Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2860▼ 165 respecto a la semana anterior
Críticas / altas1382▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)272▼ 254 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.29% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can gain persistent XSS via POST requests due to improper neutralization of special elements used to create dynamic content. | |
| Analizada | Alta (7.5) | 0.66% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | An unauthenticated remote attacker could exploit a buffer overflow vulnerability in the device causing a denial of service that affects only the network initializing wizard (Conftool) service. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can alter the configuration database via POST requests due to improper neutralization of special elements used in a SQL statement. | |
| Analizada | Media (4.9) | 0.58% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-mail action in fast succession. | |
| Analizada | Media (4.9) | 0.55% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can exhaust critical system resources by sending specifically crafted POST requests to the send-sms action in fast succession. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via GET requests in the cloud server communication script due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the diagnostic action due to improper neutralization of special elements used in an OS command. | |
| Analizada | Alta (7.2) | 0.61% | — | Mbconnectline Mbnet.mini Firmware | 21/7/2025 | 17/6/2026 | A high privileged remote attacker can execute arbitrary system commands via POST requests in the send_sms action due to improper neutralization of special elements used in an OS command. | |
| Modificada | Alta (7.5) | 0.63% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated remote attacker can get read access to files in the "/tmp" directory due to missing authentication. | |
| Modificada | Crítica (9.8) | 0.80% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | The devices contain two hard coded user accounts with hardcoded passwords that allow an unauthenticated remote attacker for full control of the affected devices. | |
| Modificada | Crítica (9.8) | 1.5% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated remote attacker can execute OS commands via UDP on the device due to missing authentication. | |
| Modificada | Alta (7.8) | 0.09% | — | Mbconnectline Mbnet.mini FirmwareHelmholz Myrex24 V2 Virtual ServerHelmholz REX 300 FirmwareHelmholz REX 200 Firmware+11 | 15/10/2024 | 17/6/2026 | An unauthenticated local attacker can decrypt the devices config file and therefore compromise the device due to a weak implementation of the encryption used. | |
| Modificada | Alta (7.8) | 0.31% | — | Mbconnectline Mbnet.mini FirmwareHelmholz REX 100 Firmware | 15/10/2024 | 17/6/2026 | An unauthenticated local attacker can gain admin privileges by deploying a config file due to improper input validation. |