Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3064▲ 586 respecto a la semana anterior
Críticas / altas1461▲ 295 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
–

14 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.7)0.47%—Rust-iot-platformAI29/8/202623/9/2026
rust-iot-platform through commit 5df942ab stores user passwords in cleartext without hashing in the user model. Attackers can read API responses from user retrieval and listing routes to obtain plaintext credentials for all accounts.
AplazadaCrítica (9.3)0.83%—Rust-iot-platformAI29/8/202623/9/2026
rust-iot-platform through commit 5df942ab contains an authentication bypass vulnerability where most REST API routes lack authentication guards in their handler signatures. Unauthenticated attackers can create, update, list, retrieve, and delete user accounts by directly accessing unprotected endpoints without…
AplazadaCrítica (9.8)0.66%—Rust-iot-platformAI5/8/202626/8/2026
rust-iot-platform allows creating a "calc rule" via POST /calc-rule/create (api/src/controller/calc_rule_router.rs) containing an arbitrary field. This route does not take the AuthToken request guard used elsewhere in the application, making it reachable without authentication.
AplazadaCrítica (9.1)0.42%—Rust-iot-platformAI5/8/202626/8/2026
rust-iot-platform's AuthToken request-guard implementation (api/src/main.rs) only checks whether the Authorization HTTP header is present, and never validates its value against any session, token store, or signature. Any request carrying an arbitrary non-empty Authorization header (e.g. ) satisfies the guard, granting…
AplazadaAlta (8.8)0.29%—Boodskap IOT PlatformAI22/9/202517/6/2026
Lack of server-side authorisation on department admin assignment APIs in AiKaan IoT Platform allows authenticated users to elevate their privileges by assigning themselves as admins of other departments. This results in unauthorized privilege escalation across the department
AnalizadaAlta (7.5)0.80%—IBM Watson IOT Platform29/2/202417/6/2026
An unauthorized attacker who has obtained an IBM Watson IoT Platform 1.0 security authentication token can use it to impersonate an authorized platform user. IBM X-Force ID: 261201.
ModificadaMedia (6.5)0.61%—Boodskap IOT Platform13/10/202217/6/2026
Boodskap IoT Platform v4.4.9-02 allows attackers to make unauthenticated API requests.
ModificadaAlta (8.8)0.84%—Boodskap IOT Platform13/10/202217/6/2026
Boodskap IoT Platform v4.4.9-02 allows attackers to escalate privileges via a crafted request sent to /api/user/upsert/<uuid>.
ModificadaMedia (5.4)0.48%—Boodskap IOT Platform13/10/202217/6/2026
Boodskap IoT Platform v4.4.9-02 contains a cross-site scripting (XSS) vulnerability.
ModificadaAlta (7.2)0.87%—Resiot IOT Platform AND Lorawan Network Server13/10/202217/6/2026
SQL injection vulnerability in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via a crafted POST request to /ResiotQueryDBActive.
ModificadaMedia (5.4)0.48%—Resiot IOT Platform AND Lorawan Network Server13/10/202217/6/2026
Multiple Cross Site Scripting (XSS) vulnerabilities in ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 via the form fields.
ModificadaAlta (8.8)0.45%—Resiot IOT Platform AND Lorawan Network Server13/10/202217/6/2026
Cross Site Request Forgery (CSRF) vulnerability in ResIOT ResIOT IOT Platform + LoRaWAN Network Server through 4.1.1000114 allows attackers to add new admin users to the platform or other unspecified impacts.
ModificadaCrítica (9.8)4.5%—IBM IOT MessagesightIBM Watson IOT Platform - Message Gateway28/1/202017/6/2026
IBM Watson IoT Message Gateway 2.0.0.x, 5.0.0.0, 5.0.0.1, and 5.0.0.2 is vulnerable to a buffer overflow, caused by improper bounds checking when handling a failed HTTP request with specific content in the headers. By sending a specially crafted HTTP request, a remote attacker could overflow a buffer and execute…
ModificadaAlta (8.8)3.5%—Cybervision KAA IOT Platform6/5/201717/6/2026
A Code Injection issue was discovered in CyberVision Kaa IoT Platform, Version 0.7.4. An insufficient-encapsulation vulnerability has been identified, which may allow remote code execution.