Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
–

5 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7.5)0.57%—Buffalo Bs-gsl2024 FirmwareBuffalo Bs-gsl2016p FirmwareBuffalo Bs-gsl2016 FirmwareBuffalo Bs-gs2008 Firmware+1211/4/202317/6/2026
Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03…
ModificadaAlta (8.1)0.29%—Buffalo Bs-gsl2024 FirmwareBuffalo Bs-gsl2016p FirmwareBuffalo Bs-gsl2016 FirmwareBuffalo Bs-gs2008 Firmware+811/4/202317/6/2026
Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a result, the product settings may be altered. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver.…
ModificadaMedia (5.4)0.37%—Buffalo Bs-gs2008 FirmwareBuffalo Bs-gs2016 FirmwareBuffalo Bs-gs2024 FirmwareBuffalo Bs-gs2048 Firmware+311/4/202317/6/2026
Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008 firmware Ver. 1.0.10.01 and earlier,…
ModificadaMedia (6.1)0.69%—GE S2020 FirmwareGE S2024 Firmware20/10/202017/6/2026
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be rendered by the site and executed by the…
ModificadaMedia (6.1)0.71%—GE S2020 FirmwareGE S2024 Firmware25/9/202017/6/2026
The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts.