Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2500▼ 420 respecto a la semana anterior
Críticas / altas1284▲ 11 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 465 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.39% | — | Vision UIAIVision UI Security-kitAI | 6/8/2025 | 17/6/2026 | Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the generateSecureId and getSecureRandomInt functions in security-kit versions prior to 3.5.0 (packaged in Vision UI 1.4.0 and below) are vulnerable to Denial of Service (DoS) attacks. The… | |
| Aplazada | Crítica (9.3) | 0.37% | — | Vision UIAIVision UI Security KITAI | 6/8/2025 | 17/6/2026 | Vision UI is a collection of enterprise-grade, dependency-free modules for modern web projects. In versions 1.4.0 and below, the getSecureRandomInt function in security-kit versions prior to 3.5.0 (packaged in Vision-ui <= 1.4.0) contains a critical cryptographic weakness. Due to a silent 32-bit integer overflow in… | |
| Analizada | Media (5.3) | 0.36% | — | Security KIT Project Security KIT | 9/1/2025 | 17/6/2026 | Access of Resource Using Incompatible Type ('Type Confusion') vulnerability in Drupal Security Kit allows HTTP DoS.This issue affects Security Kit: from 0.0.0 before 2.0.3. | |
| Modificada | Alta (8.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an… | |
| Modificada | Alta (8.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an… | |
| Modificada | Alta (8.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an… | |
| Modificada | Alta (8.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted HTTP request can lead to memory corruption, information disclosure and denial of service. An attacker can make an… | |
| Modificada | Alta (8.8) | 0.82% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to… | |
| Modificada | Alta (8.8) | 0.82% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to… | |
| Modificada | Alta (8.8) | 0.82% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to… | |
| Modificada | Alta (8.8) | 0.82% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the UPnP logging functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted UPnP negotiation can lead to memory corruption, information disclosure, and denial of service. An attacker can host a malicious UPnP service to… | |
| Modificada | Crítica (9.8) | 0.92% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and… | |
| Modificada | Crítica (9.8) | 0.92% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and… | |
| Modificada | Crítica (9.8) | 0.92% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and… | |
| Modificada | Crítica (9.8) | 0.92% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four format string injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. Specially-crafted configuration values can lead to memory corruption, information disclosure and denial of service. An attacker can modify a configuration value and… | |
| Modificada | Crítica (9.8) | 1.3% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | A format string injection vulnerability exists in the XCMD getVarHA functionality of abode systems, inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted XCMD can lead to memory corruption, information disclosure, and denial of service. An attacker can send a malicious XML payload to trigger this… | |
| Modificada | Crítica (9.8) | 0.97% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | A format string injection vulnerability exists in the ghome_process_control_packet functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9Z and 6.9X. A specially-crafted XCMD can lead to memory corruption, information disclosure and denial of service. An attacker can send a malicious XML payload to… | |
| Modificada | Crítica (9.9) | 4.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these… | |
| Modificada | Crítica (9.9) | 4.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these… | |
| Modificada | Crítica (9.9) | 4.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these… | |
| Modificada | Crítica (9.9) | 4.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exists in the web interface /action/wirelessConnect functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A specially-crafted HTTP request can lead to arbitrary command execution. An attacker can make an authenticated HTTP request to trigger these… | |
| Modificada | Crítica (10) | 3.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on… | |
| Modificada | Crítica (10) | 3.2% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability focuses on… | |
| Modificada | Crítica (10) | 3.2% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically… | |
| Modificada | Crítica (10) | 3.4% | — | Goabode Iota All-in-one Security KIT Firmware | 25/10/2022 | 17/6/2026 | Four OS command injection vulnerabilities exist in the XCMD testWifiAP functionality of Abode Systems, Inc. iota All-In-One Security Kit 6.9X and 6.9Z. A XCMD can lead to arbitrary command execution. An attacker can send a sequence of malicious commands to trigger these vulnerabilities.This vulnerability specifically… |