Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2686▼ 84 respecto a la semana anterior
Críticas / altas1444▲ 301 respecto a la semana anterior
Nueva explotación activa (KEV)7▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)64▼ 462 respecto a la semana anterior
37 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.3) | 0.16% | — | Baicells Nova 430hAI | 29/9/2026 | 29/9/2026 | In Baicells Nova 430H, an unauthenticated device within radio range can send a malformed uplink message during connection setup that contains an invalid NAS payload. Because the eNodeB does not properly validate this payload, it forwards the message to the core network, which can trigger a shutdown of the signaling… | |
| Aplazada | Media (5.3) | 0.38% | — | Pydio CellsAI | 18/8/2026 | 24/9/2026 | Pydio Cells 5.0.0 through 5.0.2 returns share-link details to any authenticated user. The REST handler for GET /a/share/link/{Uuid} in idm/share/rest/handler.go reads the workspace UUID from the path, calls LinkById, and writes the result with no authorization step, whereas the sibling handler for GET… | |
| Aplazada | Alta (7.3) | 3.7% | — | Baicells Eg3661mAIOpenwrt LuciAI | 14/8/2026 | 18/8/2026 | A vulnerability was identified in Baicells EG3661M BaiCE_BQ6_2.0.5.3_NA. This impacts an unknown function of the file /cgi-bin/luci of the component LuCI Web Interface. Such manipulation of the argument MaxHops/Timeout/Size leads to os command injection. The attack may be launched remotely. The exploit is publicly… | |
| Aplazada | Crítica (9.3) | 1.7% | — | Pydio CellsAIAjaxplorerAI | 8/8/2025 | 16/6/2026 | An unauthenticated remote command execution vulnerability exists in AjaXplorer (now known as Pydio Cells) versions prior to 2.6. The flaw resides in the checkInstall.php script within the access.ssh plugin, which fails to properly sanitize user-supplied input to the destServer GET parameter. By injecting shell… | |
| Aplazada | Crítica (9.3) | 0.36% | — | Baicells Snap Router Baice BMIAI | 25/6/2024 | 17/6/2026 | Use of Hard-coded Credentials vulnerability in Baicells Snap Router BaiCE_BMI on EP3011 (User Passwords modules) allows unauthorized access to the device. | |
| Modificada | Media (5.4) | 2.9% | — | Pydio Cells | 8/6/2023 | 17/6/2026 | Pydio Cells through 4.1.2 allows XSS. Pydio Cells implements the download of files using presigned URLs which are generated using the Amazon AWS SDK for JavaScript [1]. The secrets used to sign these URLs are hardcoded and exposed through the JavaScript files of the web application. Therefore, it is possible to… | |
| Modificada | Media (6.5) | 3.8% | — | Pydio Cells | 8/6/2023 | 17/6/2026 | Pydio Cells through 4.1.2 allows SSRF. For longer running processes, Pydio Cells allows for the creation of jobs, which are run in the background. The job "remote-download" can be used to cause the backend to send a HTTP GET request to a specified URL and save the response to a new file. The response file is then… | |
| Modificada | Alta (8.8) | 14% | — | Pydio Cells | 8/6/2023 | 17/6/2026 | Pydio Cells allows users by default to create so-called external users in order to share files with them. By modifying the HTTP request sent when creating such an external user, it is possible to assign the new user arbitrary roles. By assigning all roles to a newly created user, access to all cells and non-personal… | |
| Modificada | Media (5.4) | 0.68% | — | Abstrium Pydio Cells | 30/5/2023 | 17/6/2026 | A vulnerability, which was classified as problematic, has been found in Abstrium Pydio Cells 4.2.0. This issue affects some unknown processing of the component Chat. The manipulation leads to basic cross site scripting. The attack may be initiated remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Alta (8.8) | 1.1% | — | Abstrium Pydio Cells | 30/5/2023 | 17/6/2026 | A vulnerability classified as critical was found in Abstrium Pydio Cells 4.2.0. This vulnerability affects unknown code of the component User Creation Handler. The manipulation leads to improper control of resource identifiers. The attack can be initiated remotely. The exploit has been disclosed to the public and may… | |
| Modificada | Alta (8.8) | 0.81% | — | Abstrium Pydio Cells | 30/5/2023 | 17/6/2026 | A vulnerability classified as critical has been found in Abstrium Pydio Cells 4.2.0. This affects an unknown part of the component User Creation Handler. The manipulation leads to improper access controls. It is possible to initiate the attack remotely. The exploit has been disclosed to the public and may be used.… | |
| Modificada | Media (4.3) | 0.73% | — | Abstrium Pydio Cells | 30/5/2023 | 17/6/2026 | A vulnerability was found in Abstrium Pydio Cells 4.2.0. It has been rated as problematic. Affected by this issue is some unknown functionality of the component Change Subscription Handler. The manipulation leads to authorization bypass. The exploit has been disclosed to the public and may be used. Upgrading to… | |
