Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3005▼ 69 respecto a la semana anterior
Críticas / altas1419▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (5.9)0.37%—Cpplusworld Cp-vnr-3104 Firmware10/1/202517/6/2026
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the second RSA private key and access sensitive data or execute a man-in-the-middle attack.
AnalizadaAlta (7.4)0.31%—Cpplusworld Cp-vnr-3104 Firmware10/1/202517/6/2026
Improper handling and storage of certificates in CP Plus CP-VNR-3104 B3223P22C02424 allow attackers to decrypt communications or execute a man-in-the-middle attacks.
AnalizadaMedia (5.9)0.46%—Cpplusworld Cp-vnr-3104 Firmware10/1/202517/6/2026
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to access the Diffie-Hellman (DH) parameters and access sensitive data or execute a man-in-the-middle attack.
AnalizadaMedia (5.9)0.46%—Cpplusworld Cp-vnr-3104 Firmware10/1/202517/6/2026
An issue in CP Plus CP-VNR-3104 B3223P22C02424 allows attackers to obtain the EC private key and access sensitive data or execute a man-in-the-middle attack.
ModificadaAlta (7.5)1.1%—Cpplusworld Cp-vnr-3104 FirmwareCpplusworld Cp-vnr-3108 FirmwareCpplusworld Cp-vnr-3208 Firmware24/8/202317/6/2026
The vulnerability exists in CP-Plus NVR due to an improper input handling at the web-based management interface of the affected product. An unauthenticated remote attacker could exploit this vulnerability by sending specially crafted HTTP requests to the vulnerable device. Successful exploitation of this vulnerability…