Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2739▼ 510 respecto a la semana anterior
Críticas / altas1303▼ 212 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
195 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 6.2% | — | Motorola M2 FirmwareMotorola C1 Firmware | 7/3/2019 | 17/6/2026 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST… | |
| Modificada | Crítica (9.8) | 6.2% | — | Motorola M2 FirmwareMotorola C1 Firmware | 7/3/2019 | 17/6/2026 | An issue was discovered on Motorola C1 and M2 devices with firmware 1.01 and 1.07 respectively. This issue is a Command Injection allowing a remote attacker to execute arbitrary code, and get a root shell. A command Injection vulnerability allows attackers to execute arbitrary OS commands via a crafted /HNAP1 POST… | |
| Modificada | Crítica (9.8) | 2.6% | — | Motorola Sbg901 FirmwareMotorola Sbg941 FirmwareMotorola Svg1202 Firmware | 23/12/2018 | 17/6/2026 | Motorola SBG901 SBG901-2.10.1.1-GA-00-581-NOSH, SBG941 SBG941-2.11.0.0-GA-07-624-NOSH, and SVG1202 SVG1202-2.1.0.0-GA-14-LTSH devices allow remote attackers to discover credentials via iso.3.6.1.4.1.4491.2.4.1.1.6.1.1.0 and iso.3.6.1.4.1.4491.2.4.1.1.6.1.2.0 SNMP requests. | |
| Modificada | Alta (7.4) | 0.48% | — | Motorola Mbp853 Firmware | 2/7/2018 | 17/6/2026 | The Motorola MBP853 firmware does not correctly validate server certificates. This allows for a Man in The Middle (MiTM) attack to take place between a Motorola MBP853 camera and the servers it communicates with. In one such instance, it was identified that the device was downloading what appeared to be a client… | |
| Modificada | Media (5.5) | 0.19% | — | Motorola Mx011anm FirmwareComcast Xfinity Xr11-20 Firmware | 31/7/2017 | 17/6/2026 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) and Xfinity XR11-20 Voice Remote devices allows local users to upload arbitrary firmware images to an XR11 by leveraging root access. In other words, there is no protection mechanism involving digital signatures for the firmware. | |
| Modificada | Media (4.6) | 0.36% | — | Motorola Mx011anm Firmware | 31/7/2017 | 17/6/2026 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows physically proximate attackers to read arbitrary files by pressing "EXIT, Down, Down, 2" on an RF4CE remote to reach the diagnostic display, and then launching a Remote Web Inspector script. | |
| Modificada | Media (5.3) | 0.97% | — | Motorola Mx011anm Firmware | 31/7/2017 | 17/6/2026 | The Comcast firmware on Motorola MX011ANM (firmware version MX011AN_2.9p6s1_PROD_sey) devices allows remote attackers to enable a Remote Web Inspector that is accessible from the public Internet. | |
| Modificada | Crítica (9.8) | 1.3% | — | GE Multilin SR 750 Feeder Protection Relay FirmwareGE Multilin SR 760 Feeder Protection Relay FirmwareGE Multilin SR 469 Motor Protection Relay FirmwareMultilin SR 489 Generator Protection Relay Firmware+6 | 30/6/2017 | 17/6/2026 | A Weak Cryptography for Passwords issue was discovered in General Electric (GE) Multilin SR 750 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 760 Feeder Protection Relay, firmware versions prior to Version 7.47; SR 469 Motor Protection Relay, firmware versions prior to Version 5.23; SR 489… | |
| Modificada | Alta (7.5) | 1.1% | — | Bavarian Motor Works Bluetooth Stack | 23/5/2017 | 17/6/2026 | The Bluetooth stack on the BMW 330i 2011 allows a remote crash of the CD/Multimedia software via %x or %c format string specifiers in a device name. | |
| Modificada | Alta (7.1) | 0.91% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+75 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP packets sent on a local Ethernet segment (Layer 2) to an affected product could cause a denial of service condition of that product. Human interaction is required to recover the system. PROFIBUS interfaces are not affected. | |
| Modificada | Alta (7.1) | 1.1% | — | Siemens Simatic CP 343-1 STD FirmwareSiemens Simatic CP 343-1 Lean FirmwareSiemens Simatic CP 343-1 ADV FirmwareSiemens Simatic CP 443-1 STD Firmware+89 | 11/5/2017 | 17/6/2026 | Specially crafted PROFINET DCP broadcast packets could cause a denial of service condition of affected products on a local Ethernet segment (Layer 2). Human interaction is required to recover the systems. PROFIBUS interfaces are not affected. | |
