Vulnerabilidades em Helmholz

71 resultados
Análise Vexday

O portfólio de vulnerabilidades da Helmholz reúne 70 CVEs catalogadas, com um volume expressivo de 42 entradas registradas nos últimos 90 dias, sinalizando um ciclo recente de descobertas que merece acompanhamento contínuo. Nenhuma dessas vulnerabilidades consta no catálogo de explorações ativas da CISA (KEV), e a taxa de exploração situa-se abaixo da média geral do catálogo, o que indica menor pressão ofensiva imediata. A CVE mais relevante no momento, CVE-2024-45274, apresenta EPSS de 0,0154, e o tipo de falha mais recorrente é CWE-89 (injeção de SQL), categoria que, quando presente em dispositivos industriais ou de rede, pode permitir acesso não autorizado a dados e comprometimento de integridade. As três vulnerabilidades de severidade crítica e a ausência de PoCs públicas conhecidas reduzem o risco de exploração oportunista a curto prazo, mas a concentração de novas CVEs recentes exige triagem prioritária para identificar possíveis encadeamentos de falhas.

CVE-2026-32969HIGHPre-Auth Blind SQLi in userinfo EndpointEPSS 0.4%CVE-2025-3092HIGHMB connect line: Observable response discrepancy in mbCONNECT24/mymbCONNECT24EPSS 0.4%CVE-2025-3090HIGHMB connect line: Missing Authentication in mbCONNECT24/mymbCONNECT24EPSS 0.4%CVE-2026-40850HIGHUnauthenticated SQLi in getAccountData functionEPSS 0.4%CVE-2026-40852HIGHCommand injection via malicious configurationEPSS 0.4%CVE-2023-34412MEDIUMStored XXS vulnerability in mbnet, mbnet.rokey, REX 200 and REX 250EPSS 0.3%CVE-2025-3091HIGHMB connect line: Authorization bypass in mbCONNECT24/mymbCONNECT24EPSS 0.3%CVE-2023-4834MEDIUMIn Red Lion Europe mbCONNECT24 and mymbCONNECT24 and Helmholz myREX24 and myREX24.virtual up to and including 2.14.2 an improperly implementEPSS 0.3%CVE-2026-40831HIGHAuthenticated SQLi in Easy ViewEPSS 0.3%CVE-2026-40817HIGHUnauthenticated SQLi in getAlarmProfiles functionEPSS 0.3%CVE-2026-40810HIGHUnauthenticated SQLi in userinfo EndpointEPSS 0.3%CVE-2026-40818HIGHUnauthenticated SQLi in _mb24confi_getDevice function functionEPSS 0.3%CVE-2026-40814HIGHUnauthenticated SQLi in _mb24confi_getTagAlarm functionEPSS 0.3%CVE-2026-40813HIGHUnauthenticated SQLi in getLiveValuesEPSS 0.3%CVE-2026-40812HIGHUnauthenticated SQLi in getLiveValues functionEPSS 0.3%CVE-2026-40819HIGHUnauthenticated SQLi in sync_data24 taskEPSS 0.3%CVE-2026-40816HIGHUnauthenticated SQLi in _mb24confi_getTagAlarm functionEPSS 0.3%CVE-2026-40811HIGHUnauthenticated SQLi in ssoabstractserviceEPSS 0.3%CVE-2026-40815HIGHUnauthenticated SQLi in _mb24api_getUserAccount functionEPSS 0.3%CVE-2024-45271HIGHMB connect line/Helmholz: Remote code execution due to improper input validationEPSS 0.3%