Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3146▲ 578 respecto a la semana anterior
Críticas / altas1455▲ 58 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 1 respecto a la semana anterior
Sin puntuar (sin CVSS)301▲ 287 respecto a la semana anterior
26.338 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.4) | 0.18% | — | Aqara HUB M2 FirmwareAqara HUB M3 FirmwareAqara Camera HUB G3 Firmware | 10/12/2025 | 25/9/2026 | Los dispositivos Aqara Hub, incluyendo Camera Hub G3 4.1.9_0027, Hub M2 4.3.6_0027 y Hub M3 4.3.6_0025, no validan los certificados del servidor durante las descargas de firmware por HTTPS, lo que permite a los atacantes man-in-the-middle interceptar el tráfico de actualización de firmware y potencialmente entregar… | |
| Analizada | Media (6.8) | 0.32% | — | Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware | 10/12/2025 | 17/6/2026 | The ESP32 system on a chip (SoC) that powers the Meatmeet basestation device was found to lack Secure Boot. The Secure Boot feature ensures that only authenticated software can execute on the device. The Secure Boot process forms a chain of trust by verifying all mutable software entities involved in the Application… | |
| Analizada | Media (4.6) | 0.13% | — | Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware | 10/12/2025 | 17/6/2026 | The firmware on the basestation of the Meatmeet is not encrypted. An adversary with physical access to the Meatmeet device can disassemble the device, connect over UART, and retrieve the firmware dump for analysis. Within the NVS partition they may discover the credentials of the current and previous Wi-Fi networks.… | |
| Analizada | Media (6.8) | 0.21% | — | Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware | 10/12/2025 | 17/6/2026 | The ESP32 system on a chip (SoC) that powers the Meatmeet Pro was found to have JTAG enabled. By leaving JTAG enabled on an ESP32 in a commercial product an attacker with physical access to the device can connect over this port and reflash the device's firmware with malicious code which will be executed upon running.… | |
| Analizada | Alta (7.5) | 0.37% | — | Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware | 10/12/2025 | 17/6/2026 | As UART download mode is still enabled on the ESP32 chip on which the firmware runs, an adversary can dump the flash from the device and retrieve sensitive information such as details about the current and previous Wi-Fi network from the NVS partition. Additionally, this allows the adversary to reflash the device with… | |
| Modificada | Media (5.1) | 0.73% | — | Dbbroadcast SFT DAB 015/c FirmwareDbbroadcast SFT DAB 050/c FirmwareDbbroadcast SFT DAB 150/c FirmwareDbbroadcast SFT DAB 300/c Firmware+1 | 10/12/2025 | 17/6/2026 | Screen SFT DAB 1.9.3 contains a weak session management vulnerability that allows attackers to bypass authentication controls by reusing IP address-bound session identifiers. Attackers can exploit the vulnerable API by intercepting and reusing established sessions to remove user accounts without proper authorization. | |
| Analizada | Alta (8.6) | 0.88% | — | Dbbroadcast SFT DAB 015/c FirmwareDbbroadcast SFT DAB 050/c FirmwareDbbroadcast SFT DAB 150/c FirmwareDbbroadcast SFT DAB 300/c Firmware+1 | 10/12/2025 | 17/6/2026 | Screen SFT DAB 1.9.3 contains an authentication bypass vulnerability that allows attackers to change the admin password without providing the current credentials. Attackers can exploit the userManager.cgx endpoint by sending a crafted JSON request with a new MD5-hashed password to directly modify the admin account. | |
| Analizada | Crítica (9.3) | 1.1% | — | Medivision Digital Signage Firmware | 10/12/2025 | 17/6/2026 | UBICOD Medivision Digital Signage 1.5.1 contains an authorization bypass vulnerability that allows normal users to escalate privileges by manipulating the 'ft[grp]' parameter. Attackers can send a GET request to /html/user with 'ft[grp]' set to integer value '3' to gain super admin rights without authentication. | |
| Analizada | Alta (8.6) | 0.31% | — | Medivision Digital Signage Firmware | 10/12/2025 | 17/6/2026 | UBICOD Medivision Digital Signage 1.5.1 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that submits a form to the /query/user/itSet endpoint to add a new admin user with… | |
| Analizada | Crítica (9.3) | 1.2% | — | Sony Snc-dh120t Firmware | 10/12/2025 | 17/6/2026 | Sony IPELA Network Camera 1.82.01 contains a stack buffer overflow vulnerability in the ftpclient.cgi endpoint that allows remote attackers to execute arbitrary code. Attackers can exploit the vulnerability by sending a crafted POST request with oversized data to the FTP client functionality, potentially causing… | |
| Modificada | Alta (7.5) | 0.31% | 💥 PoC | Jxlindia JXL 9 Inch CAR Android Double DIN Player Firmware | 10/12/2025 | 5/7/2026 | An issue in the Bluetooth firmware of JXL 9 Inch Car Android Double Din Player Android v12.0 allows attackers to cause a Denial of Service (DoS) via sending a crafted Link Manager Protocol (LMP) packet. | |
| Modificada | Media (6.5) | 0.28% | — | Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware | 10/12/2025 | 25/9/2026 | Un atacante no autenticado dentro de la proximidad del dispositivo Meatmeet puede emitir varios comandos a través de Bluetooth de Baja Energía (BLE) a estos dispositivos, lo que resultaría en una denegación de servicio. Estos comandos incluyen: apagado, reinicio, borrar configuración. Borrar configuración desasociaría… | |
