Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2624▼ 236 respecto a la semana anterior
Críticas / altas1384▲ 151 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)56▼ 473 respecto a la semana anterior
–

22 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.5)0.68%—Newtype WebeipAI3/8/202612/8/2026
A vulnerability was detected in NewType WebEIP up to 3.0. This affects an unknown part of the file /EIP_Com_FileList.aspx. The manipulation results in improper authentication. It is possible to launch the attack remotely. The exploit is now public and may be used. The vendor was contacted early about this disclosure…
AplazadaAlta (7.8)0.67%—Newtonsoft JsonAIAlex4ssb ADB ExplorerAI13/2/202617/6/2026
ADB Explorer is a fluent UI for ADB on Windows. Prior to Beta 0.9.26020, ADB Explorer is vulnerable to Insecure Deserialization leading to Remote Code Execution. The application attempts to deserialize the App.txt settings file using Newtonsoft.Json with TypeNameHandling set to Objects. This allows an attacker to…
AnalizadaCrítica (9.8)0.55%—Newtec Celoxa504 FirmwareNewtec Celoxa820 Firmware19/11/202517/6/2026
The Newtec Celox UHD (models: CELOXA504, CELOXA820) running firmware version celox-21.6.13 is vulnerable to an authentication bypass. An attacker can exploit this issue by modifying intercepted responses from the /celoxservice endpoint. By injecting a forged response body during the loginWithUserName flow, the…
AplazadaMedia (6.9)0.41%—Newtype Infortech NUP PortalAI12/9/202517/6/2026
NUP Portal developed by NewType Infortech has a Missing Authentication vulnerability, allowing unauthenticated remote attackers to directly upload files. If the attacker manages to bypass the file extension restrictions, they could upload a webshell and execute it on the server side.
AplazadaCrítica (9.3)0.57%—Newtype Infortech NUP PROAI12/9/202517/6/2026
NUP Pro developed by NewType Infortech has a SQL Injection vulnerability, allowing unauthenticated remote attackers to inject arbitrary SQL commands to read, modify, and delete database contents.
AplazadaCrítica (9.5)0.52%—Newtec Ntc2218AINewtec Ntc2250AINewtec Ntc2299AI17/1/202517/6/2026
Buffer Copy without Checking Size of Input ('Classic Buffer Overflow') vulnerability in Newtec NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM (Updating signaling process in the swdownload binary modules) allows Local Execution of Code, Remote Code Inclusion. This issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1…
AplazadaCrítica (9.3)0.64%—Newtec Ntc2218AINewtec Ntc2250AINewtec Ntc2299AI17/1/202517/6/2026
Improper Neutralization of Special Elements used in an OS Command ('OS Command Injection') vulnerability in Newtec/iDirect NTC2218, NTC2250, NTC2299 on Linux, PowerPC, ARM allows Local Code Inclusion.This issue affects NTC2218, NTC2250, NTC2299: from 1.0.1.1 through 2.2.6.19. The `commit_multicast` page used to…
AnalizadaAlta (8.8)0.65%—Newtype Flowmaster BPM Plus15/10/202417/6/2026
The specific query functionality in the FlowMaster BPM Plus from NewType does not properly restrict user input, allowing remote attackers with regular privileges to inject SQL commands to read, modify, or delete database contents.
AnalizadaAlta (8.8)0.61%—Newtype Flowmaster BPM Plus15/10/202417/6/2026
The FlowMaster BPM Plus system from NewType has a privilege escalation vulnerability. Remote attackers with regular privileges can elevate their privileges to administrator by tampering with a specific cookie.
AnalizadaMedia (5.4)0.29%—Newtype Webeip15/10/202417/6/2026
NewType WebEIP v3.0 does not properly validate user input, allowing a remote attacker with regular privileges to insert JavaScript into specific parameters, resulting in a Reflected Cross-site Scripting (XSS) attack. The affected product is no longer maintained. It is recommended to upgrade to the new product.
