Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.1) | 0.24% | — | MY Excitel APPAI | 24/2/2025 | 17/6/2026 | A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component One-Time Password Handler. The manipulation leads to improper restriction of excessive authentication attempts. The vendor was contacted early… | |
| Modificada | Crítica (9.3) | 0.47% | — | Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware | 27/6/2024 | 17/6/2026 | TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions. | |
| Modificada | Crítica (9.3) | 0.57% | — | Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware | 27/6/2024 | 17/6/2026 | TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges. | |
| Modificada | Crítica (9.3) | 0.52% | — | Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware | 27/6/2024 | 17/6/2026 | TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials. | |
| Modificada | Crítica (9.3) | 1.2% | — | Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware | 27/6/2024 | 17/6/2026 | TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges. | |
| Modificada | Alta (7.2) | 0.37% | — | Excite EWS | 30/11/1998 | 16/6/2026 | Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack. | |
| Modificada | Alta (7.2) | 0.35% | — | Excite EWS | 30/11/1998 | 16/6/2026 | Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file. | |
| Modificada | Alta (7.2) | 0.42% | — | Excite EWS | 30/11/1998 | 16/6/2026 | Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi. | |
| Modificada | Alta (7.5) | 3.9% | — | Excite EWS | 1/1/1998 | 16/6/2026 | Excite for Web Servers (EWS) allows remote command execution via shell metacharacters. |