Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2855▼ 166 respecto a la semana anterior
Críticas / altas1379▲ 45 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

52 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.8)0.12%—Navtor Navbox Firmware4/6/202622/7/2026
NAVTOR NavBox through version 4.16.1.20 contains hard-coded credentials within its Windows Communication Foundation (SOAP) implementation. If the SOAP functionality is enabled, a local attacker can extract credentials to bypass the intended transfer workflow. Successful authentication against the SOAP interface grants…
AnalizadaAlta (7.5)0.67%—Navtor Navbox Firmware6/3/202617/6/2026
Navtor NavBox exposes sensitive configuration and operational data due to missing authentication on HTTP API endpoints. An unauthenticated remote attacker with network access to the device can execute HTTP GET requests to TCP port 8080 to retrieve internal network parameters including ECDIS & OT Information, device…
AnalizadaAlta (7.5)0.71%—Navtor Navbox Firmware6/3/202617/6/2026
An Absolute Path Traversal vulnerability exists in Navtor NavBox. The application exposes an HTTP service that fails to properly sanitize user-supplied path input. Unauthenticated remote attackers can exploit this issue by submitting requests containing absolute filesystem paths. Successful exploitation allows the…
AnalizadaMedia (5.3)0.46%—Navtor Navbox Firmware6/3/202617/6/2026
Navtor NavBox allows information disclosure via the /api/ais-data endpoint. A remote, unauthenticated attacker can send crafted requests to trigger an unhandled exception, causing the server to return verbose .NET stack traces. These error messages expose internal class names, method calls, and third-party library…
AnalizadaAlta (7.3)0.25%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an attacker to flash modified firmware with no cryptographic protections.
AnalizadaAlta (7.5)0.43%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modification of partitions.
AnalizadaMedia (5.4)0.23%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access to flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls.
AnalizadaCrítica (9.4)0.23%—Bitdefender BOX Firmware12/3/202517/6/2026
Bitdefender Box, versions 1.3.11.490 through 1.3.11.505, uses the insecure HTTP protocol to download assets over the Internet to update and restart daemons and detection rules on the devices. Updates can be remotely triggered through the /set_temp_token API method. Then, an unauthenticated and network-adjacent…
AnalizadaCrítica (9.4)0.77%—Bitdefender BOX Firmware12/3/202517/6/2026
A command injection vulnerability exists in the /check_image_and_trigger_recovery API endpoint of Bitdefender Box 1 (firmware version 1.3.11.490). This flaw allows an unauthenticated, network-adjacent attacker to execute arbitrary commands on the device, potentially leading to full remote code execution (RCE).
AnalizadaBaja (1.8)0.17%—Bitdefender BOX Firmware12/3/202517/6/2026
An improper access control vulnerability exists in Bitdefender Box 1 (firmware version 1.3.52.928 and below) that allows an unauthenticated attacker to downgrade the device's firmware to an older, potentially vulnerable version of a Bitdefender-signed firmware. The attack requires Bitdefender BOX to be booted in…
ModificadaAlta (8.6)0.39%—Motorola Vigilant Fixed LPR Coms BOX Firmware13/6/202417/6/2026
An attacker can access the maintenance console using hard coded credentials for a hidden wireless network on the device.
ModificadaAlta (7)0.15%—Motorola Vigilant Fixed LPR Coms BOX Firmware13/6/202417/6/2026
An unauthorized user is able to gain access to sensitive data, including credentials, by physically retrieving the hard disk of the product as the data is stored in clear text.
ModificadaMedia (5.1)0.25%—Motorola Vigilant Fixed LPR Coms BOX Firmware13/6/202417/6/2026
The affected product is vulnerable to an attacker modifying the bootloader by using custom arguments to bypass authentication and gain access to the file system and obtain password hashes.
AnalizadaMedia (5.4)0.48%—SMA Sunny Webbox Firmware26/2/202417/6/2026
Vulnerability whereby an attacker could send a malicious link to an authenticated operator, which could allow remote attackers to perform a clickjacking attack on Sunny WebBox firmware version 1.6.1 and earlier.
ModificadaAlta (7.2)1.1%—Enbw Senec Storage BOX Firmware7/12/202317/6/2026
SENEC Storage Box V1,V2 and V3 accidentially expose a management UI accessible with publicly known admin credentials.
ModificadaCrítica (9.8)0.90%—Enbw Senec Storage BOX Firmware7/12/202317/6/2026
The affected devices use publicly available default credentials with administrative privileges.
ModificadaCrítica (9.1)0.58%—Enbw Senec Storage BOX Firmware7/12/202317/6/2026
The affected devices transmit sensitive information unencrypted allowing a remote unauthenticated attacker to capture and modify network traffic.
ModificadaAlta (7.5)0.96%—Enbw Senec Storage BOX Firmware7/12/202317/6/2026
In SENEC Storage Box V1,V2 and V3 an unauthenticated remote attacker can obtain the devices' logfiles that contain sensitive data.
ModificadaAlta (8.1)0.98%—Showmojo Mojobox Firmware20/7/202317/6/2026
ShowMojo MojoBox Digital Lockbox 1.4 is vulnerable to Authentication Bypass. The implementation of the lock opening mechanism via Bluetooth Low Energy (BLE) is vulnerable to replay attacks. A malicious user is able to intercept BLE requests and replicate them to open the lock at any time. Alternatively, an attacker…
ModificadaAlta (8.8)0.76%—Phoenixcontact Energy AXC PUPhoenixcontact Infobox FirmwarePhoenixcontact Smartrtu AXC SG FirmwarePhoenixcontact Smartrtu AXC IG Firmware17/4/202317/6/2026
In Phoenix Contacts ENERGY AXC PU Web service an authenticated restricted user of the web frontend can access, read, write and create files throughout the file system using specially crafted URLs via the upload and download functionality of the web service. This may lead to full control of the service.
ModificadaMedia (6.5)0.43%—Schneider-electric Conext Combox Firmware30/1/202317/6/2026
A CWE-1021: Improper Restriction of Rendered UI Layers or Frames vulnerability exists that could cause an adversary to trick the interface user/admin into interacting with the application in an unintended way when the product does not implement restrictions on the ability to render within frames on external addresses.…
ModificadaMedia (6.5)0.25%—Schneider-electric Conext Combox Firmware30/1/202317/6/2026
A CWE-352: Cross-Site Request Forgery (CSRF) vulnerability exists that could cause system’s configurations override and cause a reboot loop when the product suffers from POST-Based Cross-Site Request Forgery (CSRF). Affected Products: Conext™ ComBox (All Versions)
ModificadaCrítica (9.8)0.64%—Schneider-electric Conext Combox Firmware30/1/202317/6/2026
A CWE-307: Improper Restriction of Excessive Authentication Attempts vulnerability exists that could cause brute force attacks to take over the admin account when the product does not implement a rate limit mechanism on the admin authentication form. Affected Products: Conext™ ComBox (All Versions)
ModificadaAlta (7.5)0.92%—V88 Smart TV BOX Project V88 Smart TV BOX FirmwareRK MAX Smart TV BOX Project RK MAX Smart TV BOX Firmware20/7/202217/6/2026
An issue was discovered in RK Smart TV Box MAX and V88 SmartTV box that allows attackers to cause a denial of service via the switchNextDisplayInterface service.
ModificadaAlta (7.5)0.90%—Schneider-electric Conext Combox Firmware11/2/202217/6/2026
A CWE-522: Insufficiently Protected Credentials vulnerability exists that could cause Sensitive data such as login credentials being exposed when a Network is sniffed. Affected Product: Conext� ComBox (All Versions)