Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2619▼ 461 respecto a la semana anterior
Críticas / altas1277▼ 72 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)235▼ 274 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (8.8)1.1%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Cross-Site Request Forgery (CSRF).
ModificadaCrítica (9.8)40%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Authenticated Command Injection with root Code Execution.
ModificadaCrítica (10)6.5%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Unauthenticated File Upload.
ModificadaCrítica (9.8)21%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Cookie Path Traversal.
ModificadaCrítica (9.8)4.6%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware2/7/201917/6/2026
Linear eMerge 50P/5000P devices allow Authentication Bypass.
ModificadaCrítica (9.8)3.6%—Nortekcontrol Linear Emerge 50P FirmwareNortekcontrol Linear Emerge 5000p Firmware1/7/201917/6/2026
Nortek Linear eMerge 50P/5000P devices have Default Credentials.
ModificadaMedia (5)1.3%—Linearcorp Emerge 50Linearcorp Emerge 500025/6/201016/6/2026
The Linear eMerge 50 and 5000 uses a default password of eMerge for the IEIeMerge account, which makes it easier for remote attackers to obtain Video Recorder data by establishing a session to the device.
ModificadaAlta (10)1.7%—S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess25/6/201016/6/2026
The S2 Security NetBox 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, uses a weak hash algorithm for storing the Administrator password, which makes it easier for context-dependent attackers to obtain privileged access by recovering the cleartext of this password.
ModificadaMedia (5)1.4%—S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess25/6/201016/6/2026
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not require setting a password for the FTP server that stores database backups, which makes it easier for remote attackers to download backup files via unspecified FTP requests.
ModificadaMedia (5)1.9%—S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess25/6/201016/6/2026
The S2 Security NetBox, possibly 2.x and 3.x, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, does not properly prevent downloading of database backups, which allows remote attackers to obtain sensitive information via requests for full_*.dar files with predictable filenames.
ModificadaMedia (5)2.5%—S2sys NetboxLinearcorp Emerge 50Linearcorp Emerge 5000Sonitrol Eaccess25/6/201016/6/2026
The S2 Security NetBox 2.5, 3.3, and 4.0, as used in the Linear eMerge 50 and 5000 and the Sonitrol eAccess, stores sensitive information under the web root with insufficient access control, which allows remote attackers to download node logs, photographs of persons, and backup files via unspecified HTTP requests.