Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3007▼ 67 respecto a la semana anterior
Críticas / altas1403▲ 50 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
9 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.92% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Weak password requirements in Blaauw Remote Kiln Control through v3.00r4 allow a user to set short or guessable passwords (e.g., 1 or 1234). | |
| Modificada | Alta (8.8) | 2.5% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | A path traversal in debug.php accessed via default.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to upload arbitrary files, leading to arbitrary remote code execution. | |
| Modificada | Media (6.5) | 1.1% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | A path traversal via the iniFile parameter in excel.php in Blaauw Remote Kiln Control through v3.00r4 allows an authenticated attacker to download arbitrary files from the host machine. | |
| Modificada | Crítica (9.8) | 1.3% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Leftover Debug Code in Blaauw Remote Kiln Control through v3.00r4 allows a user to execute arbitrary php code via /default.php?idx=17. | |
| Modificada | Alta (7.5) | 1.2% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Unauthenticated SQL injection via the username in the login mechanism in Blaauw Remote Kiln Control through v3.00r4 allows a user to extract arbitrary data from the rkc database. | |
| Modificada | Alta (7.5) | 1.3% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | /server-info and /server-status in Blaauw Remote Kiln Control through v3.00r4 allow an unauthenticated attacker to gain sensitive information about the host machine. | |
| Modificada | Crítica (9.8) | 0.84% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to access MySQL credentials in cleartext in /engine/db.inc, /lang/nl.bak, or /lang/en.bak. | |
| Modificada | Alta (7.5) | 1.2% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Browsable directories in Blaauw Remote Kiln Control through v3.00r4 allow an attacker to enumerate sensitive filenames and locations, including source code. This affects /ajax/, /common/, /engine/, /flash/, /images/, /Images/, /jscripts/, /lang/, /layout/, /programs/, and /sms/. | |
| Modificada | Media (5.3) | 1.1% | — | Blaauwproducts Remote Kiln Control | 7/5/2020 | 17/6/2026 | Information disclosure via error message discrepancies in authentication functions in Blaauw Remote Kiln Control through v3.00r4 allows an unauthenticated attacker to enumerate valid usernames. |