Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9) | 3.2% | — | Redlion N-tron 702-w FirmwareRedlion N-tron 702m12-w Firmware | 1/9/2020 | 17/6/2026 | The affected product is vulnerable to reflected cross-site scripting, which may allow an attacker to remotely execute arbitrary code and perform actions in the context of an attacked user on the N-Tron 702-W / 702M12-W (all versions). | |
| Modificada | Alta (8.8) | 1.2% | — | Redlion N-tron 702-w FirmwareRedlion N-tron 702m12-w Firmware | 1/9/2020 | 17/6/2026 | The affected product is vulnerable to cross-site request forgery, which may allow an attacker to modify different configurations of a device by luring an authenticated user to click on a crafted link on the N-Tron 702-W / 702M12-W (all versions). | |
| Modificada | Crítica (9) | 3.2% | — | Redlion N-tron 702-w FirmwareRedlion N-tron 702m12-w Firmware | 1/9/2020 | 17/6/2026 | The affected product is vulnerable to stored cross-site scripting, which may allow an attacker to remotely execute arbitrary code to gain access to sensitive data on the N-Tron 702-W / 702M12-W (all versions). | |
| Modificada | Crítica (9.8) | 5.5% | — | Redlion N-tron 702-w FirmwareRedlion N-tron 702m12-w Firmware | 1/9/2020 | 17/6/2026 | The affected product is vulnerable due to an undocumented interface found on the device, which may allow an attacker to execute commands as root on the device on the N-Tron 702-W / 702M12-W (all versions). | |
| Modificada | Alta (8.8) | 6.2% | — | BusyboxDebian LinuxVmware EsxiRedlion N-tron 702-w Firmware+2 | 20/11/2017 | 17/6/2026 | In the add_match function in libbb/lineedit.c in BusyBox through 1.27.2, the tab autocomplete feature of the shell, used to get a list of filenames in a directory, does not sanitize filenames and results in executing any escape sequence in the terminal. This could potentially result in code execution, arbitrary file… |