Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2720▼ 598 respecto a la semana anterior
Críticas / altas1299▼ 202 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.41% | — | Vincent Mimoun-prat WP Pt-viewerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in Vincent Mimoun-Prat WP PT-Viewer wp-ptviewer allows Reflected XSS.This issue affects WP PT-Viewer: from n/a through <= 2.0.2. | |
| Aplazada | Media (4.3) | 0.41% | — | Mimo Woocommerce Order TrackingAI | 9/1/2025 | 17/6/2026 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on several functions in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above, to add, update, and… | |
| Aplazada | Alta (8.5) | 0.52% | — | Marti Batlles Martinez MimoosAI | 16/12/2024 | 17/6/2026 | Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection') vulnerability in Martí Batlles Martinez Mimoos devoluciones-packback allows SQL Injection.This issue affects Mimoos: from n/a through <= 1.2. | |
| Aplazada | Media (6.4) | 0.24% | — | Mimo Woocommerce Order TrackingAI | 19/6/2024 | 17/6/2026 | The MIMO Woocommerce Order Tracking plugin for WordPress is vulnerable to unauthorized modification of data due to a missing capability check on the 'mimo_update_provider' function in all versions up to, and including, 1.0.2. This makes it possible for authenticated attackers, with Subscriber-level access and above,… | |
| Aplazada | Crítica (9.4) | 12% | — | Ligowave UnityAILigowave PROAILigowave MimoAILigowave APC PropellerAI | 16/5/2024 | 17/6/2026 | A vulnerability in the web-based management interface of multiple Ligowave devices could allow an authenticated remote attacker to execute arbitrary commands with elevated privileges.This issue affects UNITY: through 6.95-2; PRO: through 6.95-1.Rt3883; MIMO: through 6.95-1.Rt2880; APC Propeller: through… | |
| Modificada | Media (6.5) | 0.52% | — | Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+1 | 18/2/2022 | 17/6/2026 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 uses the MD5 algorithm to hash the passwords before storing them but does not salt the hash. As a result, attackers may be able to crack the hashed passwords. | |
| Modificada | Crítica (9.8) | 1.4% | — | Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+1 | 18/2/2022 | 17/6/2026 | This vulnerability could allow an attacker to force the server to create and execute a web request granting access to backend APIs that are only accessible to the Mimosa MMP server, or request pages that could perform some actions themselves. The attacker could force the server into accessing routes on those… | |
| Modificada | Crítica (9.8) | 3.7% | — | Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+1 | 18/2/2022 | 17/6/2026 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization and authentication checks on multiple API routes. An attacker may gain access to these API routes and achieve remote code execution,… | |
| Modificada | Alta (7.5) | 1.1% | — | Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+1 | 18/2/2022 | 17/6/2026 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input, which may allow an attacker to perform a SQL injection and obtain sensitive information. | |
| Modificada | Crítica (9.8) | 1.2% | — | Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+1 | 18/2/2022 | 17/6/2026 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not properly sanitize user input on several locations, which may allow an attacker to inject arbitrary commands. | |
| Modificada | Crítica (9.8) | 3.2% | — | Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+1 | 18/2/2022 | 17/6/2026 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 does not perform proper authorization checks on multiple API functions. An attacker may gain access to these functions and achieve remote code execution, create a… | |
| Modificada | Alta (7.5) | 0.99% | — | Airspan Mimosa Management PlatformAirspan C6X FirmwareAirspan C5X FirmwareAirspan C5C Firmware+1 | 18/2/2022 | 17/6/2026 | MMP: All versions prior to v1.0.3, PTP C-series: Device versions prior to v2.8.6.1, and PTMP C-series and A5x: Device versions prior to v2.5.4.1 has a deserialization function that does not validate or check the data, allowing arbitrary classes to be created. | |
| Modificada | Alta (7.2) | 5.3% | — | Mimosa B5 FirmwareMimosa B5C FirmwareMimosa C5C Firmware | 20/7/2021 | 17/6/2026 | The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 allows authenticated command injection in the Throughput, WANStats, PhyStats, and QosStats API classes. An attacker with access to a web console account may execute operating system commands on affected devices by sending crafted POST requests to the… | |
| Modificada | Media (6.1) | 0.91% | — | Mimosa B5 FirmwareMimosa B5C FirmwareMimosa C5C Firmware | 20/7/2021 | 17/6/2026 | The web console for Mimosa B5, B5c, and C5x firmware through 2.8.0.2 is vulnerable to stored XSS in the set_banner() function of /var/www/core/controller/index.php. An unauthenticated attacker may set the contents of the /mnt/jffs2/banner.txt file, stored on the device's filesystem, to contain arbitrary JavaScript.… | |
| Modificada | Media (5.3) | 0.19% | — | Mimobaby Mimo Baby 2 Firmware | 15/5/2018 | 17/6/2026 | Mimo Baby 2 devices do not use authentication or encryption for the Bluetooth Low Energy (BLE) communication from a Turtle to a Lilypad, which allows attackers to inject fake information about the position and temperature of a baby via a replay or spoofing attack. | |
| Modificada | Alta (7.5) | 0.82% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An issue was discovered on Mimosa Client Radios before 2.2.3. In the device's web interface, there is a page that allows an attacker to use an unsanitized GET parameter to download files from the device as the root user. The attacker can download any file from the device's filesystem. This can be used to view… | |
| Modificada | Alta (8.8) | 1.3% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An issue was discovered on Mimosa Client Radios before 2.2.4 and Mimosa Backhaul Radios before 2.2.4. On the backend of the device's web interface, there are some diagnostic tests available that are not displayed on the webpage; these are only accessible by crafting a POST request with a program like cURL. There is… | |
| Modificada | Alta (7.5) | 1.2% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An information-leakage issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. There is a page in the web interface that will show you the device's serial number, regardless of whether or not you have logged in. This information-leakage issue is relevant because there is… | |
| Modificada | Alta (8.8) | 1.3% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. In the device's web interface, after logging in, there is a page that allows you to ping other hosts from the device and view the results. The user is allowed to specify which host to ping, but this variable is not… | |
| Modificada | Alta (7.5) | 1.1% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | A hard-coded credentials issue was discovered on Mimosa Client Radios before 2.2.3, Mimosa Backhaul Radios before 2.2.3, and Mimosa Access Points before 2.2.3. These devices run Mosquitto, a lightweight message broker, to send information between devices. By using the vendor's hard-coded credentials to connect to the… | |
| Modificada | Alta (7.5) | 2.6% | — | Mimosa Backhaul RadiosMimosa Client Radios | 21/5/2017 | 17/6/2026 | An issue was discovered on Mimosa Client Radios before 2.2.3 and Mimosa Backhaul Radios before 2.2.3. By connecting to the Mosquitto broker on an access point and one of its clients, an attacker can gather enough information to craft a command that reboots the client remotely when sent to the client's Mosquitto… |