Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2623▼ 224 respecto a la semana anterior
Críticas / altas1384▲ 157 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 472 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.2) | 2.7% | — | Lynxtechnology Twonky Server | 19/11/2025 | 17/6/2026 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to a cryptographic flaw, use of hard-coded cryptographic keys. An attacker with knowledge of the encrypted administrator password can decrypt the value with static keys to view the plain text password and gain administrator-level access to Twonky Server. | |
| Analizada | Crítica (9.3) | 32% | — | Lynxtechnology Twonky Server | 19/11/2025 | 17/6/2026 | Twonky Server 8.5.2 on Linux and Windows is vulnerable to an access control flaw. An unauthenticated attacker can bypass web service API authentication controls to leak a log file and read the administrator's username and encrypted password. | |
| Aplazada | Alta (8.7) | 0.31% | — | General Industrial Controls Lynx Plus GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is vulnerable to a cleartext transmission vulnerability that could allow an attacker to observe network traffic to obtain sensitive information, including plaintext credentials. | |
| Aplazada | Alta (8.7) | 0.37% | — | General Industrial Controls Lynx+ GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to send GET requests to obtain sensitive device information. | |
| Aplazada | Crítica (9.2) | 0.63% | — | General Industrial Controls Lynx+ GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is missing critical authentication in the embedded web server which could allow an attacker to remotely reset the device. | |
| Aplazada | Alta (8.8) | 0.28% | — | General Industrial Controls Lynx Plus GatewayAI | 15/11/2025 | 17/6/2026 | General Industrial Controls Lynx+ Gateway is vulnerable to a weak password requirement vulnerability, which may allow an attacker to execute a brute-force attack resulting in unauthorized access and login. | |
| Analizada | Alta (8.7) | 0.48% | — | Westermo L210-f2g Lynx Firmware | 20/6/2024 | 17/6/2026 | An attacker may be able to cause a denial-of-service condition by sending many packets repeatedly. | |
| Modificada | Crítica (9.8) | 0.45% | — | Lynx-technik Yellobrik PEC 1864 Firmware | 6/4/2023 | 17/6/2026 | Yellobrik PEC-1864 implements authentication checks via javascript in the frontend interface. When the device can be accessed over the network an attacker could bypass authentication. This would allow an attacker to : - Change the password, resulting in a DOS of the users - Change the streaming source, compromising… | |
| Modificada | Media (5.3) | 4.1% | — | Lynx Project LynxDebian LinuxFedoraproject Fedora | 7/8/2021 | 17/6/2026 | Lynx through 2.8.9 mishandles the userinfo subcomponent of a URI, which allows remote attackers to discover cleartext credentials because they may appear in SNI data. | |
| Modificada | Media (5.4) | 0.51% | — | Versiant Lynx Customer Service Portal | 30/3/2020 | 17/6/2026 | Versiant LYNX Customer Service Portal (CSP), version 3.5.2, is vulnerable to stored cross-site scripting, which could allow a local, authenticated attacker to insert malicious JavaScript that is stored and displayed to the end user. This could lead to website redirects, session cookie hijacking, or information… | |
| Modificada | Media (6.1) | 1.4% | — | Lynxtechnology Twonky Server | 8/6/2018 | 17/6/2026 | Twonky Server before 8.5.1 has XSS via a modified "language" parameter in the Language section. | |
| Modificada | Media (6.1) | 0.68% | — | Lynxtechnology Twonky Server | 8/6/2018 | 17/6/2026 | Twonky Server before 8.5.1 has XSS via a folder name on the Shared Folders screen. | |
| Modificada | Media (6.1) | 2.3% | — | Lynxtechnology Twonky Server | 30/3/2018 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to inject arbitrary web script or HTML via the friendlyname parameter to rpc/set_all. | |