| Modificada | Alta (7.5) | 0.64% | — | Motorola Moscad IP Gateway Firmware | 23/12/2015 | 17/6/2026 | Cross-site request forgery (CSRF) vulnerability in Motorola Solutions MOSCAD IP Gateway allows remote attackers to hijack the authentication of administrators for requests that modify a password. | |
| Modificada | Alta (7.5) | 1.5% | — | Motorola Moscad IP Gateway Firmware | 23/12/2015 | 17/6/2026 | Motorola Solutions MOSCAD IP Gateway allows remote attackers to read arbitrary files via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.48% | — | Motorola Scanner SDK | 16/2/2015 | 17/6/2026 | Motorola Scanner SDK uses weak permissions for (1) CoreScanner.exe, (2) rsmdriverproviderservice.exe, and (3) ScannerService.exe, which allows local users to gain privileges via unspecified vectors. | |
| Modificada | Media (6.8) | 3.3% | — | Motorola Scanner SDK | 16/2/2015 | 17/6/2026 | Multiple stack-based buffer overflows in Motorola Scanner SDK allow remote attackers to execute arbitrary code via a crafted string to the Open method in (1) IOPOSScanner.ocx or (2) IOPOSScale.ocx. | |
| Modificada | Media (5.4) | 0.27% | — | Alawar Motor Town\ | 21/10/2014 | 17/6/2026 | The Motor Town: Machine Soul Free (aka com.alawar.motortownfree) application 1.1 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Digifi Motoring Classics | 19/10/2014 | 17/6/2026 | The Motoring Classics (aka com.aptusi.android.motoring) application 1.8.6 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (5.4) | 0.27% | — | Magzter Motor | 19/10/2014 | 17/6/2026 | The Motor (aka com.magzter.motorhwpublishing) application 3.0 for Android does not verify X.509 certificates from SSL servers, which allows man-in-the-middle attackers to spoof servers and obtain sensitive information via a crafted certificate. | |
| Modificada | Media (6.9) | 0.18% | — | Google AndroidMotorola Defy XT | 25/9/2013 | 16/6/2026 | Stack-based buffer overflow in the sub_E110 function in init in a certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless allows local users to gain privileges or cause a denial of service (memory corruption) by writing a long string to the /dev/socket/init_runit socket that is… | |
| Modificada | Media (6.9) | 0.21% | — | Google AndroidMotorola Defy XT | 25/9/2013 | 16/6/2026 | A certain configuration of Android 2.3.7 on the Motorola Defy XT phone for Republic Wireless uses init to create a /dev/socket/init_runit socket that listens for shell commands, which allows local users to gain privileges by interacting with a LocalSocket object. | |
| Modificada | Media (6.2) | 0.23% | — | Qualcomm Msm8960Motorola AndroidMotorola Atrix HDMotorola Razr HD+1 | 13/4/2013 | 16/6/2026 | The TrustZone kernel, when used in conjunction with a certain Motorola build of Android 4.1.2, on Motorola Razr HD, Razr M, and Atrix HD devices with the Qualcomm MSM8960 chipset does not verify the association between a certain physical-address argument and a memory region, which allows local users to unlock the… | |
| Analizada | Alta (7.8) | 3.2% | ⚠ Explotación activa💥 PoC | Linux KernelMotorola Android | 13/4/2013 | 16/6/2026 | Integer overflow in the fb_mmap function in drivers/video/fbmem.c in the Linux kernel before 3.8.9, as used in a certain Motorola build of Android 4.1.2 and other products, allows local users to create a read-write memory mapping for the entirety of kernel memory, and consequently gain privileges, via crafted… | |
| Modificada | Media (5) | 8.6% | 💥 Exploit | Motorola Surfboard Sbv6120e | 16/6/2010 | 16/6/2026 | Multiple directory traversal vulnerabilities in the web server for Motorola SURFBoard cable modem SBV6120E running firmware SBV6X2X-1.0.0.5-SCM-02-SHPC allow remote attackers to read arbitrary files via (1) "//" (multiple leading slash), (2) ../ (dot dot) sequences, and encoded dot dot sequences in a URL request. | |
| Modificada | Media (5) | 3.0% | 💥 Exploit | Ipmotor Quarkmail | 9/9/2009 | 16/6/2026 | Directory traversal vulnerability in get_message.cgi in QuarkMail allows remote attackers to read arbitrary files via a .. (dot dot) in the tf parameter. | |
| Modificada | Media (5) | 2.7% | 💥 Exploit | Visavi Wap-motor | 9/9/2009 | 16/6/2026 | Directory traversal vulnerability in gallery/gallery.php in Wap-Motor before 18.1 allows remote attackers to read arbitrary files via a .. (dot dot) in the image parameter. |