Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2862▼ 326 respecto a la semana anterior
Críticas / altas1389▼ 28 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)293▼ 216 respecto a la semana anterior
275 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Aplazada | Media (5.4) | 0.23% | — | Openbk7231tAI | 5/8/2026 | 26/8/2026 | OpenBK7231T's http_fn_ota_exec() (src/httpserver/http_fns.c) reflects the `host` query parameter directly into an HTML response via hprintf255(request, "<h3>OTA requested for %s!</h3>", tmpA) with no HTML encoding, allowing a crafted URL such as /ota_exec?host=<script>alert(1)</script> to execute JavaScript in an… | |
| Aplazada | Alta (8.5) | 0.28% | — | Openbk7231tAI | 5/8/2026 | 26/8/2026 | OpenBK7231T's CHANNEL_SetLabel (src/cmnds/cmd_channels.c) stores channel labels received via the MQTT SetChannelLabel command using strdup with no HTML sanitization. CHANNEL_GetLabel returns these labels unsanitized, and they are rendered via hprintf255 at 15+ locations in src/httpserver/http_fns.c with no HTML… | |
| Aplazada | Media (6.5) | 0.17% | — | Openbk7231tAI | 5/8/2026 | 26/8/2026 | OpenBK7231T's /cfg_wifi_set endpoint (src/httpserver/http_fns.c) accepts configuration changes via a plain GET request with no CSRF token. If the parameter is absent from the request, an else-branch silently clears the device's web admin password to an empty string. | |
| Analizada | Alta (7.8) | 0.16% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Crítica (9.8) | 0.50% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | CWE-20 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Media (6.1) | 0.24% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | CWE-79 vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Alta (7.5) | 0.44% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Alta (7.5) | 0.44% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Missing Release of Memory after Effective Lifetime vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Alta (7.5) | 0.27% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Integer Overflow or Wraparound vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-11. | |
| Analizada | Crítica (9.8) | 0.41% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | Out-of-bounds Write vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10. | |
| Analizada | Alta (7.5) | 0.27% | — | Molotovcherry Android-imagemagick7 | 24/3/2026 | 17/6/2026 | NULL Pointer Dereference vulnerability in MolotovCherry Android-ImageMagick7.This issue affects Android-ImageMagick7: before 7.1.2-10. | |
| Analizada | Media (6.9) | 0.21% | — | HP M9l65a FirmwareHP D9l20a FirmwareHP K7s32a FirmwareHP D9l21a Firmware+37 | 10/2/2026 | 17/6/2026 | Certain HP OfficeJet Pro printers may expose information if Cross‑Origin Resource Sharing (CORS) is misconfigured, potentially allowing unauthorized web origins to access device resource. CORS is disabled by default on Pro‑class devices and can only be enabled by an administrator through the Embedded Web Server (EWS).… | |
| Analizada | Media (6.9) | 0.28% | — | HP D9l18a FirmwareHP M9l66a FirmwareHP M9l67a FirmwareHP T0g46a Firmware+13 | 10/2/2026 | 17/6/2026 | Certain HP OfficeJet Pro printers may be vulnerable to potential denial of service when the IPP requests are mishandled, failing to establish a TCP connection. | |
| Analizada | Alta (8.8) | 0.78% | — | Dormakabagroup Dormakaba Access Manager 9200-k7 FirmwareDormakabagroup Dormakaba Access Manager 9230-k7 FirmwareDormakabagroup Dormakaba Access Manager 9290-k7 FirmwareDormakabagroup Dormakaba Access Manager 9200-k5 Firmware+2 | 26/1/2026 | 17/6/2026 | The binary serving the web server and executing basically all actions launched from the Web UI is running with root privileges. This is against the least privilege principle. If an attacker is able to execute code on the system via other vulnerabilities it is possible to directly execute commands with highest… | |
| Aplazada | Alta (7) | 0.11% | — | K7AIK5AI | 26/1/2026 | 17/6/2026 | With physical access to the device and enough time an attacker can desolder the flash memory, modify it and then reinstall it because of missing encryption. Thus, essential files, such as "/etc/passwd", as well as stored certificates, cryptographic keys, stored PINs and so on can be modified and read, in order to gain… | |
