Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
–

46 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.2)2.7%—Lynxtechnology Twonky Server19/11/202517/6/2026
Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server.
AnalizadaCrítica (9.3)32%—Lynxtechnology Twonky Server19/11/202517/6/2026
Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password.
AplazadaAlta (8.7)0.31%—General Industrial Controls Lynx Plus GatewayAI15/11/202517/6/2026
General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials.
AplazadaAlta (8.7)0.37%—General Industrial Controls Lynx+ GatewayAI15/11/202517/6/2026
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information.
AplazadaCrítica (9.2)0.63%—General Industrial Controls Lynx+ GatewayAI15/11/202517/6/2026
General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device.
AplazadaAlta (8.8)0.28%—General Industrial Controls Lynx Plus GatewayAI15/11/202517/6/2026
General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login.
AnalizadaAlta (8.7)0.48%—Westermo L210-f2g Lynx Firmware20/6/202417/6/2026
An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly.
ModificadaCrítica (9.8)0.45%—Lynx-technik Yellobrik PEC 1864 Firmware6/4/202317/6/2026
Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users - Change the streaming source, compromising…
ModificadaMedia (5.3)4.1%—Lynx Project LynxDebian LinuxFedoraproject Fedora7/8/202117/6/2026
Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data.
ModificadaMedia (5.4)0.51%—Versiant Lynx Customer Service Portal30/3/202017/6/2026
Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information…
ModificadaMedia (6.1)1.4%—Lynxtechnology Twonky Server8/6/201817/6/2026
Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section.
ModificadaMedia (6.1)0.68%—Lynxtechnology Twonky Server8/6/201817/6/2026
Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen.
ModificadaMedia (6.1)2.3%—Lynxtechnology Twonky Server30/3/201817/6/2026
Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all.
ModificadaAlta (7.5)28%—Lynxtechnology Twonky Server30/3/201817/6/2026
Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all.
ModificadaAlta (7.8)0.52%—Lynx Project Lynx10/1/201817/6/2026
The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes.
ModificadaMedia (5.3)1.7%—Lynx Project Lynx17/11/201717/6/2026
Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself.
ModificadaCrítica (9.8)2.4%—Gotrango Apex Lynx FirmwareGotrango Apex Orion FirmwareGotrango Giga Lynx FirmwareGotrango Giga Orion Firmware+130/3/201717/6/2026
Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to…
ModificadaCrítica (9.8)1.7%—Gotrango Apex Plus FirmwareGotrango Apex FirmwareGotrango Apex Lynx FirmwareGotrango Apex Orion Firmware+730/3/201717/6/2026
Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update…
ModificadaCrítica (9.8)1.7%—Lynxspring Jenesys BAS Bridge13/2/201717/6/2026
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials.
ModificadaAlta (8.8)0.64%—Lynxspring Jenesys BAS Bridge13/2/201717/6/2026
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request (CROSS-SITE REQUEST FORGERY).
ModificadaAlta (8.6)1.7%—Lynxspring Jenesys BAS Bridge13/2/201717/6/2026
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication.
ModificadaAlta (7.1)0.94%—Lynxspring Jenesys BAS Bridge13/2/201717/6/2026
An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and the application will accept those commands. This would allow an attacker with read-only access to make changes within the application.
ModificadaAlta (7.5)2.0%—Lynx22/12/201617/6/2026
lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host.
ModificadaAlta (7.5)1.6%—I-gen Oplynx31/12/201216/6/2026
The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support.
ModificadaMedia (5.9)0.81%—LynxCanonical Ubuntu Linux4/11/201216/6/2026
Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS function.