| Analizada | Alta (8.8) | 0.56% | — | Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware | 10/12/2025 | 25/9/2026 | Un atacante no autenticado dentro de la proximidad del dispositivo Meatmeet puede realizar una actualización de firmware Over The Air (OTA) no autorizada utilizando Bluetooth Low Energy (BLE), lo que resulta en que el firmware del dispositivo sea sobrescrito con el código del atacante. Dado que el dispositivo no… | |
| Analizada | Crítica (9.8) | 0.43% | — | Meatmeet PRO Wifi & Bluetooth Meat Thermometer Firmware | 10/12/2025 | 28/9/2026 | Se descubrió que el Meatmeet Pro se enviaba con credenciales Wi-Fi codificadas de forma rígida en el firmware, para la red de prueba en la que fue desarrollado. Si un atacante recuperara esto y encontrara la ubicación física de la red Wi-Fi, podría obtener acceso no autorizado a la red Wi-Fi del proveedor. Además, si… | |
| Analizada | Crítica (9.8) | 11% | — | Totolink X5000r Firmware | 10/12/2025 | 25/9/2026 | Habilitación de Telnet no autenticado a través de cstecgi.cgi (omisión de autenticación) que lleva a un inicio de sesión de root no autenticado con una contraseña en blanco en X5000R V9.1.0u.6369_B20230113 de fábrica/restablecido (ejecución de comandos arbitrarios). Versiones anteriores que comparten la misma… | |
| Analizada | Crítica (9.8) | 0.43% | — | Wago 0852-1328 FirmwareWago 0852-1322 Firmware | 10/12/2025 | 25/9/2026 | Un atacante remoto no autenticado puede explotar llamadas sscanf inseguras dentro de la función check_cookie() para escribir datos arbitrarios en búferes de pila de tamaño fijo, lo que lleva a un compromiso total del dispositivo. | |
| Analizada | Crítica (9.8) | 0.43% | — | Wago 0852-1328 FirmwareWago 0852-1322 Firmware | 10/12/2025 | 25/9/2026 | Un atacante remoto no autenticado puede abusar de llamadas sscanf inseguras dentro de la función check_account() para escribir datos arbitrarios en búferes de pila de tamaño fijo, lo que lleva al compromiso total del dispositivo. | |
| Analizada | Crítica (9.3) | 0.52% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains a hard-coded developer password vulnerability that allows unauthorized configuration access through an undocumented page. Attackers can exploit the hidden endpoint by using the hard-coded password 'Selea781830' to enable configuration upload and overwrite device settings. | |
| Modificada | Alta (8.5) | 0.25% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains a cross-site request forgery vulnerability that allows attackers to create administrative users without authentication. Attackers can craft a malicious web page that submits a form to add a new admin user with full system privileges when a logged-in user visits the page. | |
| Analizada | Media (5.1) | 0.30% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains a stored cross-site scripting vulnerability in the 'files_list' parameter that allows attackers to inject malicious HTML and script code. Attackers can send a POST request to /cgi-bin/get_file.php with crafted payload to execute arbitrary scripts in victim's browser session. | |
| Analizada | Crítica (9.3) | 2.6% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains an unauthenticated command injection vulnerability in utils.php that allows remote attackers to execute arbitrary shell commands. Attackers can exploit the 'addr' and 'port' parameters to inject commands and gain www-data user access through chained local file inclusion… | |
| Analizada | Alta (8.7) | 0.47% | — | Selea Izero BOX Full FirmwareSelea Izero Column Entry/8 FirmwareSelea Izero Column Full/8 FirmwareSelea Targa 504 Firmware+8 | 9/12/2025 | 17/6/2026 | Selea Targa IP OCR-ANPR Camera contains an unauthenticated vulnerability that allows remote attackers to access live video streams without authentication. Attackers can directly connect to RTP/RTSP or M-JPEG streams by requesting specific endpoints like p1.mjpg or p1.264 to view camera footage. | |
| Analizada | Alta (7.2) | 1.7% | — | Fortinet Fortiextender Firmware | 9/12/2025 | 17/6/2026 | A improper neutralization of special elements used in an os command ('os command injection') in Fortinet FortiExtender 7.6.0 through 7.6.3, FortiExtender 7.4.0 through 7.4.7, FortiExtender 7.2 all versions, FortiExtender 7.0 all versions may allow an authenticated attacker to execute unauthorized code or commands via… | |
| Analizada | Crítica (9.8) | 68% | ⚠ Explotación activa💥 PoC | Fortinet FortiproxyFortinet FortiswitchmanagerFortinet FortiosSiemens Ruggedcom Ape1808 Firmware | 9/12/2025 | 17/6/2026 | Una vulnerabilidad de verificación incorrecta de firma criptográfica en Fortinet FortiOS 7.6.0 hasta 7.6.3, FortiOS 7.4.0 hasta 7.4.8, FortiOS 7.2.0 hasta 7.2.11, FortiOS 7.0.0 hasta 7.0.17, FortiProxy 7.6.0 hasta 7.6.3, FortiProxy 7.4.0 hasta 7.4.10, FortiProxy 7.2.0 hasta 7.2.14, FortiProxy 7.0.0 hasta 7.0.21,… | |
| Analizada | Media (6.1) | 0.32% | — | Mercurycom Mr816 Firmware | 9/12/2025 | 17/6/2026 | A stored Cross site scripting (XSS) vulnerability in the Mercury MR816v2 (081C3114 4.8.7 Build 110427 Rel 36550n) router allows a remote attacker on the LAN to inject JavaScript into the router's management UI by submitting a malicious hostname. The injected script is stored and later executed in the context of an… |