Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2543▼ 416 respecto a la semana anterior
Críticas / altas1316▲ 27 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)59▼ 467 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (6.5) | 0.79% | — | Nuuo Nvrmini 2AI | 1/4/2024 | 17/6/2026 | A vulnerability, which was classified as critical, was found in NUUO NVRmini 2 up to 3.0.8. Affected is an unknown function of the file /deletefile.php. The manipulation of the argument filename leads to path traversal. It is possible to launch the attack remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Crítica (9.8) | 9.8% | — | Nuuo Nvrmini 2 Firmware | 29/5/2018 | 17/6/2026 | upload.php on NUUO NVRmini 2 devices allows Arbitrary File Upload, such as upload of .php files. | |
| Modificada | Alta (8.8) | 17% | — | Nuuo Nvrmini 2Netgear Readynas Surveillance | 31/8/2016 | 17/6/2026 | Stack-based buffer overflow in cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary code via the sn parameter to the transfer_license command. | |
| Modificada | Alta (8.8) | 14% | — | Nuuo Nvrmini 2Netgear Readynas Surveillance | 31/8/2016 | 17/6/2026 | cgi-bin/cgi_main in NUUO NVRmini 2 1.7.6 through 3.0.0 and NETGEAR ReadyNAS Surveillance 1.1.2 allows remote authenticated users to execute arbitrary commands via shell metacharacters in the sn parameter to the transfer_license command. | |
| Modificada | Crítica (9.8) | 8.7% | — | Nuuo Nvrmini 2Nuuo Nvrsolo | 31/8/2016 | 17/6/2026 | NUUO NVRmini 2 1.0.0 through 3.0.0 and NUUO NVRsolo 1.0.0 through 3.0.0 have hardcoded root credentials, which allows remote attackers to obtain administrative access via unspecified vectors. | |
| Modificada | Alta (7.5) | 12% | — | Netgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo | 31/8/2016 | 17/6/2026 | NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 have a hardcoded qwe23622260 password for the nuuoeng account, which allows remote attackers to obtain sensitive information via an __nvr_status___.php request. | |
| Modificada | Alta (7.5) | 54% | — | Netgear Readynas SurveillanceNuuo NvrsoloNuuo Nvrmini 2 | 31/8/2016 | 17/6/2026 | cgi-bin/cgi_system in NUUO NVRmini 2 1.7.5 through 2.x, NUUO NVRsolo 1.7.5 through 2.x, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to reset the administrator password via a cmd=loaddefconfig action. | |
| Modificada | Crítica (9.8) | 71% | — | Netgear Readynas SurveillanceNuuo CrystalNuuo NvrsoloNuuo Nvrmini 2 | 31/8/2016 | 17/6/2026 | handle_daylightsaving.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.0.0 through 3.0.0, NUUO Crystal 2.2.1 through 3.2.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the NTPServer parameter. | |
| Modificada | Crítica (9.8) | 95% | — | Netgear Readynas SurveillanceNuuo Nvrmini 2Nuuo Nvrsolo | 31/8/2016 | 17/6/2026 | __debugging_center_utils___.php in NUUO NVRmini 2 1.7.5 through 3.0.0, NUUO NVRsolo 1.7.5 through 3.0.0, and NETGEAR ReadyNAS Surveillance 1.1.1 through 1.4.1 allows remote attackers to execute arbitrary PHP code via the log parameter. |