Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2531▼ 362 respecto a la semana anterior
Críticas / altas1338▲ 72 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 6 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

12 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AplazadaMedia (5.1)0.21%—Naxclow Device FirmwareAIRt-threadAI12/6/202617/6/2026
During WiFi association, Naxclow device firmware prints the host network’s SSID, PSK, and negotiated WPA keys in cleartext to an exposed UART console on production hardware. The UART pads are labeled, run with default serial settings, and drop to an interactive RT-Thread shell that permits arbitrary memory reads,…
AplazadaCrítica (9.3)0.34%—Vivotek Device FirmwareAI19/11/202517/6/2026
Legacy Vivotek Device firmware uses default credetials for the root and user login accounts.
ModificadaAlta (7.5)1.0%—Hilscher Profinet IO Device FirmwarePepperl-fuchs Pgv100-f200a-b17-v1d FirmwarePepperl-fuchs Pgv150i-f200a-b17-v1d FirmwarePepperl-fuchs Pgv100-f200-b17-v1d-7477 Firmware+2016/2/202117/6/2026
A Denial of Service vulnerability was found in Hilscher PROFINET IO Device V3 in versions prior to V3.14.0.7. This may lead to unexpected loss of cyclic communication or interruption of acyclic communication.
ModificadaCrítica (9.8)1.6%—Kyland Kps2204 6 Port Managed Din-rail Programmable Serial Device Firmware17/12/202017/6/2026
A sensitive information disclosure vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to get username and password by request /cgi-bin/webadminget.cgi script via the browser.
ModificadaCrítica (9.8)2.5%—Kyland Kps2204 6 Port Managed Din-rail Programmable Serial Device Firmware17/12/202017/6/2026
An arbitrary code execution vulnerability in Kyland KPS2204 6 Port Managed Din-Rail Programmable Serial Device Servers Software Version:R0002.P05 allows remote attackers to upload a malicious script file by constructing a POST type request and writing a payload in the request parameters as an instruction to write a…
ModificadaAlta (7.8)0.34%—Sun-denshi Universal Forensic Extraction Device Firmware15/5/202017/6/2026
Cellebrite UFED 5.0 to 7.5.0.845 implements local operating system policies that can be circumvented to obtain a command prompt via the Windows file dialog that is reachable via the Certificate-Based Authentication option of the Wireless Network Connection screen.
ModificadaCrítica (9.8)2.1%—Postoaktraffic Awam Bluetooth Field Device Firmware17/2/202017/6/2026
Post Oak AWAM Bluetooth Field Device 7400v2.08.21.2018, 7800SD.2015.1.16, 2011.3, 7400v2.02.01.2019, and 7800SD.2012.12.5 is vulnerable to injections of operating system commands through timeconfig.py via shell metacharacters in the htmlNtpServer parameter.
ModificadaMedia (6.1)0.61%—Huawei Espace Integrated Access Device Firmware2/4/201717/6/2026
Huawei eSpace Integrated Access Device (IAD) with software V300R001C03, V300R001C04, V300R001C06, V300R001C20, and V300R001C07 allows an attacker to trick a user into clicking a URL containing malicious scripts to obtain user information or hijack the session, aka XSS.
ModificadaAlta (7.8)1.5%—Brickcom 100ap Device FirmwareBrickcom Fb-100apBrickcom Md-100apBrickcom Ob-100ae+34/10/201316/6/2026
Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.0.6.16C1 and earlier, do not properly restrict access to configfile.dump, which allow remote attackers to obtain sensitive information (user names, passwords, and configurations) via a get action.
ModificadaMedia (6.8)0.92%—Grandstream GXV Device FirmwareGrandstream Gxv3500Grandstream Gxv3501Grandstream Gxv3504+71/10/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in goform/usermanage in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models allows remote attackers to hijack the authentication of unspecified victims for requests…
ModificadaMedia (4.3)0.93%—Grandstream GXV Device FirmwareGrandstream Gxv3500Grandstream Gxv3501Grandstream Gxv3504+71/10/201316/6/2026
Cross-site scripting (XSS) vulnerability in Grandstream GXV3501, GXV3504, GXV3601, GXV3601HD/LL, GXV3611HD/LL, GXV3615W/P, GXV3651FHD, GXV3662HD, GXV3615WP_HD, GXV3500, and possibly other camera models before firmware 1.0.4.44, allows remote attackers to inject arbitrary web script or HTML via the PATH_INFO.
ModificadaMedia (6.8)12%—Brickcom 100ap Device FirmwareBrickcom Fb-100apBrickcom Md-100apBrickcom Ob-100ae+31/10/201316/6/2026
Cross-site request forgery (CSRF) vulnerability in cgi-bin/users.cgi in Brickcom FB-100Ap, WCB-100Ap, MD-100Ap, WFB-100Ap, OB-100Ae, OSD-040E, and possibly other camera models with firmware 3.1.0.8 and earlier, allows remote attackers to hijack the authentication of administrators for requests that add users.