Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2975▼ 108 respecto a la semana anterior
Críticas / altas1449▲ 87 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
13 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (4.8) | 0.30% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | An attacker with administrative access may inject malicious content into the login page, potentially enabling cross-site scripting (XSS) attacks, leading to the extraction of sensitive data. | |
| Analizada | Alta (8.2) | 0.32% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | An attacker may exploit missing protection against clickjacking by tricking users into performing unintended actions through maliciously crafted web pages, leading to the extraction of sensitive data. | |
| Analizada | Alta (7.5) | 0.56% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | Improper input handling in a system endpoint may allow attackers to overload resources, causing a denial of service. | |
| Analizada | Media (5.4) | 0.37% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | An attacker with low privileges may be able to trigger critical system functions such as reboot or factory reset without proper restrictions, potentially leading to service disruption or loss of configuration. | |
| Analizada | Media (6.5) | 0.41% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | An attacker with low privileges may be able to read files from specific directories on the device, potentially exposing sensitive information. | |
| Analizada | Media (6.5) | 0.31% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | An attacker with limited permissions may still be able to write files to specific locations on the device, potentially leading to system manipulation. | |
| Analizada | Media (6.1) | 0.39% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | Improper handling of a URL parameter may allow attackers to execute code in a user's browser after login. This can lead to the extraction of sensitive data. | |
| Analizada | Media (6.1) | 0.37% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | Improper validation of a login parameter may allow attackers to redirect users to malicious websites after authentication. This can lead to various risk including stealing credentials from unsuspecting users. | |
| Analizada | Alta (7.5) | 0.53% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | Firmware update files may expose password hashes for system accounts, which could allow a remote attacker to recover credentials and gain unauthorized access to the device. | |
| Analizada | Crítica (9.1) | 0.48% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | The device is deployed with weak and publicly known default passwords for certain hidden user levels, increasing the risk of unauthorized access. This represents a high risk to the integrity of the system. | |
| Analizada | Crítica (9.1) | 0.56% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | Certain system functions may be accessed without proper authorization, allowing attackers to start, stop, or delete installed applications, potentially disrupting system operations. | |
| Analizada | Crítica (9.1) | 0.60% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | Uploading unvalidated container images may allow remote attackers to gain full access to the system, potentially compromising its integrity and confidentiality. | |
| Analizada | Crítica (9.1) | 0.45% | — | Sick Tdc-x401gl Firmware | 15/1/2026 | 17/6/2026 | An attacker may gain unauthorized access to the host filesystem, potentially allowing them to read and modify system data. |