Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2567▼ 298 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.9) | 3.4% | — | F-logic Datacube3 Firmware | 24/7/2024 | 17/6/2026 | A vulnerability was found in F-logic DataCube3 1.0. It has been declared as critical. Affected by this vulnerability is an unknown functionality of the file /admin/config_time_sync.php of the component HTTP POST Request Handler. The manipulation of the argument ntp_server leads to os command injection. The attack can… | |
| Analizada | Crítica (9.8) | 13% | — | F-logic Datacube3 Firmware | 28/5/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is vulnerable to File Upload via `/admin/transceiver_schedule.php.` | |
| Analizada | Media (6.3) | 1.6% | — | F-logic Datacube3 Firmware | 28/5/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is affected by command injection due to improper string filtering at the command execution point in the ./admin/transceiver_schedule.php file. An unauthenticated remote attacker can exploit this vulnerability by sending a file name containing command injection. Successful exploitation of this… | |
| Analizada | Crítica (9.8) | 19% | — | F-logic Datacube3 Firmware | 19/4/2024 | 17/6/2026 | SQL injection vulnerability in f-logic datacube3 v.1.0 allows a remote attacker to obtain sensitive information via the req_id parameter. | |
| Analizada | Crítica (9.8) | 2.8% | — | F-logic Datacube3 | 29/2/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is vulnerable to unauthenticated SQL injection, which could allow an unauthenticated malicious actor to execute arbitrary SQL queries in database. | |
| Modificada | Alta (8.8) | 13% | — | F-logic Datacube3 | 29/2/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is vulnerable to unrestricted file upload, which could allow an authenticated malicious actor to upload a file of dangerous type by manipulating the filename extension. | |
| Analizada | Media (5.4) | 0.55% | — | F-logic Datacube3 | 29/2/2024 | 17/6/2026 | F-logic DataCube3 Version 1.0 is affected by a reflected cross-site scripting (XSS) vulnerability due to improper input sanitization. An authenticated, remote attacker can execute arbitrary JavaScript code in the web management interface. | |
| Analizada | Crítica (9.8) | 24% | — | F-logic Datacube3 Firmware | 29/2/2024 | 17/6/2026 | F-logic DataCube3 v1.0 is vulnerable to Incorrect Access Control due to an improper directory access restriction. An unauthenticated, remote attacker can exploit this, by sending a URI that contains the path of the configuration file. A successful exploit could allow the attacker to extract the root and admin password. |