| Analizada | Alta (7.7) | 0.15% | — | K7computing K7 Ultimate Security | 22/12/2025 | 17/6/2026 | An issue was discovered in K7 Ultimate Security 17.0.2045. A Local Privilege Escalation (LPE) vulnerability in the K7 Ultimate Security antivirus can be exploited by a local unprivileged user on default installations of the product. Insecure access to a named pipe allows unprivileged users to edit any registry key,… | |
| Aplazada | Alta (7.2) | 0.54% | 💥 PoC | K7 Security Anti-malwareAIK7 Rkscan.sysAI | 9/9/2025 | 17/6/2026 | K7RKScan.sys 23.0.0.10, part of the K7 Security Anti-Malware suite, allows an admin-privileged user to send crafted IOCTL requests to terminate processes that are protected through a third-party implementation. This is caused by insufficient caller validation in the driver's IOCTL handler, enabling unauthorized… | |
| Aplazada | Media (5.6) | 0.23% | 💥 PoC | K7 Security Anti-malwareAIK7 Rkscan.sysAI | 11/6/2025 | 17/6/2026 | A vulnerability in the K7RKScan.sys driver, part of the K7 Security Anti-Malware suite, allows a local low-privilege user to send crafted IOCTL requests to terminate a wide range of processes running with administrative or system-level privileges, with the exception of those inherently protected by the operating… | |
| Analizada | Crítica (9.8) | 18% | 💥 PoC | Fortinet FortiwebFortinet FortiswitchmanagerFortinet FortiswitchFortinet Fortiproxy+4 | 24/3/2025 | 17/6/2026 | A buffer underwrite ('buffer underflow') vulnerability in the administrative interface of Fortinet FortiOS version 7.2.0 through 7.2.3, version 7.0.0 through 7.0.6, version 6.4.0 through 6.4.11 and version 6.2.12 and below, FortiProxy version 7.2.0 through 7.2.2, version 7.0.0 through 7.0.8, version 2.0.12 and below… | |
| Modificada | Media (5.5) | 0.99% | 💥 Exploit | K7computing K7 Ultimate Security | 6/8/2024 | 17/6/2026 | K7RKScan.sys in K7 Ultimate Security before 17.0.2019 allows local users to cause a denial of service (BSOD) because of a NULL pointer dereference. | |
| Analizada | Media (6.3) | 0.21% | — | HP 26k70b FirmwareHP 297x1a FirmwareHP 2a9q5a FirmwareHP 26k72a Firmware+24 | 27/3/2024 | 17/6/2026 | A user with administrative privileges can create a compromised dll file of the same name as the original dll within the HP printer’s Firmware Update Utility (FUU) bundle and place it in the Microsoft Windows default downloads directory which can lead to potential arbitrary code execution. | |
| Modificada | Alta (7.5) | 0.85% | — | HP Officejet PRO 8730 D9l19a FirmwareHP Officejet PRO 8730 M9l74a FirmwareHP Officejet PRO 8730 M9l75a FirmwareHP Officejet PRO 8730 M9l76a Firmware+8 | 14/12/2023 | 17/6/2026 | Certain HP OfficeJet Pro printers are potentially vulnerable to a Denial of Service when sending a SOAP message to the service on TCP port 3911 that contains a body but no header. | |
| Modificada | Alta (8.7) | 0.96% | — | Siemens 6gk7243-8rx30-0xe0 FirmwareSiemens 6gk7543-1ax00-0xe0 FirmwareSiemens 6ag1543-1ax00-2xe0 FirmwareSiemens Simatic CP 1242-7 V2 Firmware+5 | 12/12/2023 | 17/6/2026 | A vulnerability has been identified in SIMATIC CP 1242-7 V2 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 (incl. SIPLUS variants) (All versions < V3.4.29), SIMATIC CP 1243-1 DNP3 (incl. SIPLUS variants) (All versions), SIMATIC CP 1243-1 IEC (incl. SIPLUS variants) (All versions < V3.4.29),… | |
| Modificada | Crítica (9.8) | 1.5% | — | HP Color Laserjet Cm4540 MFP Cc419a FirmwareHP Color Laserjet Cm4540 MFP Cc420a FirmwareHP Color Laserjet Cm4540 MFP Cc421a FirmwareHP Color Laserjet Cm5525 MFP Ce707a Firmware+2696 | 12/12/2022 | 17/6/2026 | Certain HP Print products and Digital Sending products may be vulnerable to potential remote code execution and buffer overflow with use of Link-Local Multicast Name Resolution or LLMNR. | |
| Modificada | Crítica (9.8) | 1.3% | — | HP P4c78a FirmwareHP P4c85a FirmwareHP T3p03a FirmwareHP P4c86a Firmware+95 | 26/9/2022 | 17/6/2026 | Certain HP Print Products are potentially vulnerable to Buffer Overflow. |