Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2568▼ 306 respecto a la semana anterior
Críticas / altas1351▲ 96 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 29% | — | Chiyu-tech Bf-430 FirmwareChiyu-tech Bf-431 FirmwareChiyu-tech Bf-450m FirmwareChiyu-tech Semac S2 Firmware+10 | 4/6/2021 | 17/6/2026 | An open redirect vulnerability exists in BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, and SEMAC devices from CHIYU Technology that can be exploited by sending a link that has a specially crafted URL to convince the user to click on it. | |
| Modificada | Media (5.4) | 88% | — | Chiyu-tech Bf-631 FirmwareChiyu-tech Bf-630 FirmwareChiyu-tech Semac S2 FirmwareChiyu-tech Semac D1 Firmware+7 | 1/6/2021 | 17/6/2026 | An XSS vulnerability exists in several IoT devices from CHIYU Technology, including SEMAC, Biosense, BF-630, BF-631, and Webpass due to a lack of sanitization on the component if.cgi - username parameter. | |
| Modificada | Media (6.5) | 44% | — | Chiyu-tech Semac S2 FirmwareChiyu-tech Semac D1 FirmwareChiyu-tech Semac D2 FirmwareChiyu-tech Semac D4 Firmware+7 | 1/6/2021 | 17/6/2026 | A denial of service condition exists after an integer overflow in several IoT devices from CHIYU Technology, including BIOSENSE, Webpass, and BF-630, BF-631, and SEMAC. The vulnerability can be explored by sending an unexpected integer (> 32 bits) on the page parameter that will crash the web portal and making it… | |
| Modificada | Media (6.1) | 5.1% | — | Chiyu-tech Bf-430 FirmwareChiyu-tech Bf-431 FirmwareChiyu-tech Bf-450m FirmwareChiyu-tech Semac S2 Firmware+11 | 1/6/2021 | 17/6/2026 | An unauthenticated XSS vulnerability exists in several IoT devices from CHIYU Technology, including BF-630, BF-450M, BF-430, BF-431, BF631-W, BF830-W, Webpass, BF-MINI-W, and SEMAC due to a lack of sanitization when the HTTP 404 message is generated. | |
| Modificada | Alta (7.5) | 1.7% | — | Chiyutw Bf-630Chiyutw Bf-630w | 1/8/2015 | 17/6/2026 | Chiyu BF-630 and BF-630W fingerprint access-control devices allow remote attackers to bypass authentication and (1) read or (2) modify (a) Voice Time Set configuration settings via a request to voice.htm or (b) UniFinger configuration settings via a request to bf.htm, a different vulnerability than CVE-2015-2871. | |
| Modificada | Media (4.3) | 1.2% | — | Chiyutw Bf-630Chiyutw Bf-630wChiyutw Bf-660c | 1/8/2015 | 17/6/2026 | Cross-site scripting (XSS) vulnerability on Chiyu BF-630, BF-630W, and BF-660C fingerprint access-control devices allows remote attackers to inject arbitrary web script or HTML via a SCRIPT element. |