Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2715▼ 529 respecto a la semana anterior
Críticas / altas1290▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)225▼ 276 respecto a la semana anterior
96 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Alta (8.3) | 0.17% | — | Milesight IOT DevicesAI | 26/8/2026 | 9/9/2026 | A cleartext transmission of sensitive information vulnerability in the NFC interface of multiple Milesight IoT device models running affected firmware versions allows an unauthenticated attacker with physical proximity to retrieve LoRaWAN ABP NwkSKey and AppSKey values and D2D keys via an NFC read operation. The… | |
| Pendiente de análisis | Alta (7.3) | 1.5% | — | Milesight Camera FirmwareAI | 28/4/2026 | 25/7/2026 | A command injection vulnerability exists in the web server of specific firmware versions of Milesight cameras. | |
| Pendiente de análisis | Crítica (9.2) | 0.39% | — | Milesight Aiot CamerasAI | 28/4/2026 | 25/7/2026 | Specific firmware versions of Milesight AIOT cameras use SSL certificates with default private keys. | |
| Pendiente de análisis | Alta (8.6) | 0.29% | — | Milesight Aiot Camera FirmwareAI | 28/4/2026 | 20/7/2026 | An out-of-bounds memory access vulnerability exists in specific firmware versions of Milesight AIOT cameras. | |
| Pendiente de análisis | Alta (7.7) | 0.35% | — | Milesight Aiot Camera FirmwareAI | 28/4/2026 | 25/7/2026 | Specific firmware versions of Milesight AIOT camera firmware contain hard-coded credentials. | |
| Pendiente de análisis | Alta (7.3) | 0.28% | — | Milesight Aiot CamerasAI | 27/4/2026 | 25/7/2026 | A weak key generation vulnerability exists in specific firmware versions of Milesight AIOT cameras allows authorization to be bypassed. | |
| Analizada | Media (6.1) | 0.35% | — | Milesight Ug65-868m-ea Firmware | 7/5/2025 | 17/6/2026 | An admin user can gain unauthorized write access to the /etc/rc.local file on the device, which is executed on a system boot. | |
| Analizada | Media (6.1) | 0.27% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-79: Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') | |
| Analizada | Alta (7.4) | 0.35% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-320: Key Management Errors may allow Authentication Bypass and Man-In-The-Middle Traffic | |
| Analizada | Alta (7.5) | 0.42% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-20 Improper Input Validation may allow Denial of Service | |
| Analizada | Crítica (9.8) | 0.52% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-330 Use of Insufficiently Random Values may allow Authentication Bypass | |
| Analizada | Crítica (9.8) | 0.47% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-305 Missing Authentication for Critical Function | |
| Analizada | Crítica (9.8) | 0.60% | — | Milesight Devicehub | 2/6/2024 | 17/6/2026 | MileSight DeviceHub - CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal') may allow Unauthenticated RCE | |
| Modificada | Alta (8.8) | 0.64% | — | Milesight Ur32l Firmware | 1/5/2024 | 17/6/2026 | A firmware update vulnerability exists in the luci2-io file-import functionality of Milesight UR32L v32.3.0.7-r2. A specially crafted network request can lead to arbitrary firmware update. An attacker can send a network request to trigger this vulnerability. | |
| Modificada | Media (6.1) | 0.42% | — | Milesight Ur51 FirmwareMilesight Ur52 FirmwareMilesight Ur55 FirmwareMilesight Ur32l Firmware+3 | 5/10/2023 | 17/6/2026 | Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 was discovered to contain a cross-site scripting (XSS) vulnerability via the admin panel. | |
| Modificada | Alta (7.5) | 64% | 💥 Exploit | Milesight Ur5x FirmwareMilesight Ur32l FirmwareMilesight Ur32 FirmwareMilesight Ur35 Firmware+1 | 4/10/2023 | 9/7/2026 | An information disclosure in Milesight UR5X, UR32L, UR32, UR35, UR41 before v35.3.0.7 allows attackers to access sensitive router components. | |
| Modificada | Alta (7.2) | 3.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages a new… | |
| Modificada | Alta (7.2) | 3.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Two OS command injection vulnerabilities exist in the zebra vlan_name functionality of Milesight UR32L v32.3.0.5. A specially crafted network request can lead to command execution. An attacker can send a network request to trigger these vulnerabilities.This command injection is in the code branch that manages an… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… | |
| Modificada | Alta (7.2) | 1.5% | — | Milesight Ur32l Firmware | 6/7/2023 | 17/6/2026 | Multiple buffer overflow vulnerabilities exist in the vtysh_ubus binary of Milesight UR32L v32.3.0.5 due to the use of an unsafe sprintf pattern. A specially crafted HTTP request can lead to arbitrary code execution. An attacker with high privileges can send HTTP requests to trigger these vulnerabilities.This buffer… |