Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3019▲ 545 respecto a la semana anterior
Críticas / altas1439▲ 265 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)382▲ 175 respecto a la semana anterior
21 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7.2) | 3.9% | — | LG Webos | 9/4/2024 | 17/6/2026 | A command injection vulnerability exists in the com.webos.service.connectionmanager/tv/setVlanStaticAddress endpoint on webOS versions 5 and 6. A series of specially crafted requests can lead to command execution as the dbus user. An attacker can make authenticated requests to trigger this vulnerability. | |
| Analizada | Alta (7.2) | 6.4% | — | LG Webos | 9/4/2024 | 17/6/2026 | A command injection vulnerability exists in the getAudioMetadata method from the com.webos.service.attachedstoragemanager service on webOS version 4 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this… | |
| Analizada | Alta (7.2) | 4.7% | — | LG Webos | 9/4/2024 | 17/6/2026 | A command injection vulnerability exists in the processAnalyticsReport method from the com.webos.service.cloudupload service on webOS version 5 through 7. A series of specially crafted requests can lead to command execution as the root user. An attacker can make authenticated requests to trigger this vulnerability.… | |
| Analizada | Crítica (9.8) | 1.1% | — | LG Webos | 9/4/2024 | 17/6/2026 | A prompt bypass exists in the secondscreen.gateway service running on webOS version 4 through 7. An attacker can create a privileged account without asking the user for the security PIN. Full versions and TV models affected: webOS 4.9.7 - 5.30.40 running on LG43UM7000PLA webOS 5.5.0 - 04.50.51 running on OLED55CXPUA… | |
| Analizada | Alta (8.8) | 0.80% | — | LG Webos Signage | 26/2/2024 | 17/6/2026 | This vulnerability allows remote attackers to traverse the directory on the affected webOS of LG Signage. | |
| Analizada | Crítica (9.8) | 0.92% | — | LG Webos Signage | 26/2/2024 | 17/6/2026 | This vulnerability allows remote attackers to execute arbitrary code on the affected webOS of LG Signage. | |
| Modificada | Alta (7.8) | 0.63% | — | LG Webos | 11/3/2022 | 17/6/2026 | V8 javascript engine (heap vulnerability) can cause privilege escalation ,which can impact on some webOS TV models. | |
| Modificada | Crítica (9.8) | 1.0% | — | LG Webos | 11/3/2022 | 17/6/2026 | The public API error causes for the attacker to be able to bypass API access control. | |
| Modificada | Alta (7.8) | 0.23% | — | LG Webos | 28/1/2022 | 17/6/2026 | There is a privilege escalation vulnerability in some webOS TVs. Due to wrong setting environments, local attacker is able to perform specific operation to exploit this vulnerability. Exploitation may cause the attacker to obtain a higher privilege | |
| Modificada | Alta (7.8) | 0.48% | — | LG Webos | 23/3/2020 | 17/6/2026 | A Vulnerability of LG Electronic web OS TV Emulator could allow an attacker to escalate privileges and overwrite certain files. This vulnerability is due to wrong environment setting. An attacker could exploit this vulnerability through crafted configuration files and executable files. | |
| Modificada | Media (5.4) | 3.9% | — | HP Palm PRE Webos | 13/9/2011 | 16/6/2026 | The LunaSysMgr process in Palm Pre WebOS 1.1 and earlier, when not viewing web pages in landscape mode, allows remote attackers to cause a denial of service (crash) via a web page containing a long string following a refresh tag, which triggers a floating point exception. | |
| Modificada | Alta (7.1) | 1.9% | — | HP Palm PRE Webos | 13/9/2011 | 16/6/2026 | Palm Pre WebOS 1.1 and earlier processes JavaScript in email messages, which allows remote attackers to execute arbitrary JavaScript, as demonstrated by reading PalmDatabase.db3. | |
| Modificada | Media (4.3) | 1.5% | — | HP Palm Webos | 11/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Calendar application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Media (4.3) | 1.5% | — | HP Palm Webos | 11/8/2011 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Contacts application in HP Palm webOS 3.x before 3.0.2 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.2) | 0.49% | — | HP Palm Webos | 13/5/2011 | 16/6/2026 | HP Palm webOS 1.4.5 and 1.4.5.1 does not properly restrict Plug-in Development Kit (PDK) applications, which allows local users to gain privileges by leveraging unintended filesystem write access. | |
| Modificada | Media (4.3) | 1.7% | — | HP Palm Webos | 13/5/2011 | 16/6/2026 | Multiple cross-site scripting (XSS) vulnerabilities in the Email application in HP Palm webOS 1.4.5 and 1.4.5.1 allow remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (10) | 2.4% | — | HP Palm PRE Webos | 19/4/2011 | 16/6/2026 | Unspecified vulnerability in Palm Pre WebOS before 1.2.1 has unknown impact and attack vectors related to an "included contact template file." | |
| Modificada | Media (4.3) | 1.7% | — | HP Palm Webos | 8/12/2010 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the Contacts Application in HP Palm webOS before 2.0 allows remote attackers to inject arbitrary web script or HTML via a crafted vCard file. | |
| Modificada | Media (5.6) | 1.2% | — | HP Palm Webos | 28/10/2010 | 16/6/2026 | Unspecified vulnerability in the camera application in HP Palm webOS 1.4.1 allows local users to overwrite arbitrary files via unknown vectors. | |
| Modificada | Media (6.2) | 0.43% | — | HP Palm Webos | 28/10/2010 | 16/6/2026 | Unspecified vulnerability in the service API in HP Palm webOS 1.4.1 allows local users to gain privileges by leveraging the ability to perform certain service calls. | |
| Modificada | Alta (9.3) | 6.9% | — | HP Palm Webos | 28/10/2010 | 16/6/2026 | Unspecified vulnerability in Doc Viewer in HP Palm webOS 1.4.1 allows remote attackers to execute arbitrary code via a crafted document, as demonstrated by a Word document. |