Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
6 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Baja (2.1) | 0.31% | — | Yealink Vp59 Firmware | 29/4/2024 | 17/6/2026 | An issue in Yealink VP59 Microsoft Teams Phone firmware 91.15.0.118 (fixed in 122.15.0.142) allows a physically proximate attacker to disable the phone lock via the Walkie Talkie menu option. | |
| Analizada | Media (6.8) | 0.37% | — | Yealink Vp59 Firmware | 25/4/2024 | 17/6/2026 | An issue discovered in Yealink VP59 Teams Editions with firmware version 91.15.0.118 allows a physically proximate attacker to gain control of an account via a flaw in the factory reset procedure. | |
| Analizada | Alta (7.5) | 0.84% | — | Yealink Vp59 Firmware | 26/3/2024 | 17/6/2026 | Directory Traversal vulnerability in Yealink VP59 v.91.15.0.118 allows a physically proximate attacker to obtain sensitive information via terms of use function in the company portal component. | |
| Modificada | Alta (7.5) | 0.53% | — | Zoom MeetingsZoom RoomsZoom Video Software Development KITZoom+5 | 30/6/2023 | 17/6/2026 | Exposure of information intended to be encrypted by some Zoom clients may lead to disclosure of sensitive information. | |
| Modificada | Alta (8.8) | 3.7% | — | Yeahlink Vp59 FirmwareYeahlink T49g FirmwareYeahlink T58v Firmware | 8/10/2019 | 17/6/2026 | Yealink phones through 2019-08-04 have an issue with OpenVPN file upload. They execute tar as root to extract files, but do not validate the extraction directory. Creating a tar file with ../../../../ allows replacement of almost any file on a phone. This leads to password replacement and arbitrary code execution as… | |
| Modificada | Alta (8.8) | 2.0% | — | Yeahlink Vp59 FirmwareYeahlink T49g FirmwareYeahlink T58v Firmware | 8/10/2019 | 17/6/2026 | Yealink phones through 2019-08-04 do not properly check user roles in POST requests. Consequently, the default User account (with a password of user) can make admin requests via HTTP. |