Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
3 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 0.83% | — | Hikvision Ds-a71024 FirmwareHikvision Ds-a71048 FirmwareHikvision Ds-a71072r FirmwareHikvision Ds-a80624s Firmware+6 | 11/4/2023 | 17/6/2026 | Some Hikvision Hybrid SAN/Cluster Storage products have an access control vulnerability which can be used to obtain the admin permission. The attacker can exploit the vulnerability by sending crafted messages to the affected devices. | |
| Modificada | Media (6.1) | 0.80% | — | Hikvision Ds-a71024 FirmwareHikvision Ds-a71048 FirmwareHikvision Ds-a71072r FirmwareHikvision Ds-a80624s Firmware+7 | 27/6/2022 | 17/6/2026 | The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to XSS attack by sending messages with malicious commands to the affected device. | |
| Modificada | Crítica (9.8) | 52% | — | Hikvision Ds-a71024 FirmwareHikvision Ds-a71048 FirmwareHikvision Ds-a71072r FirmwareHikvision Ds-a80624s Firmware+7 | 27/6/2022 | 17/6/2026 | The web module in some Hikvision Hybrid SAN/Cluster Storage products have the following security vulnerability. Due to the insufficient input validation, attacker can exploit the vulnerability to execute restricted commands by sending messages with malicious commands to the affected device. |