModificadaMedia (5.3)0.32%—Huawei Alp-al00b FirmwareHuawei Alp-l09 FirmwareHuawei Alp-l29 FirmwareHuawei Bla-l29c Firmware+4327/4/202017/6/2026
There are two denial of service vulnerabilities on some Huawei smartphones. An attacker may send specially crafted TD-SCDMA messages from a rogue base station to the affected devices. Due to insufficient input validation of two values when parsing the messages, successful exploit may cause device abnormal. This is 1…
ModificadaAlta (7.8)0.48%—Claranova Adaware Antivirus18/3/202017/6/2026
Adaware antivirus 12.6.1005.11662 and 12.7.1055.0 has a quarantine flaw that allows privilege escalation. Exploitation uses an NTFS directory junction to restore a malicious DLL from quarantine into the system32 folder.
AnalizadaAlta (7.8)1.4%⚠ Explotación activa💥 PoCGoogle AndroidHuawei Berkeley-l09 FirmwareHuawei Columbia-al10b FirmwareHuawei Columbia-l29d Firmware+2510/3/202017/6/2026
In the ioctl handlers of the Mediatek Command Queue driver, there is a possible out of bounds write due to insufficient input sanitization and missing SELinux restrictions. This could lead to local escalation of privilege with no additional execution privileges needed. User interaction is not needed for…
ModificadaBaja (3.3)0.41%—Openstack Nova19/2/202017/6/2026
An issue was discovered in OpenStack Nova before 18.2.4, 19.x before 19.1.0, and 20.x before 20.1.0. It can leak consoleauth tokens into log files. An attacker with read access to the service's logs may obtain tokens used for console access. All Nova setups using novncproxy are affected. This is related to…
ModificadaAlta (8.8)6.1%💥 PoCGoogle AndroidHuawei Mate 20 FirmwareHuawei Mate 20 PRO FirmwareHuawei Mate 20 X Firmware+1813/2/202017/6/2026
In reassemble_and_dispatch of packet_fragmenter.cc, there is possible out of bounds write due to an incorrect bounds calculation. This could lead to remote code execution over Bluetooth with no additional execution privileges needed. User interaction is not needed for exploitation.Product: AndroidVersions: Android-8.0…
ModificadaCrítica (9.8)1.4%—Eginnovations EG Manager3/2/202017/6/2026
eG Manager 7.1.2 allows SQL Injection via the user parameter to com.eg.LoginHelperServlet (aka the Forgot Password feature).
ModificadaCrítica (9.8)1.4%—Eginnovations EG Manager3/2/202017/6/2026
eG Manager 7.1.2 allows authentication bypass via a com.egurkha.EgLoginServlet?uname=admin&upass=&accessKey=eGm0n1t0r request.
ModificadaMedia (5.5)0.48%—Huawei Mate 10 PRO FirmwareHuawei Honor V10 FirmwareHuawei Honor 10 FirmwareHuawei Nova 4 Firmware3/1/202017/6/2026
Mate 10 Pro;Honor V10;Honor 10;Nova 4 smartphones have a denial of service vulnerability. The system does not properly check the status of certain module during certain operations, an attacker should trick the user into installing a malicious application, successful exploit could cause reboot of the smartphone.
ModificadaMedia (5.5)0.36%—Openstack NovaDebian Linux5/12/201916/6/2026
OpenStack nova base images permissions are world readable
ModificadaAlta (7.8)0.27%—Huawei Nova 5I PRO FirmwareHuawei Nova 5 Firmware29/11/201917/6/2026
Nova 5i pro and Nova 5 smartphones with versions earlier than 9.1.1.190(C00E190R6P2)and Versions earlier than 9.1.1.175(C00E170R3P2) have an improper validation of array index vulnerability. The system does not properly validate the input value before use it as an array index when processing certain image information.…
Orbitaley — Vulnerabilidades