Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 237 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

8 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)1.8%—Uffizio GPS Tracker16/12/202317/6/2026
A Remote Code Execution vulnerability exist in Uffizio's GPS Tracker all versions. The web server can be compromised by uploading and executing a web/reverse shell. An attacker could then run commands, browse system files, and browse local resources
ModificadaMedia (6.1)0.49%—Uffizio GPS Tracker16/12/202317/6/2026
An Open Redirection vulnerability exists in Uffizio's GPS Tracker all versions allows an attacker to construct a URL within the application that causes a redirection to an arbitrary external domain.
ModificadaAlta (7.5)0.84%—Uffizio GPS Tracker16/12/202317/6/2026
An improper access control vulnerability exists in Uffizio's GPS Tracker all versions that lead to sensitive information disclosure of all the connected devices. By visiting the vulnerable host at port 9000, we see it responds with a JSON body that has all the details about the devices which have been deployed.
ModificadaAlta (8.8)0.41%—Uffizio GPS Tracker22/4/202217/6/2026
All versions of Uffizio GPS Tracker may allow an attacker to perform unintended actions on behalf of a user.
ModificadaMedia (6.1)0.60%—Uffizio GPS Tracker22/4/202217/6/2026
An attacker may be able to inject client-side JavaScript code on multiple instances within all versions of Uffizio GPS Tracker.
ModificadaAlta (7.5)0.49%—Eviewgps Ev-07s GPS Tracker Firmware27/3/201717/6/2026
Due to a lack of standard encryption when transmitting sensitive information over the internet to a centralized monitoring service, the Eview EV-07S GPS Tracker discloses personally identifying information, such as GPS data and IMEI numbers, to any man-in-the-middle (MitM) listener.
ModificadaMedia (5.3)0.89%—Eviewgps Ev-07s GPS Tracker Firmware27/3/201717/6/2026
Due to a lack of bounds checking, several input configuration fields for the Eview EV-07S GPS Tracker will overflow data stored in one variable to another, overwriting the data of another field.
ModificadaAlta (7.5)2.0%—Eviewgps Ev-07s GPS Tracker Firmware27/3/201717/6/2026
Due to a lack of authentication, an unauthenticated user who knows the Eview EV-07S GPS Tracker's phone number can revert the device to a factory default configuration with an SMS command, "RESET!"