Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)0.87%—Bg-tek Coslat Bx5s1d3 FirmwareBg-tek Coslat Bx5s1d4 FirmwareBg-tek Coslat Bx5s1d5 FirmwareBg-tek Coslat Rm1ds1000 Firmware+424/2/202317/6/2026
Improper Handling of Parameters vulnerability in BG-TEK COSLAT Firewall allows Remote Code Inclusion. This issue affects COSLAT Firewall: from 5.24.0.R.20180630 before 5.24.0.R.20210727.
ModificadaCrítica (9)0.98%—Asus Zenwifi Xd4s FirmwareAsus Zenwifi XT9 FirmwareAsus Zenwifi XD5 FirmwareAsus Zenwifi PRO Et12 Firmware+895/7/202217/6/2026
ASUS RT-A88U 3.0.0.4.386_45898 is vulnerable to Cross Site Scripting (XSS). The ASUS router admin panel does not sanitize the WiFI logs correctly, if an attacker was able to change the SSID of the router with a custom payload, they could achieve stored XSS on the device.
ModificadaMedia (5.3)1.6%—Dten D5 FirmwareDten D7 Firmware6/1/202017/6/2026
DTEN D5 and D7 before 1.3.2 devices allows remote attackers to read saved whiteboard image PDF documents via storage/emulated/0/Notes/PDF on TCP port 8080 without authentication.
ModificadaAlta (7.5)0.67%—Dten D5 FirmwareDten D7 Firmware6/1/202017/6/2026
DTEN D5 before 1.3 and D7 before 1.3 devices transfer customer data files via unencrypted HTTP.
ModificadaCrítica (9.8)2.3%—Dten D5 FirmwareDten D7 Firmware6/1/202017/6/2026
DTEN D5 and D7 before 1.3.4 devices allow unauthenticated root shell access through Android Debug Bridge (adb), leading to arbitrary code execution and system administration. Also, this provides a covert ability to capture screen data from the Zoom Client on Windows by executing commands on the Android OS.
ModificadaCrítica (9.8)1.2%—Dten D5 FirmwareDten D7 Firmware6/1/202017/6/2026
On DTEN D5 and D7 before 1.3.4 devices, factory settings allows for firmware reflash and Android Debug Bridge (adb) enablement.
ModificadaBaja (3.5)0.78%—Y-cam Ycb004 FirmwareY-cam Ycb002 FirmwareY-cam Yck002 FirmwareY-cam Yck003 Firmware+1414/5/201517/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware…
ModificadaMedia (6.8)1.3%—Y-cam Yceb03 FirmwareY-cam Ycb004 FirmwareY-cam Ycb002 FirmwareY-cam Ycbl03 Firmware+1414/5/201517/6/2026
Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote authenticated users to…
ModificadaMedia (5)1.5%—Y-cam Ycb002 FirmwareY-cam Ycb004 FirmwareY-cam Ycw003 FirmwareY-cam Ycb001 Firmware+1414/5/201517/6/2026
Y-Cam camera models SD range YCB003, YCK003, and YCW003; S range YCB004, YCK004, YCW004; EyeBall YCEB03; Bullet VGA YCBL03 and YCBLB3; Bullet HD 720 YCBLHD5; Y-cam Classic Range YCB002, YCK002, and YCW003; and Y-cam Original Range YCB001, YCW001, running firmware 4.30 and earlier, allow remote attackers to bypass…