Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2550▼ 376 respecto a la semana anterior
Críticas / altas1325▲ 47 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
10 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (7.1) | 0.30% | — | Nuki BridgeAINuki Home Solutions BridgeAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. The HTTP API exposed by a Bridge used an unencrypted channel to provide an administrative interface. A token can be easily eavesdropped by a malicious actor to impersonate a legitimate user and gain access to the full set of API endpoints. This affects… | |
| Aplazada | Alta (8.8) | 0.29% | — | Nuki Smart Lock 3.0AINuki Bridge V1AINuki Bridge V2AI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. Lack of certificate validation on HTTP communications allows attackers to intercept and tamper data. This affects Nuki Smart Lock 3.0 before 3.3.5, Nuki Bridge v1 before 1.22.0 and Nuki Bridge v2 before 2.13.2. | |
| Aplazada | Alta (7.5) | 1.3% | — | Nuki BridgeAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. By sending a malformed HTTP verb, it is possible to force a reboot of the device. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2. | |
| Aplazada | Alta (8.8) | 0.52% | — | Nuki Smart Lock 3.0AINuki Smart Lock 2.0AI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. Some BLE commands, which should have been designed to be only called from privileged accounts, could also be called from unprivileged accounts. This demonstrates that no access controls were implemented for the different BLE commands across the different… | |
| Aplazada | Media (6.4) | 0.43% | — | Nuki Smart Lock 3.0AINuki Smart Lock 2.0AINuki BridgeAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to the circuit board could use the SWD debug features to control the execution of code on the processor and debug the firmware, as well as read or alter the content of the internal and external flash memory. This affects… | |
| Aplazada | Alta (7.1) | 0.46% | — | Nuki Smart Lock 3.0AINuki Smart Lock 2.0AI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. It is possible to send multiple BLE malformed packets to block some of the functionality and reboot the device. This affects Nuki Smart Lock 3.0 before 3.3.5 and Nuki Smart Lock 2.0 before 2.12.4. | |
| Aplazada | Crítica (9.8) | 1.6% | — | Nuki Smart Lock 3.0AINuki Smart Lock 2.0AINuki Bridge V1AINuki Bridge V2AI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. The code used to parse the JSON objects received from the WebSocket service provided by the device leads to a stack buffer overflow. An attacker would be able to exploit this to gain arbitrary code execution on a KeyTurner device. This affects Nuki Smart… | |
| Aplazada | Alta (7.6) | 0.50% | — | Nuki KeypadAINuki FOBAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. An attacker with physical access to this JTAG port may be able to connect to the device and bypass both hardware and software security protections. This affects Nuki Keypad before 1.9.2 and Nuki Fob before 1.8.1. | |
| Aplazada | Media (6.3) | 1.3% | — | Nuki BridgeAINuki Home SolutionsAI | 14/5/2024 | 17/6/2026 | An issue was discovered on certain Nuki Home Solutions devices. There is a buffer overflow over the encrypted token parsing logic in the HTTP service that allows remote code execution. This affects Nuki Bridge v1 before 1.22.0 and v2 before 2.13.2. | |
| Modificada | Media (5.4) | 0.42% | — | Nukium GLS | 15/11/2023 | 17/6/2026 | Nukium nkmgls before version 3.0.2 is vulnerable to Cross Site Scripting (XSS) via NkmGlsCheckoutModuleFrontController::displayAjaxSavePhoneMobile. |