Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 302 respecto a la semana anterior
Críticas / altas1389▼ 21 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.8) | 3.8% | — | Amazon Blink XT2 Sync Module Firmware | 31/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when the device retrieves updates scripts from the internet. | |
| Modificada | Crítica (9.8) | 3.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when retrieving internal network configuration data. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the bssid parameter. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the key parameter. | |
| Modificada | Alta (8.8) | 1.2% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the encryption parameter. | |
| Modificada | Alta (8.8) | 1.7% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary commands on the device due to improperly sanitized input when configuring the devices wifi configuration via the ssid parameter. | |
| Modificada | Media (6.8) | 1.0% | — | Amazon Blink XT2 Sync Module Firmware | 11/12/2019 | 17/6/2026 | Blink XT2 Sync Module firmware prior to 2.13.11 allows remote attackers to execute arbitrary code and commands on the device due to insufficient UART protections. | |
| Modificada | Media (6.5) | 0.74% | — | Blinkforhome Sync Module | 15/12/2018 | 17/6/2026 | A design flaw in the BlinkForHome (aka Blink For Home) Sync Module 2.10.4 and earlier allows attackers to disable cameras via Wi-Fi, because incident clips (triggered by the motion sensor) are not saved if the attacker's traffic (such as Dot11Deauth) successfully disconnects the Sync Module from the Wi-Fi network.… |