AnalizadaAlta (8.8)0.65%—Newtype Webeip15/10/202417/6/2026
WebEIP v3.0 from NewType does not properly validate user input, allowing remote attackers with regular privilege to inject SQL commands to read, modify, and delete data stored in database. The affected product is no longer maintained. It is recommended to upgrade to the new product.
ModificadaAlta (7.5)33%—Newtonsoft Json.net3/1/202414/7/2026
Newtonsoft.Json before version 13.0.1 is affected by a mishandling of exceptional conditions vulnerability. Crafted data that is passed to the JsonConvert.DeserializeObject method may trigger a StackOverflow exception resulting in denial of service. Depending on the usage of the library, an unauthenticated and remote…
ModificadaCrítica (9.8)0.41%—Ip-label Newtest30/1/20239/7/2026
The Robot application in Ip-label Newtest before v8.5R0 was discovered to use weak signature checks on executed binaries, allowing attackers to have write access and escalate privileges via replacing NEWTESTREMOTEMANAGER.EXE.
ModificadaMedia (4.7)0.43%—Bruhn-newtech Cbrn-analysis12/11/202217/6/2026
CBRN-Analysis before 22 allows XXE attacks via am mws XML document, leading to NTLMv2-SSP hash disclosure.
ModificadaAlta (8.8)0.50%—Bruhn-newtech Cbrn-analysis12/11/202217/6/2026
CBRN-Analysis before 22 has weak file permissions under Public Profile, leading to disclosure of file contents or privilege escalation.
ModificadaMedia (5.4)0.90%—Newtarget Custom Global Variables25/2/202117/6/2026
Stored cross-site scripting (XSS) in form field in robust.systems product Custom Global Variables v 1.0.5 allows a remote attacker to inject arbitrary code via the vars[0][name] field.
ModificadaAlta (8.8)2.4%—Opennms HorizonOpennms MeridianOpennms Newts17/2/202117/6/2026
OpenNMS Meridian 2016, 2017, 2018 before 2018.1.25, 2019 before 2019.1.16, and 2020 before 2020.1.5, Horizon 1.2 through 27.0.4, and Newts <1.5.3 has Incorrect Access Control, which allows local and remote code execution using JEXL expressions.
ModificadaMedia (6.1)0.99%—Cloudmagic Newton18/3/202017/6/2026
The Newton application through 10.0.23 for Android allows XSS via an event attribute and arbitrary file loading via a src attribute, if the application has the READ_EXTERNAL_STORAGE permission.
ModificadaMedia (5.8)2.0%—Newtelligence Dasblog23/10/201417/6/2026
Open redirect vulnerability in the Click-Through feature in Newtelligence dasBlog 2.1 (2.1.8102.813), 2.2 (2.2.8279.16125), and 2.3 (2.3.9074.18820) allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via a URL in the url parameter to ct.ashx.
ModificadaMedia (4.6)0.50%—Fedorahosted Newt29/9/200916/6/2026
Heap-based buffer overflow in textbox.c in newt 0.51.5, 0.51.6, and 0.52.2 allows local users to cause a denial of service (application crash) or possibly execute arbitrary code via a request to display a crafted text dialog box.
ModificadaAlta (10)6.6%—Casio Photo LoaderNewtone Imagekit4/12/200616/6/2026
Multiple buffer overflows in the ActiveX controls in Newtone ImageKit 5 before Fix 30 and 6 before Fix 40, as used in CASIO Photo Loader software before 3.01 and possibly other software, allow remote attackers to execute arbitrary code via a crafted HTML document.
ModificadaMedia (4.3)1.8%—Newtelligence Dasblog1/9/200416/6/2026
Cross-site scripting (XSS) vulnerability in the Activity and Events Viewer for Newtelligence DasBlog allows remote attackers to inject arbitrary web script or HTML via the (1) User Agent or (2) Referrer HTTP headers.