Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2534▼ 399 respecto a la semana anterior
Críticas / altas1321▲ 41 respecto a la semana anterior
Nueva explotación activa (KEV)6▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)96▼ 431 respecto a la semana anterior
7 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.5) | 0.34% | — | Hosteng H0-ecom100 Firmware | 28/10/2022 | 17/6/2026 | Using custom code, an attacker can write into name or description fields larger than the appropriate buffer size causing a stack-based buffer overflow on Host Engineering H0-ECOM100 Communications Module Firmware versions v5.0.155 and prior. This may allow an attacker to crash the affected device or cause it to become… | |
| Modificada | Alta (7.5) | 1.5% | — | Hosteng H0-ecom100 FirmwareHosteng H2-ecom100 FirmwareHosteng H4-ecom100 Firmware | 15/12/2020 | 17/6/2026 | The length of the input fields of Host Engineering H0-ECOM100, H2-ECOM100, and H4-ECOM100 modules are verified only on the client side when receiving input from the configuration web server, which may allow an attacker to bypass the check and send input to crash the device. | |
| Modificada | Media (5) | 1.3% | — | Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+4 | 13/4/2012 | 16/6/2026 | The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to cause a denial of service (resource consumption) via unspecified vectors. | |
| Modificada | Alta (10) | 3.5% | — | Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+4 | 13/4/2012 | 16/6/2026 | The web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 does not require authentication, which allows remote attackers to perform unspecified functions via unknown vectors. | |
| Modificada | Media (4.3) | 1.0% | — | Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+4 | 13/4/2012 | 16/6/2026 | Cross-site scripting (XSS) vulnerability in the web server in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors. | |
| Modificada | Alta (7.5) | 2.0% | — | Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+4 | 13/4/2012 | 16/6/2026 | The ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 supports a maximum password length of 8 bytes, which makes it easier for remote attackers to obtain access via a brute-force attack. | |
| Modificada | Alta (10) | 5.5% | — | Koyo H0-ecomKoyo H0-ecom100Koyo H2-ecomKoyo H2-ecom-f+4 | 13/4/2012 | 16/6/2026 | Buffer overflow in the ECOM Ethernet module in Koyo H0-ECOM, H0-ECOM100, H2-ECOM, H2-ECOM-F, H2-ECOM100, H4-ECOM, H4-ECOM-F, and H4-ECOM100 allows remote attackers to execute arbitrary code via long strings in unspecified parameters. |