Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2564▼ 301 respecto a la semana anterior
Críticas / altas1351▲ 99 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.1) | 0.27% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Analizada | Alta (7.4) | 0.35% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic | |
| Analizada | Alta (7.5) | 0.42% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service | |
| Analizada | Crítica (9.8) | 0.52% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass | |
| Analizada | Crítica (9.8) | 0.47% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function | |
| Analizada | Crítica (9.8) | 0.60% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE |