Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

9 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.92%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234).
ModificadaAlta (8.8)2.5%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution.
ModificadaMedia (6.5)1.1%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine.
ModificadaCrítica (9.8)1.3%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17.
ModificadaAlta (7.5)1.2%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database.
ModificadaAlta (7.5)1.3%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
/server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine.
ModificadaCrítica (9.8)0.84%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak.
ModificadaAlta (7.5)1.2%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /common/, /engine/, /flash/, /images/, /Images/, /jscripts/, /lang/, /layout/, /programs/, and /sms/.
ModificadaMedia (5.3)1.1%—Blaauwproducts Remote Kiln Control7/5/202017/6/2026
Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames.