Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

6 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaCrítica (9.8)64%—LG LED Assistant25/3/202417/6/2026
This vulnerability allows remote attackers to traverse paths via file upload on the affected LG LED Assistant.
AnalizadaCrítica (9.8)51%—LG LED Assistant25/3/202417/6/2026
This vulnerability allows remote attackers to reset the password of anonymous users without authorization on the affected LG LED Assistant.
ModificadaAlta (7.5)1.6%—LG LED Assistant4/9/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/thumbnail endpoint. The issue results from the lack of proper validation of a user-supplied…
ModificadaAlta (7.5)1.6%—LG LED Assistant4/9/202317/6/2026
This vulnerability allows remote attackers to disclose sensitive information on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/download/updateFile endpoint. The issue results from the lack of proper validation of a…
ModificadaCrítica (9.8)2.5%—LG LED Assistant4/9/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/installation/setThumbnailRc endpoint. The issue results from the lack of proper validation of a…
ModificadaCrítica (9.8)2.5%—LG LED Assistant4/9/202317/6/2026
This vulnerability allows remote attackers to execute arbitrary code on affected installations of LG LED Assistant. Authentication is not required to exploit this vulnerability. The specific flaw exists within the /api/settings/upload endpoint. The issue results from the lack of proper validation of a user-supplied…