Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2556▼ 352 respecto a la semana anterior
Críticas / altas1335▲ 66 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)93▼ 434 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 1.3% | — | Microchip Miwi | 5/8/2021 | 17/6/2026 | In version 6.5 Microchip MiWi software and all previous versions including legacy products, the stack is validating only two out of four Message Integrity Check (MIC) bytes. | |
| Modificada | Alta (7.5) | 1.2% | — | Microchip Miwi | 5/8/2021 | 17/6/2026 | In version 6.5 of Microchip MiWi software and all previous versions including legacy products, there is a possibility of frame counters being validated/updated prior to the message authentication. With this vulnerability in place, an attacker may increment the incoming frame counter values by injecting messages with a… | |
| Modificada | Media (5.3) | 1.1% | — | Miwisoft Mijosearch | 22/11/2019 | 17/6/2026 | The Mijosoft MijoSearch component 2.0.1 and earlier for Joomla! allows remote attackers to obtain sensitive information via a request to component/mijosearch/search, which reveals the installation path in an error message. | |
| Modificada | Media (6.1) | 0.78% | — | Miwisoft Mijosearch | 22/11/2019 | 17/6/2026 | Cross-site scripting (XSS) vulnerability in the Mijosoft MijoSearch component 2.0.4 and earlier for Joomla! allows remote attackers to inject arbitrary web script or HTML via the query parameter to component/mijosearch/search. | |
| Modificada | Alta (8.8) | 24% | — | Miwifi OS | 27/11/2018 | 17/6/2026 | System command injection in request_mitv in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary system commands via the "payload" URL parameter. | |
| Modificada | Alta (8.8) | 24% | — | Miwifi OS | 27/11/2018 | 17/6/2026 | System command injection vulnerability in wifi_access in Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute system commands via the "timeout" URL parameter. | |
| Modificada | Media (6.1) | 0.69% | — | Miwifi OS | 27/11/2018 | 17/6/2026 | Cross-site scripting vulnerability in the API 404 page on Xiaomi Mi Router 3 version 2.22.15 allows attackers to execute arbitrary JavaScript via a modified URL path. | |
| Modificada | Alta (7.5) | 2.0% | — | Xiaomi Miwifi Xiaomi 55dd Firmware | 5/9/2018 | 17/6/2026 | An "Out-of-band resource load" issue was discovered on Xiaomi MIWiFi Xiaomi_55DD Version 2.8.50 devices. It is possible to induce the application to retrieve the contents of an arbitrary external URL and return those contents in its own response. If a domain name (containing a random string) is used in the HTTP Host… |