Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9)3.2%—Redlion N-tron 702-w FirmwareRedlion N-tron 702m12-w Firmware1/9/202017/6/2026
The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform actions in the context of an attacked user on the N-Tron 702-W / 702M12-W (all versions).
ModificadaAlta (8.8)1.2%—Redlion N-tron 702-w FirmwareRedlion N-tron 702m12-w Firmware1/9/202017/6/2026
The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by luring an authenticated user to click on a crafted link on the N-Tron 702-W / 702M12-W (all versions).
ModificadaCrítica (9)3.2%—Redlion N-tron 702-w FirmwareRedlion N-tron 702m12-w Firmware1/9/202017/6/2026
The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbitrary code to gain access to sensitive data on the N-Tron 702-W / 702M12-W (all versions).
ModificadaCrítica (9.8)5.5%—Redlion N-tron 702-w FirmwareRedlion N-tron 702m12-w Firmware1/9/202017/6/2026
The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on the device on the N-Tron 702-W / 702M12-W (all versions).
ModificadaAlta (8.8)6.2%—BusyboxDebian LinuxVmware EsxiRedlion N-tron 702-w Firmware+220/11/201717/6/2026
In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file…
Orbitaley — Vulnerabilidades