Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaMedia (6.4)0.40%—Unitree GO2 Firmware26/2/202617/6/2026
Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLite database…
ModificadaAlta (8.5)0.44%—Unitree GO2 FirmwareUnitree GO2 EDU Firmware26/2/202617/6/2026
Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join DDS domain 0 and publish a crafted…
AnalizadaAlta (7.3)2.7%—Unitree G1 FirmwareUnitree GO2 FirmwareUnitree H1 FirmwareUnitree B2 Firmware26/9/202517/6/2026
Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can…
ModificadaAlta (7.8)0.35%—Kramerav VIA GO2 FirmwareKramerav VIA Connect2 Firmware9/8/20239/7/2026
In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level.
ModificadaCrítica (9.1)0.76%—Kramerav VIA GO2 FirmwareKramerav VIA Connect2 Firmware9/8/20239/7/2026
KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen.
ModificadaCrítica (9.8)0.76%—Kramerav VIA GO2 Firmware31/5/202317/6/2026
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection.
ModificadaCrítica (9.8)1.4%—Kramerav VIA GO2 Firmware31/5/202317/6/2026
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE).
ModificadaAlta (7.5)0.70%—Kramerav VIA GO2 Firmware31/5/202317/6/2026
KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read.