Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2841▼ 157 respecto a la semana anterior
Críticas / altas1370▲ 51 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 258 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (8) | 0.81% | — | Swisscom Internet-box 2 FirmwareSwisscom Internet-box Standard FirmwareSwisscom Internet-box Plus FirmwareSwisscom Internet-box 3 Firmware+1 | 4/8/2020 | 17/6/2026 | An issue was discovered on Swisscom Internet Box 2, Internet Box Standard, Internet Box Plus prior to 10.04.38, Internet Box 3 prior to 11.01.20, and Internet Box light prior to 08.06.06. Given the (user-configurable) credentials for the local Web interface or physical access to a device's plus or reset button, an… | |
| Modificada | Crítica (9.8) | 4.2% | — | Bitdefender BOX 2 Firmware | 27/1/2020 | 17/6/2026 | A command injection vulnerability has been discovered in the bootstrap stage of Bitdefender BOX 2, versions 2.1.47.42 and 2.1.53.45. The API method `/api/download_image` unsafely handles the production firmware URL supplied by remote servers, leading to arbitrary execution of system commands. In order to exploit the… | |
| Modificada | Crítica (9.8) | 2.1% | — | Bitdefender BOX 2 FirmwareBitdefender Central | 27/1/2020 | 17/6/2026 | A OS Command Injection vulnerability in the bootstrap stage of Bitdefender BOX 2 allows the manipulation of the `get_image_url()` function in special circumstances to inject a system command. | |
| Modificada | Alta (8.1) | 1.9% | — | Bitdefender BOX 2 Firmware | 27/1/2020 | 17/6/2026 | An exploitable command execution vulnerability exists in the recovery partition of Bitdefender BOX 2, version 2.0.1.91. The API method `/api/update_setup` does not perform firmware signature checks atomically, leading to an exploitable race condition (TOCTTOU) that allows arbitrary execution of system commands. This… | |
| Modificada | Alta (7.5) | 0.70% | — | Swisscom Internet-box Standard FirmwareSwisscom Internet-box Light FirmwareSwisscom Internet-box Plus FirmwareSwisscom Internet-box 2 Firmware | 17/12/2018 | 17/6/2026 | A stack-based buffer overflow in the LAN UPnP service running on UDP port 1900 of Swisscom Internet-Box (2, Standard, and Plus) prior to v09.04.00 and Internet-Box light prior to v08.05.02 allows remote code execution. No authentication is required to exploit this vulnerability. Sending a simple UDP packet to port… | |
| Modificada | Media (6.7) | 0.33% | — | Compulab Intense PC FirmwareCompulab Mintbox 2 Firmware | 6/6/2017 | 17/6/2026 | CompuLab Intense PC and MintBox 2 devices with BIOS before 2017-05-21 do not use the CloseMnf protection mechanism for write protection of flash memory regions, which allows local users to install a firmware rootkit by leveraging administrative privileges. |