Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2719▼ 93 respecto a la semana anterior
Críticas / altas1415▲ 185 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)101▼ 398 respecto a la semana anterior
55 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.7) | 0.44% | — | Advantech IviewAI | 4/12/2025 | 17/6/2026 | Advantech iView versions 5.7.05.7057 and prior do not properly sanitize SNMP v1 trap (Port 162) requests, which could allow an attacker to inject SQL commands. | |
| Analizada | Crítica (9.3) | 0.63% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_search_value’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows… | |
| Analizada | Alta (8.8) | 0.46% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘data’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for the… | |
| Analizada | Crítica (9.3) | 0.69% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘search_term’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for… | |
| Analizada | Crítica (9.3) | 0.63% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘getInventoryReportData’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation… | |
| Analizada | Alta (8.8) | 0.50% | — | Advantech Iview | 6/11/2025 | 17/6/2026 | Advantech iView versions prior to v5.7.04 build 6425 contain a vulnerability within the SNMP management tool that allows for remote attackers to bypass authentication checks and reach a SQL injection vulnerability within the ‘ztp_config_id’ parameter to the ‘NetworkServlet’ endpoint. Successful exploitation allows for… | |
| Aplazada | Baja (1.9) | 0.27% | — | Changsha Developer Technology Iview EditorAI | 25/9/2025 | 17/6/2026 | A vulnerability was found in Changsha Developer Technology iView Editor up to 1.1.1. This impacts an unknown function of the component Markdown Handler. The manipulation results in cross site scripting. The attack may be performed from remote. The exploit has been made public and could be used. The vendor was… | |
| Analizada | Media (5.1) | 0.21% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating specific parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious… | |
| Analizada | Alta (8.7) | 0.57% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that allows for SQL injection and remote code execution through NetworkServlet.archiveTrap(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not sanitized, allowing an attacker to perform SQL injection and… | |
| Analizada | Alta (7.1) | 0.32% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that allows for argument injection in the NetworkServlet.restoreDatabase(). This issue requires an authenticated attacker with at least user-level privileges. An input parameter can be used directly in a command without proper sanitization, allowing arbitrary arguments to be… | |
| Analizada | Alta (8.7) | 6.1% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that could allow for SQL injection and remote code execution through NetworkServlet.getNextTrapPage(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters in this function are not properly sanitized, allowing an attacker to… | |
| Analizada | Media (5.1) | 0.21% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By exploiting this flaw, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other malicious activities. | |
| Analizada | Alta (8.7) | 0.57% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that could allow SQL injection and remote code execution through NetworkServlet.archiveTrapRange(). This issue requires an authenticated attacker with at least user-level privileges. Certain input parameters are not properly sanitized, allowing an attacker to perform SQL… | |
| Aplazada | Alta (7.1) | 0.31% | — | Advantech IviewAI | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that allows for argument injection in NetworkServlet.backupDatabase(). This issue requires an authenticated attacker with at least user-level privileges. Certain parameters can be used directly in a command without proper sanitization, allowing arbitrary arguments to be… | |
| Analizada | Alta (7.2) | 0.29% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView that could allow for SQL injection through the CUtils.checkSQLInjection() function. This vulnerability can be exploited by an authenticated attacker with at least user-level privileges, potentially leading to information disclosure or a denial-of-service condition. | |
| Analizada | Media (5.3) | 4.7% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView in NetworkServlet.processImportRequest() that could allow for a directory traversal attack. This issue requires an authenticated attacker with at least user-level privileges. A specific parameter is not properly sanitized or normalized, potentially allowing an attacker to… | |
| Analizada | Media (5.1) | 0.21% | — | Advantech Iview | 11/7/2025 | 17/6/2026 | A vulnerability exists in Advantech iView versions prior to 5.7.05 build 7057, which could allow a reflected cross-site scripting (XSS) attack. By manipulating certain input parameters, an attacker could execute unauthorized scripts in the user's browser, potentially leading to information disclosure or other… | |
| Aplazada | Media (6.5) | 0.23% | — | Uniview EzplayerAI | 16/1/2025 | 17/6/2026 | Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in ezmarketing EZPlayer ezplayer allows Stored XSS.This issue affects EZPlayer: from n/a through <= 1.0.10. | |
| Analizada | Alta (7.5) | 1.3% | — | Advantech Iview | 22/11/2024 | 17/6/2026 | Advantech iView ConfigurationServlet SQL Injection Information Disclosure Vulnerability. This vulnerability allows remote attackers to disclose sensitive information on affected installations of Advantech iView. Authentication is not required to exploit this vulnerability. The specific flaw exists within the… | |
| Analizada | Media (6.3) | 0.44% | — | Bandisoft Bandiview | 3/10/2024 | 17/6/2026 | Bandisoft BandiView 7.05 is vulnerable to Buffer Overflow via sub_0x410d1d. The vulnerability occurs due to insufficient validation of PSD files. | |
| Analizada | Media (6.3) | 0.44% | — | Bandisoft Bandiview | 3/10/2024 | 17/6/2026 | Bandisoft BandiView 7.05 is Incorrect Access Control via sub_0x232bd8 resulting in denial of service (DOS). | |
| Analizada | Media (6.5) | 0.46% | — | Bandisoft Bandiview | 3/10/2024 | 17/6/2026 | Bandisoft BandiView 7.05 is vulnerable to Incorrect Access Control in sub_0x3d80fc via a crafted POC file. | |
| Modificada | Media (4.8) | 0.89% | — | Uniview Nvr301-04s2-p4 Firmware | 10/6/2024 | 17/6/2026 | Uniview NVR301-04S2-P4 is vulnerable to reflected cross-site scripting attack (XSS). An attacker could send a user a URL that if clicked on could execute malicious JavaScript in their browser. This vulnerability also requires authentication before it can be exploited, so the scope and severity is limited. Also, even… | |
| Analizada | Media (5.5) | 0.41% | — | Bandisoft Bandiview | 12/4/2024 | 17/6/2026 | Buffer Overflow vulnerability in bandisoft bandiview v7.0, allows local attackers to cause a denial of service (DoS) via exr image file. | |
| Modificada | Crítica (9.8) | 32% | — | Uniview ISC 2500-s Firmware | 22/1/2024 | 17/6/2026 | ** UNSUPPORTED WHEN ASSIGNED ** A vulnerability, which was classified as critical, has been found in Uniview ISC 2500-S up to 20210930. Affected by this issue is the function setNatConfig of the file /Interface/DevManage/VM.php. The manipulation of the argument natAddress/natPort/natServerPort leads to os command… |