Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2682▼ 88 respecto a la semana anterior
Críticas / altas1443▲ 300 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (7.5)0.31%—Flocksafety License Plate Reader Firmware2/10/202517/6/2026
Flock Safety Falcon and Sparrow License Plate Readers OPM1.171019.026 ship with development Wi-Fi credentials (test_flck) stored in cleartext in production firmware.
AnalizadaCrítica (9.8)0.67%—Flocksafety Flock Safety2/10/202517/6/2026
The Flock Safety DetectionProcessing com.flocksafety.android.objects application 6.35.33 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) bundles a Java Keystore (flock_rye.bks) along with its hardcoded password (flockhibiki17) in its code. The keystore contains a…
AnalizadaMedia (6.2)0.17%—Flocksafety Flock Safety2/10/202517/6/2026
The Flock Safety Pisco com.flocksafety.android.pisco application 6.21.11 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) has a cleartext Auth0 client secret in its codebase. Because application binaries can be trivially decompiled or inspected, attackers can…
AnalizadaAlta (7.5)0.47%—Flocksafety Flock Safety2/10/202517/6/2026
The Flock Safety Peripheral com.flocksafety.android.peripheral application 7.38.3 for Android (installed on Falcon and Sparrow License Plate Readers and Bravo Edge AI Compute Devices) contains a cleartext DataDog API key within in its codebase. Because application binaries can be trivially decompiled or inspected,…
ModificadaCrítica (9.8)1.1%—Flocksafety Flock Safety2/10/202517/6/2026
The Flock Safety Android Collins application (aka com.flocksafety.android.collins) 6.35.31 for Android lacks authentication. It is responsible for the camera feed on Falcon, Sparrow, and Bravo devices, but exposes administrative API endpoints on port 8080 without authentication. Endpoints include but are not limited…
AnalizadaAlta (7.3)0.25%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with Secure Boot disabled. This allows an attacker to flash modified firmware with no cryptographic protections.
AnalizadaAlta (7.5)0.43%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 ships with its bootloader unlocked. This permits bypass of Android Verified Boot (AVB) and allows direct modification of partitions.
AnalizadaMedia (5.4)0.23%—Flocksafety Bravo Compute BOX Firmware25/9/202517/6/2026
Flock Safety Bravo Edge AI Compute Device BRAVO_00.00_local_20241017 accepts the default Thundercomm TurboX 6490 Firehose loader in EDL/QDL mode. This enables attackers with physical access to flash arbitrary firmware, dump partitions, and bypass bootloader and OS security controls.
AnalizadaBaja (2.4)0.15%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have cleartext storage of code.
AnalizadaMedia (4.6)0.24%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have a hardcoded password for a system.
AnalizadaMedia (6.8)0.25%—Flocksafety License Plate Reader Firmware27/6/202517/6/2026
Flock Safety LPR (License Plate Reader) devices with firmware through 2.2 have an on-chip debug interface with improper access control.
AnalizadaMedia (4.6)0.23%—Flocksafety Gunshot Detection Firmware27/6/202517/6/2026
Flock Safety Gunshot Detection devices before 1.3 have a hardcoded password for a system.
AnalizadaBaja (2.4)0.16%—Flocksafety Gunshot Detection Firmware27/6/202517/6/2026
Flock Safety Gunshot Detection devices before 1.3 have cleartext storage of code.
AnalizadaMedia (6.8)0.26%—Flocksafety Gunshot Detection Firmware27/6/202517/6/2026
Flock Safety Gunshot Detection devices before 1.3 have an on-chip debug interface with improper access control.
AnalizadaMedia (4.6)0.24%—Flocksafety Gunshot Detection Firmware27/6/202517/6/2026
Flock Safety Gunshot Detection devices before 1.3 have a hard-coded password for a connection.
AnalizadaMedia (6.1)0.57%—Codeflock WP Desklite15/5/202517/6/2026
The WP DeskLite WordPress plugin through 1.0.0 does not sanitise and escape a parameter before outputting it back in the page, leading to a Reflected Cross-Site Scripting which could be used against high privilege users such as admin.
AplazadaAlta (8.6)0.59%—Codeflock Free Download ManagerAI17/10/202417/6/2026
Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') vulnerability in CodeFlock FREE DOWNLOAD MANAGER free-download-manager allows Path Traversal.This issue affects FREE DOWNLOAD MANAGER: from n/a through <= 1.0.0.
ModificadaMedia (4.3)1.0%—Flock20/9/201016/6/2026
Cross-site scripting (XSS) vulnerability in Flock Browser 3.x before 3.0.0.4114 allows remote attackers to inject arbitrary web script or HTML via a crafted RSS feed.
ModificadaMedia (4.3)1.4%—Flock13/9/201016/6/2026
Cross-site scripting (XSS) vulnerability in Flock Browser 3.0.0.3989 allows remote attackers to inject arbitrary web script or HTML via a crafted bookmark.
ModificadaMedia (4.3)1.4%—Google ChromeFlock1/4/201016/6/2026
The protocolIs function in platform/KURLGoogle.cpp in WebCore in WebKit before r55822, as used in Google Chrome before 4.1.249.1036 and Flock Browser 3.x before 3.0.0.4112, does not properly handle whitespace at the beginning of a URL, which allows remote attackers to conduct cross-site scripting (XSS) attacks via a…
ModificadaMedia (4.3)0.64%—FlockMozilla FirefoxMozilla Seamonkey28/8/200916/6/2026
Mozilla Firefox 3.5.1 and SeaMonkey 1.1.17, and Flock 2.5.1, allow context-dependent attackers to spoof the address bar, via window.open with a relative URI, to show an arbitrary file: URL after a victim has visited any file: URL, as demonstrated by a visit to a file: document written by the attacker.
ModificadaMedia (4.3)1.3%—Flock29/1/200716/6/2026
Flock beta 1 0.7 allows remote attackers to cause a denial of service (application crash) via a web page that contains a large number of nested marquee tags, a related issue to CVE-2006-2723.