Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2535▼ 358 respecto a la semana anterior
Críticas / altas1338▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
17 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.3) | 0.29% | — | Buy-addons BagoogleshoppingAI | 19/6/2024 | 17/6/2026 | In the module "Bulk Export products to Google Merchant-Google Shopping" (bagoogleshopping) up to version 1.0.26 from Buy Addons for PrestaShop, a guest can perform SQL injection via`GenerateCategories::renderCategories(). | |
| Modificada | Alta (7.5) | 1.6% | — | Ohler Agoo | 4/5/2022 | 17/6/2026 | Agoo before 2.14.3 does not reject GraphQL fragment spreads that form cycles, leading to an application crash. NOTE: the vendor has disputed this on the grounds that it is not the server's responsibility to "enforce all the various ways a developer could write code with logic errors. | |
| Modificada | Media (5.3) | 1.2% | — | Amazee Lagoon | 14/12/2020 | 17/6/2026 | The GitLab Webhook Handler in amazee.io Lagoon before 1.12.3 has incorrect access control associated with project deletion. | |
| Modificada | Alta (7.5) | 1.2% | — | Ohler Agoo | 10/6/2020 | 17/6/2026 | agoo prior to 2.14.0 allows request smuggling attacks where agoo is used as a backend and a frontend proxy also being vulnerable. HTTP pipelining issues and request smuggling attacks might be possible due to incorrect Content-Length and Transfer encoding header parsing. It is possible to conduct HTTP request smuggling… | |
| Modificada | Alta (7.5) | 1.5% | — | Cacagoo Tv-288zd-2mp Firmware | 2/4/2020 | 17/6/2026 | The CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 allows access to the RTSP service without a password. | |
| Modificada | Crítica (9.8) | 2.4% | — | Cacagoo Tv-288zd-2mp Firmware | 2/4/2020 | 17/6/2026 | CACAGOO Cloud Storage Intelligent Camera TV-288ZD-2MP with firmware 3.4.2.0919 has weak authentication of TELNET access, leading to root privileges without any password required. | |
| Modificada | Media (5.5) | 0.33% | — | Leagoo Power 5 Firmware | 14/11/2019 | 17/6/2026 | The Leagoo Power 5 Android device with a build fingerprint of LEAGOO/Power_5/Power_5:8.1.0/O11019/1532686195:user/release-keys contains a pre-installed app with a package name of com.mediatek.wfo.impl app (versionCode=27, versionName=8.1.0) that allows any app co-located on the device to modify a system property… | |
| Modificada | Crítica (9.1) | 2.3% | — | Leagoo P1 Firmware | 25/4/2019 | 17/6/2026 | The Leagoo P1 device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.wtk.factory (versionCode=1, versionName=1.0) that contains an exported broadcast receiver named com.wtk.factory.MMITestReceiver… | |
| Modificada | Media (5.5) | 0.39% | — | Leagoo P1 Firmware | 25/4/2019 | 17/6/2026 | The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains the android framework (i.e., system_server) with a package name of android that has been modified by Leagoo or another entity in the supply chain. The system_server process in… | |
| Modificada | Media (6.8) | 0.73% | — | Leagoo P1 Firmware | 28/12/2018 | 17/6/2026 | The Leagoo P1 Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a hidden root privilege escalation capability to achieve command execution as the root user. They have made modifications that allow a user with physical access to the device to… | |
| Modificada | Alta (7.5) | 1.2% | — | Leagoo Z5C Firmware | 28/12/2018 | 17/6/2026 | The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) containing an exported content provider… | |
| Modificada | Alta (7.1) | 0.35% | — | Leagoo Z5C Firmware | 28/12/2018 | 17/6/2026 | The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed platform app with a package name of com.android.settings (versionCode=23, versionName=6.0-android.20170630.092853) that contains an exported broadcast receiver… | |
| Modificada | Alta (7.5) | 1.0% | — | Leagoo Z5C Firmware | 28/12/2018 | 17/6/2026 | The Leagoo Z5C Android device with a build fingerprint of sp7731c_1h10_32v4_bird:6.0/MRA58K/android.20170629.214736:user/release-keys contains a pre-installed app with a package name of com.android.messaging (versionCode=1000110, versionName=1.0.001, (android.20170630.092853-0)) with an exported broadcast receiver app… | |
| Modificada | Alta (8.1) | 2.6% | — | Infinixauthority HOT X507 FirmwareInfinixauthority HOT 2 X510 FirmwareInfinixauthority Zero X506 FirmwareInfinixauthority Zero 2 X509 Firmware+15 | 13/7/2018 | 17/6/2026 | Android devices with code from Ragentek contain a privileged binary that performs over-the-air (OTA) update checks. Additionally, there are multiple techniques used to hide the execution of this binary. This behavior could be described as a rootkit. This binary, which resides as /system/bin/debugs, runs with root… | |
| Modificada | Alta (7.5) | 2.3% | — | Dragoon | 15/4/2008 | 16/6/2026 | Directory traversal vulnerability in forum/kietu/libs/calendrier.php in Dragoon 0.1 allows remote attackers to include and execute arbitrary local files via a .. (dot dot) in the cal[lng] parameter. | |
| Modificada | Media (6.8) | 27% | — | Dragoon | 14/4/2008 | 16/6/2026 | PHP remote file inclusion vulnerability in includes/header.inc.php in Dragoon 0.1 allows remote attackers to execute arbitrary PHP code via a URL in the root parameter. | |
| Modificada | Alta (7.5) | 1.5% | — | Amar Sagoo Tofu | 21/9/2005 | 16/6/2026 | Tofu 0.2 allows remote attackers to execute arbitrary Python code via crafted pickled objects, which Tofu unpickles and executes. |