Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2811▼ 173 respecto a la semana anterior
Críticas / altas1356▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)267▼ 256 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (6.4)0.13%—Ingenic T31AIWyze Video Doorbell V2AI19/8/20269/9/2026
The Ingenic T31 SoC boot ROM flash-boot verification path compares only a single 32-bit word of the RSA signature output against a single 32-bit word of the SHA-256 payload digest, rather than compare the full data. This allows an attacker with physical write access to boot media to forge modified SPL (Secondary…
AplazadaMedia (6.8)0.15%—Ingenic T41AIIngenic T32AIIngenic T40AIIngenic A1AI19/8/20269/9/2026
The Ingenic T41, and probably also T32, T40, and A1 SoC boot ROMs parse and execute an attacker-controlled init table from the SPL header before checking the secure boot state and before invoking signature verification. The init table parser supports full-address 32-bit write operations, allowing modification of…
AplazadaMedia (5.1)0.35%—Ingenico Estate ManagerAI30/6/202417/6/2026
A vulnerability classified as problematic was found in Ingenico Estate Manager 2023. Affected by this vulnerability is an unknown functionality of the file /emgui/rest/preferences/PREF_HOME_PAGE/sponsor/3/ of the component New Widget Handler. The manipulation of the argument URL leads to cross site scripting. The…
ModificadaMedia (5.1)0.41%—Ingenico Estate Management17/6/202417/6/2026
A vulnerability, which was classified as problematic, has been found in Ingenico Estate Manager 2023. This issue affects some unknown processing of the file /emgui/rest/ums/messages of the component News Feed. The manipulation of the argument message leads to cross site scripting. The attack may be initiated remotely.…
ModificadaMedia (6.8)0.58%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals have an insecure NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (6.8)0.60%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals have a buffer overflow via SOCKET_TASK in the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (6.8)0.67%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals allow arbitrary code execution via the TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (6.6)0.48%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals have hardcoded FTP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (6.6)0.56%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals have a buffer overflow via the RemotePutFile command of the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (6.6)0.56%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals have a buffer overflow via the 0x26 command of the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (6.8)0.58%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals have an insecure TRACE protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (6.8)0.55%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals have hardcoded PPP credentials. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (4.6)0.53%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS Telium2 OS allow bypass of file-reading restrictions via the NTPT3 protocol. This is fixed in Telium 2 SDK v9.32.03 patch N.
ModificadaMedia (6.8)0.56%—Ingenico Telium 2 Firmware9/9/202017/6/2026
Ingenico Telium 2 POS terminals have undeclared TRACE protocol commands. This is fixed in Telium 2 SDK v9.32.03 patch N.