Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2838▼ 146 respecto a la semana anterior
Críticas / altas1377▲ 68 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)255▼ 268 respecto a la semana anterior
4 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.3) | 0.13% | — | Johnsoncontrols Exacqvision Server | 1/8/2024 | 17/6/2026 | Under certain circumstances the exacqVision Server will not properly validate TLS certificates provided by connected devices. | |
| Analizada | Crítica (9) | 0.44% | — | Johnsoncontrols Exacqvision ClientJohnsoncontrols Exacqvision Server | 1/8/2024 | 17/6/2026 | Under certain circumstances the communication between exacqVision Client and exacqVision Server will use insufficient key length and exchange | |
| Modificada | Alta (7.5) | 1.6% | — | Johnsoncontrols Exacqvision Server | 11/10/2021 | 17/6/2026 | An unauthenticated remote user could exploit a potential integer overflow condition in the exacqVision Server with a specially crafted script and cause denial-of-service condition. | |
| Modificada | Alta (7.8) | 0.83% | — | Johnsoncontrols Exacqvision Server | 19/7/2019 | 17/6/2026 | ExacqVision Server’s services 'exacqVisionServer', 'dvrdhcpserver' and 'mdnsresponder' have an unquoted service path. If an authenticated user is able to insert code in their system root path it potentially can be executed during the application startup. This could allow the authenticated user to elevate privileges on… |