Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (5.4) | 1.1% | — | Moxa Sds-3008 FirmwareMoxa Sds-3008-t Firmware | 7/2/2023 | 17/6/2026 | A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="switch_contact" | |
| Modificada | Media (5.4) | 1.1% | — | Moxa Sds-3008 FirmwareMoxa Sds-3008-t Firmware | 7/2/2023 | 17/6/2026 | A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field id="Switch… | |
| Modificada | Media (5.4) | 1.0% | — | Moxa Sds-3008 FirmwareMoxa Sds-3008-t Firmware | 7/2/2023 | 17/6/2026 | A stored cross-site scripting vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to arbitrary Javascript execution. An attacker can send an HTTP request to trigger this vulnerability.Form field… | |
| Modificada | Alta (7.5) | 0.65% | — | Moxa Sds-3008 FirmwareMoxa Sds-3008-t Firmware | 7/2/2023 | 17/6/2026 | A cleartext transmission vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted network sniffing can lead to a disclosure of sensitive information. An attacker can sniff network traffic to trigger this vulnerability. | |
| Modificada | Media (5.3) | 1.5% | — | Moxa Sds-3008 FirmwareMoxa Sds-3008-t Firmware | 7/2/2023 | 17/6/2026 | An information disclosure vulnerability exists in the web application functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP request can lead to a disclosure of sensitive information. An attacker can send an HTTP request to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 65% | — | Moxa Sds-3008 FirmwareMoxa Sds-3008-t Firmware | 7/2/2023 | 17/6/2026 | A denial of service vulnerability exists in the web server functionality of Moxa SDS-3008 Series Industrial Ethernet Switch 2.1. A specially-crafted HTTP message header can lead to denial of service. An attacker can send an HTTP request to trigger this vulnerability. |