| Modificada | Alta (7.5) | 28% | — | Lynxtechnology Twonky Server | 30/3/2018 | 17/6/2026 | Directory traversal vulnerability in Twonky Server 7.0.11 through 8.5 allows remote attackers to share the contents of arbitrary directories via a .. (dot dot) in the contentbase parameter to rpc/set_all. | |
| Modificada | Alta (7.8) | 0.52% | — | Lynx Project Lynx | 10/1/2018 | 17/6/2026 | The lynx gem before 1.0.0 for Ruby places the configured password on command lines, which allows local users to obtain sensitive information by listing processes. | |
| Modificada | Media (5.3) | 1.7% | — | Lynx Project Lynx | 17/11/2017 | 17/6/2026 | Lynx before 2.8.9dev.16 is vulnerable to a use after free in the HTML parser resulting in memory disclosure, because HTML_put_string() can append a chunk onto itself. | |
| Modificada | Crítica (9.8) | 2.4% | — | Gotrango Apex Lynx FirmwareGotrango Apex Orion FirmwareGotrango Giga Lynx FirmwareGotrango Giga Orion Firmware+1 | 30/3/2017 | 17/6/2026 | Trango ApexLynx 2.0, ApexOrion 2.0, GigaLynx 2.0, GigaOrion 2.0, and StrataLink 3.0 devices have a built-in, hidden root account, with a default password for which the MD5 hash value is public (but the cleartext value is perhaps not yet public). This account is accessible via SSH and/or TELNET, and grants access to… | |
| Modificada | Crítica (9.8) | 1.7% | — | Gotrango Apex Plus FirmwareGotrango Apex FirmwareGotrango Apex Lynx FirmwareGotrango Apex Orion Firmware+7 | 30/3/2017 | 17/6/2026 | Trango Apex <= 2.1.1, ApexLynx < 2.0, ApexOrion < 2.0, ApexPlus <= 3.2.0, Giga <= 2.6.1, GigaLynx < 2.0, GigaOrion < 2.0, GigaPlus <= 3.2.3, GigaPro <= 1.4.1, StrataLink < 3.0, and StrataPro devices have a built-in, hidden root account, with a default password that was once stored in cleartext within a software update… | |
| Modificada | Crítica (9.8) | 1.7% | — | Lynxspring Jenesys BAS Bridge | 13/2/2017 | 17/6/2026 | An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application's database lacks sufficient safeguards for protecting credentials. | |
| Modificada | Alta (8.8) | 0.64% | — | Lynxspring Jenesys BAS Bridge | 13/2/2017 | 17/6/2026 | An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application does not sufficiently verify if a request was intentionally provided by the user who submitted the request (CROSS-SITE REQUEST FORGERY). | |
| Modificada | Alta (8.6) | 1.7% | — | Lynxspring Jenesys BAS Bridge | 13/2/2017 | 17/6/2026 | An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. The application uses a hard-coded username with no password allowing an attacker into the system without authentication. | |
| Modificada | Alta (7.1) | 0.94% | — | Lynxspring Jenesys BAS Bridge | 13/2/2017 | 17/6/2026 | An issue was discovered in Lynxspring JENEsys BAS Bridge versions 1.1.8 and older. A user with read-only access can send commands to the software and the application will accept those commands. This would allow an attacker with read-only access to make changes within the application. | |
| Modificada | Alta (7.5) | 2.0% | — | Lynx | 22/12/2016 | 17/6/2026 | lynx: It was found that Lynx doesn't parse the authority component of the URL correctly when the host name part ends with '?', and could instead be tricked into connecting to a different host. | |
| Modificada | Alta (7.5) | 1.6% | — | I-gen Oplynx | 31/12/2012 | 16/6/2026 | The Central application in i-GEN opLYNX before 2.01.9 allows remote attackers to bypass authentication via vectors involving the disabling of browser JavaScript support. | |
| Modificada | Media (5.9) | 0.81% | — | LynxCanonical Ubuntu Linux | 4/11/2012 | 16/6/2026 | Lynx does not verify that the server's certificate is signed by a trusted certification authority, which allows man-in-the-middle attackers to spoof SSL servers via a crafted certificate, related to improper use of a certain GnuTLS function. |