Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2561▼ 314 respecto a la semana anterior
Críticas / altas1347▲ 83 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 7 respecto a la semana anterior
Sin puntuar (sin CVSS)62▼ 466 respecto a la semana anterior
–

102 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
Pendiente de análisisAlta (7.1)0.10%—Redpine Signals Rs9116wAIRedpine Signals Siwx917AI8/9/20268/9/2026
An unencrypted 'pause encryption request' message causes a denial of service in the in the RS9116W/SiWx917. See vulnerability B-E10 in the related paper below.
Pendiente de análisisAlta (8.8)0.35%—Redpine Signals Rs9116wAISilabs Siwx917AI13/8/20268/9/2026
Spoofing an already bonded device can force either RS9116W or SiWx917 to re-pair/bond with a rogue device. See V1 in BLERP paper below
Pendiente de análisisMedia (6.9)0.30%—Suzuki SwiftAIAlpsalpine Cwtr53r0AI25/6/202626/6/2026
Remote Keyless Entry System (RKES), using the 433 MHz key fob bearing FCC ID CWTR53R0 manufactured by ALPS ALPINE CO., LTD., is vulnerable to a roll-back attack against its rolling-code authentication. An attacker within RF range who records two consecutive lock or unlock transmissions from a legitimate key fob can…
Pendiente de análisisAlta (7.4)0.25%—Redpine Signals Rs9116AI14/5/202617/6/2026
Timing limitations of the HRNG in RS9116 when power save mode is enabled results in predictable values
AplazadaAlta (7.1)0.25%—Foreverpinetree ThebeAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thebe thebe allows Reflected XSS.This issue affects Thebe: from n/a through <= 1.3.0.
AplazadaAlta (7.1)0.25%—Foreverpinetree ThecsAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree Thecs thecs allows Reflected XSS.This issue affects Thecs: from n/a through <= 1.4.7.
AplazadaAlta (7.1)0.25%—Foreverpinetree ThebiAI5/3/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheBi thebi allows Reflected XSS.This issue affects TheBi: from n/a through <= 1.0.5.
AplazadaAlta (8.8)0.38%—Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI15/2/202617/6/2026
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper…
AplazadaAlta (8.8)0.38%—Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI15/2/202617/6/2026
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper…
AplazadaAlta (8.8)0.38%—Bosch Infotainment ECUAIAlpsalpine Bluetooth StackAI15/2/202617/6/2026
The specific flaw exists within the Bluetooth stack developed by Alps Alpine of the Infotainment ECU manufactured by Bosch. The issue results from the lack of proper boundary validation of user-supplied data, which can result in a stack-based buffer overflow when receiving a specific packet on the established upper…
AplazadaAlta (7.1)0.29%—Foreverpinetree ThenaAI22/1/202617/6/2026
Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting') vulnerability in foreverpinetree TheNa thena allows Reflected XSS.This issue affects TheNa: from n/a through <= 1.5.5.
ModificadaAlta (8.1)0.50%—Axiomthemes Pinevale18/12/202517/6/2026
Improper Control of Filename for Include/Require Statement in PHP Program ('PHP Remote File Inclusion') vulnerability in axiomthemes Pinevale pinevale allows PHP Local File Inclusion.This issue affects Pinevale: from n/a through <= 1.0.14.
AnalizadaMedia (6.9)0.40%—Spinetix Fusion Digital Signage10/12/202517/6/2026
SpinetiX Fusion Digital Signage 3.4.8 contains a username enumeration vulnerability in its login script that allows attackers to identify valid user accounts. Attackers can send crafted login requests with different usernames to distinguish between existing and non-existing accounts by analyzing the server's error…
AnalizadaAlta (8.7)0.42%—Spinetix Fusion Digital Signage10/12/202517/6/2026
SpinetiX Fusion Digital Signage 3.4.8 contains an unauthenticated information disclosure vulnerability in the database backup directory. Attackers can access the /content/files/backups/ endpoint to download sensitive backup files containing user credentials and system information.
AnalizadaMedia (6.9)0.27%—Spinetix Fusion Digital Signage10/12/202517/6/2026
SpinetiX Fusion Digital Signage 3.4.8 contains a cross-site request forgery vulnerability that allows attackers to create administrative user accounts without proper request validation. Attackers can craft a malicious web page that automatically submits a form to create a new admin user with full system privileges…
AnalizadaAlta (8.8)0.90%—Spinetix Fusion Digital Signage10/12/202517/6/2026
SpinetiX Fusion Digital Signage 3.4.8 and lower contains an authenticated path traversal vulnerability that allows attackers to manipulate file backup and deletion operations through unverified input parameters. Attackers can exploit path traversal techniques in index.php to write backup files to arbitrary locations…
AplazadaAlta (7.1)0.18%—Redpine Signals Rs9116 Wiseconnect SDKAI17/11/202517/6/2026
In a Bluetooth device, using RS9116-WiseConnect SDK experiences a Denial of Service, if it receives malformed L2CAP packets, only hard reset will bring the device to normal operation
AnalizadaAlta (8)0.69%—Alpsalpine Ilx-507 Firmware1/8/202517/6/2026
Alpine iLX-507 Command Injection Remote Code Execution. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the Tidal music streaming…
AnalizadaAlta (7.4)0.28%—Alpsalpine Ilx-507 Firmware1/8/202517/6/2026
Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a malicious…
AnalizadaAlta (8)0.13%—Alpsalpine Ilx-507 Firmware1/8/202517/6/2026
Alpine iLX-507 TIDAL Improper Certificate Validation Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the TIDAL music streaming…
AnalizadaAlta (7.4)0.29%—Alpsalpine Ilx-507 Firmware1/8/202517/6/2026
Alpine iLX-507 AVRCP Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to a…
AnalizadaMedia (6.8)0.25%—Alpsalpine Ilx-507 Firmware1/8/202517/6/2026
Alpine iLX-507 CarPlay Stack-based Buffer Overflow Code Execution Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaMedia (6.6)0.73%—Alpsalpine Ilx-507 Firmware1/8/202517/6/2026
Alpine iLX-507 UPDM_wstpCBCUpdStart Command Injection Vulnerability. This vulnerability allows physically present attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. Authentication is not required to exploit this vulnerability. The specific flaw exists within the…
AnalizadaAlta (7.4)0.29%—Alpsalpine Ilx-507 Firmware1/8/202517/6/2026
Alpine iLX-507 vCard Parsing Stack-based Buffer Overflow Remote Code Execution Vulnerability. This vulnerability allows network-adjacent attackers to execute arbitrary code on affected installations of Alpine iLX-507 devices. User interaction is required to exploit this vulnerability in that the target must connect to…
AplazadaMedia (4.3)0.23%—Sharespine Woocommerce ConnectorAI16/5/202517/6/2026
Missing Authorization vulnerability in Sharespine Sharespine Woocommerce Connector sharespine-woocommerce-connector allows Exploiting Incorrectly Configured Access Control Security Levels.This issue affects Sharespine Woocommerce Connector: from n/a through <= 4.7.55.