Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
–

140 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.8)1.5%—Billion Sg600 R2 Firmware9/1/202017/6/2026
An exposed Telnet Service on the Billion Smart Energy Router SG600R2 with firmware v3.02.rc6 allows a local network attacker to authenticate via hardcoded credentials into a shell, gaining root execution privileges over the device.
ModificadaMedia (5.4)0.78%—Billion Sg600 R2 Firmware9/1/202017/6/2026
XSS in the DHCP lease-status table in Billion Smart Energy Router SG600R2 Firmware v3.02.rc6 allows an attacker to inject arbitrary HTML/JavaScript code to achieve client-side code execution via crafted DHCP request packets to etc_ro/web/internet/dhcpcliinfo.asp.
ModificadaAlta (7.5)1.1%—Honeywell H4d8pr1 FirmwareHoneywell Hfd5pr1 FirmwareHoneywell Hpw2p1 FirmwareHoneywell Hdzp304di Firmware+4431/10/201917/6/2026
Honeywell equIP and Performance series IP cameras, multiple versions, A vulnerability exists where the affected product allows unauthenticated access to audio streaming over HTTP.
ModificadaAlta (7.5)2.1%—Honeywell H2w2pc1m FirmwareHoneywell H2w2per3 FirmwareHoneywell H2w4per3 FirmwareHoneywell H4w2per2 Firmware+2131/10/201917/6/2026
Honeywell equIP series IP cameras Multiple equIP Series Cameras, A vulnerability exists in the affected products where a specially crafted HTTP packet request could result in a denial of service.
ModificadaCrítica (9.8)1.4%—Honeywell H2w2pc1m FirmwareHoneywell H2w2per3 FirmwareHoneywell H2w4per3 FirmwareHoneywell H4w2per2 Firmware+6031/10/201917/6/2026
Honeywell equIP series and Performance series IP cameras and recorders, A vulnerability exists in the affected products where IP cameras and recorders have a potential replay attack vulnerability as a weak authentication method is retained for compatibility with legacy products.
ModificadaMedia (5.3)1.8%—Honeywell Hbd3pr2 FirmwareHoneywell H4d3prv3 FirmwareHoneywell Hed3pr3 FirmwareHoneywell H4d3prv2 Firmware+5526/9/201917/6/2026
In Honeywell Performance IP Cameras and Performance NVRs, the integrated web server of the affected devices could allow remote attackers to obtain web configuration data in JSON format for IP cameras and NVRs (Network Video Recorders), which can be accessed without authentication over the network. Affected performance…
ModificadaAlta (8.8)0.65%—Tibco Loglogic Enterprise Virtual ApplianceTibco Loglogic LOG Management IntelligenceTibco Loglogic Lx825 FirmwareTibco Loglogic Lx4025 Firmware+1813/8/201917/6/2026
The web server component of TIBCO Software Inc.'s TIBCO LogLogic Enterprise Virtual Appliance, and TIBCO LogLogic Log Management Intelligence contains multiple vulnerabilities that theoretically allow persistent and reflected cross-site scripting (XSS) attacks, as well as cross-site request forgery (CSRF) attacks.…
ModificadaMedia (5.5)1.0%—Mitsubishielectric Electric FR Configurator2 Firmware26/7/201917/6/2026
Mitsubishi Electric FR Configurator2, Version 1.16S and prior. This vulnerability is triggered when input passed to the XML parser is not sanitized while parsing the XML project and/or template file (.frc2). Once a user opens the file, the attacker could read arbitrary files.
ModificadaAlta (7.5)1.6%—Siemens Sinamics Perfect Harmony Gh180 With NXG I Control Mlfb 6sr2 FirmwareSiemens Sinamics Perfect Harmony Gh180 With NXG I Control Mlfb 6sr3 FirmwareSiemens Sinamics Perfect Harmony Gh180 With NXG I Control Mlfb 6sr4 FirmwareSiemens Sinamics Perfect Harmony Gh180 With NXG II Control Mlfb 6sr2 Firmware+214/5/201917/6/2026
A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G28), SINAMICS PERFECT HARMONY GH180 with NXG II control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G28). A denial of service vulnerability exists…
ModificadaAlta (7.5)1.8%—Siemens Sinamics Perfect Harmony Gh180 With NXG I Control Mlfb 6sr2 FirmwareSiemens Sinamics Perfect Harmony Gh180 With NXG I Control Mlfb 6sr3 FirmwareSiemens Sinamics Perfect Harmony Gh180 With NXG I Control Mlfb 6sr4 FirmwareSiemens Sinamics Perfect Harmony Gh180 With NXG II Control Mlfb 6sr2 Firmware+214/5/201917/6/2026
A vulnerability has been identified in SINAMICS PERFECT HARMONY GH180 with NXG I control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option G21, G22, G23, G26, G28, G31, G32, G38, G43 or G46), SINAMICS PERFECT HARMONY GH180 with NXG II control, MLFBs: 6SR2...-, 6SR3...-, 6SR4...- (All Versions with option…
ModificadaAlta (7.5)2.3%—Foscam C1 Lite FirmwareFoscam C1 FirmwareFoscam Fi9800p FirmwareFoscam Fi9821ep Firmware+289/7/201817/6/2026
Stack-based buffer overflow in the getSWFlag function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1…
ModificadaAlta (7.2)4.5%—Foscam C1 Lite FirmwareFoscam C1 FirmwareFoscam Fi9800p FirmwareFoscam Fi9821ep Firmware+289/7/201817/6/2026
The setSystemTime function in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47 and…
ModificadaAlta (7.5)2.6%—Foscam C1 Lite FirmwareFoscam C1 FirmwareFoscam Fi9800p FirmwareFoscam Fi9821ep Firmware+289/7/201817/6/2026
Directory traversal vulnerability in Foscam Cameras C1 Lite V3, and C1 V3 with firmware 2.82.2.33 and earlier, FI9800P V3, FI9803P V4, FI9851P V3, and FI9853EP V2 2.84.2.33 and earlier, FI9816P V3, FI9821EP V2, FI9821P V3, FI9826P V3, and FI9831P V3 2.81.2.33 and earlier, C1, C1 V2, C1 Lite, and C1 Lite V2 2.52.2.47…
ModificadaMedia (5.4)0.80%—Iodata Wn-g300r2 FirmwareIodata Wn-g300r3 FirmwareIodata Wn-g300r Firmware14/5/201617/6/2026
Cross-site scripting (XSS) vulnerability on I-O DATA DEVICE WN-G300R devices with firmware 1.12 and earlier, WN-G300R2 devices with firmware 1.12 and earlier, and WN-G300R3 devices with firmware 1.01 and earlier allows remote authenticated users to inject arbitrary web script or HTML via unspecified vectors.
ModificadaMedia (5)1.6%—Iodata Wn-g54/r2 Firmware22/8/201517/6/2026
I-O DATA DEVICE WN-G54/R2 routers with firmware before 1.03 and NP-BBRS routers allow remote attackers to cause a denial of service (SSDP reflection) via UPnP requests.