Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2751▲ 29 respecto a la semana anterior
Críticas / altas1468▲ 334 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)85▼ 441 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Crítica (9.8) | 7.0% | — | RVR Tex30lcd/s FirmwareRVR Tex50lcd/s FirmwareRVR Tex100lcd/s FirmwareRVR Tex150lcd/s Firmware+7 | 19/11/2025 | 17/6/2026 | The R.V.R Elettronica TEX product (firmware TEXL-000400, Web GUI TLAN-000400) is vulnerable to broken access control due to improper authentication checks on the /_Passwd.html endpoint. An attacker can send an unauthenticated POST request to change the Admin, Operator, and User passwords, resulting in complete system… | |
| Aplazada | Media (5.3) | 0.26% | — | Exagid Ex10AI | 21/8/2025 | 17/6/2026 | An XML external entities (XXE) injection vulnerability in the /init API endpoint in Exagid EX10 before 6.4.0 P20, 7.0.1 P12, and 7.2.0 P08 allows an authenticated, unprivileged attacker to achieve information disclosure and privilege escalation via a crafted ISys XML message. | |
| Aplazada | Alta (7.3) | 0.29% | — | Exagrid Ex10AI | 31/7/2025 | 17/6/2026 | ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control. Since version 6.3, ExaGrid enforces restrictions preventing users with the Admin role from creating or modifying users with the Security Officer role without approval. However, a flaw in the account creation process allows an attacker to bypass… | |
| Aplazada | Media (5.4) | 0.22% | — | Exagrid Ex10AI | 31/7/2025 | 17/6/2026 | ExaGrid EX10 6.3 - 7.0.1.P08 is vulnerable to Incorrect Access Control in the MailConfiguration API endpoint, where users with operator-level privileges can issue an HTTP request to retrieve SMTP credentials, including plaintext passwords. | |
| Modificada | Alta (7.5) | 74% | — | Exagrid Ex3000 FirmwareExagrid Ex5000 FirmwareExagrid Ex7000 FirmwareExagrid Ex10000e Firmware+4 | 21/4/2017 | 17/6/2026 | ExaGrid appliances with firmware before 4.8 P26 have a default SSH public key in the authorized_keys file for root, which allows remote attackers to obtain SSH access by leveraging knowledge of a private key from another installation or a firmware image. | |
| Modificada | Crítica (9.8) | 72% | — | Exagrid Ex3000 FirmwareExagrid Ex5000 FirmwareExagrid Ex7000 FirmwareExagrid Ex10000e Firmware+4 | 21/4/2017 | 17/6/2026 | ExaGrid appliances with firmware before 4.8 P26 have a default password of (1) inflection for the root shell account and (2) support for the support account in the web interface, which allows remote attackers to obtain administrative access via an SSH or HTTP session. |