Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3023▼ 71 respecto a la semana anterior
Críticas / altas1419▲ 54 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▼ 128 respecto a la semana anterior
5 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Alta (7.5) | 0.57% | — | Buffalo Bs-gsl2024 FirmwareBuffalo Bs-gsl2016p FirmwareBuffalo Bs-gsl2016 FirmwareBuffalo Bs-gs2008 Firmware+12 | 11/4/2023 | 17/6/2026 | Use of hard-coded credentials vulnerability in Buffalo network devices allows an attacker to access the debug function of the product. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver. 1.10-0.03 and earlier, BS-GSL2016 firmware Ver. 1.10-0.03… | |
| Modificada | Alta (8.1) | 0.29% | — | Buffalo Bs-gsl2024 FirmwareBuffalo Bs-gsl2016p FirmwareBuffalo Bs-gsl2016 FirmwareBuffalo Bs-gs2008 Firmware+8 | 11/4/2023 | 17/6/2026 | Improper access control vulnerability in Buffalo network devices allows a network-adjacent attacker to obtain specific files of the product. As a result, the product settings may be altered. The affected products and versions are as follows: BS-GSL2024 firmware Ver. 1.10-0.03 and earlier, BS-GSL2016P firmware Ver.… | |
| Modificada | Media (5.4) | 0.37% | — | Buffalo Bs-gs2008 FirmwareBuffalo Bs-gs2016 FirmwareBuffalo Bs-gs2024 FirmwareBuffalo Bs-gs2048 Firmware+3 | 11/4/2023 | 17/6/2026 | Stored-cross-site scripting vulnerability in Buffalo network devices allows an attacker with access to the web management console of the product to execute arbitrary JavaScript on a legitimate user's web browser. The affected products and versions are as follows: BS-GS2008 firmware Ver. 1.0.10.01 and earlier,… | |
| Modificada | Media (6.1) | 0.69% | — | GE S2020 FirmwareGE S2024 Firmware | 20/10/2020 | 17/6/2026 | The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow attackers to trick users into following a link or navigating to a page that posts a malicious JavaScript statement to the vulnerable site, causing the malicious JavaScript to be rendered by the site and executed by the… | |
| Modificada | Media (6.1) | 0.71% | — | GE S2020 FirmwareGE S2024 Firmware | 25/9/2020 | 17/6/2026 | The affected Reason S20 Ethernet Switch is vulnerable to cross-site scripting (XSS), which may allow an attacker to trick application users into performing critical application actions that include, but are not limited to, adding and updating accounts. |