| Modificada | Crítica (9.8) | 1.1% | — | Baicells Eg7035-m11 Firmware | 1/3/2023 | 17/6/2026 | Baicells EG7035-M11 devices with firmware through BCE-ODU-1.0.8 are vulnerable to improper code exploitation via HTTP GET command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods have been tested and validated by a 3rd party analyst and have been… | |
| Modificada | Crítica (10) | 1.2% | — | Baicells Neutrino 430 FirmwareBaicells Nova430l FirmwareBaicells Nova430e FirmwareBaicells Nova436q Firmware | 11/2/2023 | 17/6/2026 | Baicells Nova 436Q, Nova 430E, Nova 430I, and Neutrino 430 LTE TDD eNodeB devices with firmware through QRTB 2.12.7 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been… | |
| Modificada | Crítica (9.6) | 1.6% | — | Baicells RTD FirmwareBaicells RTS Firmware | 26/1/2023 | 17/6/2026 | Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB and Nova 246 devices with firmware through RTS/RTD 3.6.6 are vulnerable to remote shell code exploitation via HTTP command injections. Commands are executed using pre-login execution and executed with root permissions. The following methods below have been… | |
| Modificada | Crítica (9.8) | 1.6% | — | Baicells RTD FirmwareBaicells RTS Firmware | 26/1/2023 | 17/6/2026 | Baicells Nova 227, Nova 233, and Nova 243 LTE TDD eNodeB devices with firmware through RTS/RTD 3.7.11.3 have hardcoded credentials that are easily discovered and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.) | |
| Modificada | Crítica (9.8) | 3.3% | — | Baicells Nova436q FirmwareBaicells Neutrino 430 Firmware | 30/3/2022 | 17/6/2026 | Baicells Nova436Q and Neutrino 430 devices with firmware through QRTB 2.7.8 have hardcoded credentials that are easily discovered, and can be used by remote attackers to authenticate via ssh. (The credentials are stored in the firmware, encrypted by the crypt function.) | |
| Modificada | Media (6.5) | 2.1% | — | Pydio Cells | 30/9/2021 | 17/6/2026 | Directory traversal in the Copy, Move, and Delete features in Pydio Cells 2.2.9 allows remote authenticated users to enumerate personal files (or Cells files belonging to any user) via the nodes parameter (for Copy and Move) or via the Path parameter (for Delete). | |
| Modificada | Media (6.5) | 1.1% | — | Pydio Cells | 30/9/2021 | 17/6/2026 | Broken access control for user creation in Pydio Cells 2.2.9 allows remote anonymous users to create standard users via the profile parameter. (In addition, such users can be granted several admin permissions via the Roles parameter.) | |
| Modificada | Media (6.5) | 2.1% | — | Pydio Cells | 30/9/2021 | 17/6/2026 | Directory traversal in the Compress feature in Pydio Cells 2.2.9 allows remote authenticated users to overwrite personal files, or Cells files belonging to any user, via the format parameter. | |
| Modificada | Alta (7) | 0.49% | — | Pydio Cells | 11/6/2020 | 17/6/2026 | The following vulnerability applies only to the Pydio Cells Enterprise OVF version 2.0.4. Prior versions of the Pydio Cells Enterprise OVF (such as version 2.0.3) have a looser policy restriction allowing the “pydio” user to execute any privileged command using sudo. In version 2.0.4 of the appliance, the user pydio… | |
| Modificada | Media (5.4) | 0.83% | — | Pydio Cells | 5/6/2020 | 17/6/2026 | Pydio Cells 2.0.4 allows any user to upload a profile image to the web application, including standard and shared user roles. These profile pictures can later be accessed directly with the generated URL by any unauthenticated or authenticated user. | |
| Modificada | Media (5.4) | 1.1% | — | Pydio Cells | 5/6/2020 | 17/6/2026 | In Pydio Cells 2.0.4, once an authenticated user shares a file selecting the create a public link option, a hidden shared user account is created in the backend with a random username. An anonymous user that obtains a valid public link can get the associated hidden account username and password and proceed to login to… | |
| Modificada | Media (6.1) | 0.76% | — | Pydio Cells | 4/6/2020 | 17/6/2026 | Pydio Cells 2.0.4 allows XSS. A malicious user can either upload or create a new file that contains potentially malicious HTML and JavaScript code to personal folders or accessible cells. | |
| Modificada | Media (6.8) | 2.4% | — | Pydio Cells | 4/6/2020 | 17/6/2026 | The update feature for Pydio Cells 2.0.4 allows an administrator user to set a custom update URL and the public RSA key used to validate the downloaded update package. The update process involves downloading the updated binary file from a URL indicated in the update server response, validating its checksum and… |