Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaAlta (8.9)0.58%—SocialstreamAILaravel JetstreamAILaravel SocialiteAI20/12/202417/6/2026
Socialstream is a third-party package for Laravel Jetstream. It replaces the published authentication and profile scaffolding provided by Laravel Jetstream, with scaffolding that has support for Laravel Socialite. When linking a social account to an already authenticated user, the lack of a confirmation step…
ModificadaMedia (6.5)0.83%—Jetstream Jetselect14/5/202017/6/2026
An issue was discovered in all versions of Bond JetSelect. Within the JetSelect Application, the web interface hides RADIUS secrets, WPA passwords, and SNMP strings from 'non administrative' users using HTML 'password field' obfuscation. By using Developer tools or similar, it is possible to change the obfuscation so…
ModificadaCrítica (9.8)1.3%—Jetstream Jetselect14/5/202017/6/2026
Bond JetSelect (all versions) has an issue in the Java class (ENCtool.jar) and corresponding password generation algorithm (used to set initial passwords upon first installation). It XORs the plaintext into the 'encrypted' password that is then stored within the database. These steps are able to be trivially reversed,…
ModificadaMedia (6.5)0.60%—Jetstream Jetselect14/5/202017/6/2026
The administrative passwords for all versions of Bond JetSelect are stored within an unprotected file on the filesystem, rather than encrypted within the MySQL database. This backup copy of the passwords is made as part of the installation script, after the administrator has generated a password using ENCtool.jar (see…
ModificadaAlta (7.5)1.7%—Wavlink Wl-wn575a3 FirmwareWavlink Wl-wn579g3 FirmwareWavlink Wn531a6 FirmwareWavlink Wn535g3 Firmware+97/5/202017/6/2026
An issue was discovered affecting a backup feature where a crafted POST request returns the current configuration of the device in cleartext, including the administrator password. No authentication is required. Affected devices: Wavlink WN575A3, Wavlink WN579G3, Wavlink WN531A6, Wavlink WN535G3, Wavlink WN530H4,…
ModificadaAlta (7.5)1.8%—Wavlink Wl-wn579g3 FirmwareWavlink Wl-wn575a3 FirmwareWavlink Wl-wn530hg4 FirmwareWavlink Wn531g3 Firmware+1127/4/202017/6/2026
An issue was discovered where there are multiple externally accessible pages that do not require any sort of authentication, and store system information for internal usage. The devices automatically query these pages to update dashboards and other statistics, but the pages can be accessed externally without any…