Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2817▼ 183 respecto a la semana anterior
Críticas / altas1372▲ 48 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)247▼ 271 respecto a la semana anterior
8 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Crítica (9.1) | 1.2% | — | Winstonprivacy Winston Firmware | 28/10/2020 | 17/6/2026 | Winston 1.5.4 devices have a CORS configuration that trusts arbitrary origins. This allows requests to be made and viewed by arbitrary origins. | |
| Modificada | Alta (7.8) | 0.43% | — | Winstonprivacy Winston Firmware | 28/10/2020 | 17/6/2026 | Winston 1.5.4 devices have a local www-data user that is overly permissioned, resulting in root privilege escalation. | |
| Modificada | Media (6.8) | 0.47% | — | Winstonprivacy Winston Firmware | 28/10/2020 | 17/6/2026 | Winston 1.5.4 devices allow a U-Boot interrupt, resulting in local root access. | |
| Modificada | Alta (7.5) | 0.93% | — | Winstonprivacy Winston Firmware | 28/10/2020 | 17/6/2026 | Winston 1.5.4 devices do not enforce authorization. This is exploitable from the intranet, and can be combined with other vulnerabilities for remote exploitation. | |
| Modificada | Crítica (9.8) | 1.8% | — | Winstonprivacy Winston Firmware | 28/10/2020 | 17/6/2026 | Winston 1.5.4 devices have an SSH user account with access from bastion hosts. This is undocumented in device documents and is not announced to the user. | |
| Modificada | Alta (7.1) | 0.39% | — | Winstonprivacy Winston Firmware | 28/10/2020 | 17/6/2026 | Winston 1.5.4 devices make use of a Monit service (not managed during the normal user process) which is configured with default credentials. | |
| Modificada | Alta (8.8) | 0.66% | — | Winstonprivacy Winston Firmware | 28/10/2020 | 17/6/2026 | The API on Winston 1.5.4 devices is vulnerable to CSRF. | |
| Modificada | Crítica (9.8) | 3.7% | — | Winstonprivacy Winston Firmware | 28/10/2020 | 17/6/2026 | Winston 1.5.4 devices are vulnerable to command injection via the API. |