Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2865▼ 160 respecto a la semana anterior
Críticas / altas1384▲ 52 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)266▼ 260 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.4) | 0.40% | — | Unitree GO2 Firmware | 26/2/2026 | 17/6/2026 | Unitree Go2 firmware versions 1.1.7 through 1.1.11, when used with the Unitree Go2 Android application (com.unitree.doggo2), are vulnerable to remote code execution due to missing integrity protection and validation of user-created programmes. The Android application stores programs in a local SQLite database… | |
| Modificada | Alta (8.5) | 0.44% | — | Unitree GO2 FirmwareUnitree GO2 EDU Firmware | 26/2/2026 | 17/6/2026 | Unitree Go2 firmware versions V1.1.7 through V1.1.9, and V1.1.11 (EDU) do not implement DDS authentication or authorization for the Eclipse CycloneDDS topic rt/api/programming_actuator/request handled by actuator_manager.py. A network-adjacent, unauthenticated attacker can join DDS domain 0 and publish a crafted… | |
| Analizada | Alta (7.3) | 2.7% | — | Unitree G1 FirmwareUnitree GO2 FirmwareUnitree H1 FirmwareUnitree B2 Firmware | 26/9/2025 | 17/6/2026 | Multiple robotic products by Unitree sharing a common firmware, including the Go2, G1, H1, and B2 devices, contain a command injection vulnerability. By setting a malicious string when configuring the on-board WiFi via a BLE module of an affected robot, then triggering a restart of the WiFi service, an attacker can… | |
| Modificada | Alta (7.8) | 0.35% | — | Kramerav VIA GO2 FirmwareKramerav VIA Connect2 Firmware | 9/8/2023 | 9/7/2026 | In instances where the screen is visible and remote mouse connection is enabled, KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 can be exploited to achieve local code execution at the root level. | |
| Modificada | Crítica (9.1) | 0.76% | — | Kramerav VIA GO2 FirmwareKramerav VIA Connect2 Firmware | 9/8/2023 | 9/7/2026 | KramerAV VIA Connect (2) and VIA Go (2) devices with a version prior to 4.0.1.1326 exhibit a vulnerability that enables remote manipulation of the device. This vulnerability involves extracting the connection confirmation code remotely, bypassing the need to obtain it directly from the physical screen. | |
| Modificada | Crítica (9.8) | 0.76% | — | Kramerav VIA GO2 Firmware | 31/5/2023 | 17/6/2026 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to SQL Injection. | |
| Modificada | Crítica (9.8) | 1.4% | — | Kramerav VIA GO2 Firmware | 31/5/2023 | 17/6/2026 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to unauthenticated file upload resulting in Remote Code Execution (RCE). | |
| Modificada | Alta (7.5) | 0.70% | — | Kramerav VIA GO2 Firmware | 31/5/2023 | 17/6/2026 | KramerAV VIA GO² < 4.0.1.1326 is vulnerable to Unauthenticated arbitrary file read. |