Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.2) | 0.42% | — | Alliedtelesis Ae1021 FirmwareAIAlliedtelesis Ae1021pe FirmwareAI | 18/12/2024 | 17/6/2026 | Inclusion of undocumented features or chicken bits issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to enable telnet service. | |
| Aplazada | Alta (7.2) | 1.6% | — | Ametek Ae1021AIAmetek Ae1021peAI | 18/12/2024 | 17/6/2026 | Improper neutralization of special elements used in an OS command ('OS Command Injection') issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier, which may allow a logged-in user to execute an arbitrary OS command using a crafted HTTP request. | |
| Aplazada | Alta (7.5) | 0.41% | — | Aesensors Ae1021AIAesensors Ae1021peAI | 18/12/2024 | 17/6/2026 | Weak authentication issue exists in AE1021 firmware versions 2.0.10 and earlier and AE1021PE firmware versions 2.0.10 and earlier. If this vulnerability is exploited, the authentication may be bypassed with an undocumented specific string. | |
| Analizada | Alta (8.8) | 50% | ⚠ Explotación activa | FXC Ae1021 FirmwareFXC Ae1021pe Firmware | 6/12/2023 | 17/6/2026 | An OS command injection vulnerability exists in AE1021PE firmware version 2.0.9 and earlier and AE1021 firmware version 2.0.9 and earlier. If this vulnerability is exploited, an arbitrary OS command may be executed by an attacker who can log in to the product. | |
| Modificada | Media (4.8) | 0.52% | — | Fxc5210 FirmwareFxc5218 FirmwareFxc5224 FirmwareFxc5426f Firmware+6 | 15/11/2018 | 17/6/2026 | Cross-site scripting vulnerability in multiple FXC Inc. network devices (Managed Ethernet switch FXC5210/5218/5224 firmware prior to version Ver1.00.22, Managed Ethernet switch FXC5426F firmware prior to version Ver1.00.06, Managed Ethernet switch FXC5428 firmware prior to version Ver1.00.07, Power over Ethernet (PoE)… |