Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2557▼ 320 respecto a la semana anterior
Críticas / altas1342▲ 78 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.24%—MY Excitel APPAI24/2/202517/6/2026
A vulnerability was found in Excitel Broadband Private my Excitel App 3.13.0 on Android. It has been classified as problematic. Affected is an unknown function of the component One-Time Password Handler. The manipulation leads to improper restriction of excessive authentication attempts. The vendor was contacted early…
ModificadaCrítica (9.3)0.47%—Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware27/6/202417/6/2026
TELSAT marKoni FM Transmitters are vulnerable to users gaining unauthorized access to sensitive information or performing actions beyond their designated permissions.
ModificadaCrítica (9.3)0.57%—Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware27/6/202417/6/2026
TELSAT marKoni FM Transmitters are vulnerable to an attacker bypassing authentication and gaining administrator privileges.
ModificadaCrítica (9.3)0.52%—Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware27/6/202417/6/2026
TELSAT marKoni FM Transmitters are vulnerable to an attacker exploiting a hidden admin account that can be accessed through the use of hard-coded credentials.
ModificadaCrítica (9.3)1.2%—Markoni-d (compact) FirmwareMarkoni-dh (exciter+amplifiers) Firmware27/6/202417/6/2026
TELSAT marKoni FM Transmitters are vulnerable to a command injection vulnerability through the manipulation of settings and could allow an attacker to gain unauthorized access to the system with administrative privileges.
ModificadaAlta (7.2)0.37%—Excite EWS30/11/199816/6/2026
Excite for Web Servers (EWS) 1.1 records the first two characters of a plaintext password in the beginning of the encrypted password, which makes it easier for an attacker to guess passwords via a brute force or dictionary attack.
ModificadaAlta (7.2)0.35%—Excite EWS30/11/199816/6/2026
Excite for Web Servers (EWS) 1.1 installs the Architext.conf authentication file with world-writeable permissions, which allows local users to gain access to Excite accounts by modifying the file.
ModificadaAlta (7.2)0.42%—Excite EWS30/11/199816/6/2026
Excite for Web Servers (EWS) 1.1 allows local users to gain privileges by obtaining the encrypted password from the world-readable Architext.conf authentication file and replaying the encrypted password in an HTTP request to AT-generated.cgi or AT-admin.cgi.
ModificadaAlta (7.5)3.9%—Excite EWS1/1/199816/6/2026
Excite for Web Servers (EWS) allows remote command execution via shell metacharacters.