Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2704▼ 598 respecto a la semana anterior
Críticas / altas1288▼ 199 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)299▼ 211 respecto a la semana anterior
46 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Media (6.3) | 0.32% | — | Gl-inet Comet Gl-rm1 Firmware | 17/3/2026 | 17/6/2026 | The GL-iNet Comet (GL-RM1) KVM connects to a GL-iNet site during boot-up to provision client and CA certificates. The GL-RM1 does not verify certificates used for this connection, allowing an attacker-in-the-middle to serve invalid client and CA certificates. The GL-RM1 will attempt to use the invalid certificates and… | |
| Analizada | Crítica (9.3) | 0.55% | — | Gl-inet Comet Gl-rm1 Firmware | 17/3/2026 | 17/6/2026 | The GL-iNet Comet (GL-RM1) KVM web interface does not limit login requests, enabling brute-force attempts to guess credentials. | |
| Analizada | Alta (7) | 0.34% | — | Gl-inet Comet Gl-rm1 Firmware | 17/3/2026 | 17/6/2026 | The GL-iNet Comet (GL-RM1) KVM before 1.8.2 does not require authentication on the UART serial console. This attack requires physically opening the device and connecting to the UART pins. | |
| Analizada | Alta (7) | 0.13% | — | Gl-inet Comet Gl-rm1 Firmware | 17/3/2026 | 17/6/2026 | The GL-iNet Comet (GL-RM1) KVM before version 1.8.2 does not sufficiently verify the authenticity of uploaded firmware files. An attacker-in-the-middle or a compromised update server could modify the firmware and the corresponding MD5 hash to pass verification. | |
| Modificada | Media (4.6) | 0.15% | — | Idec Kit-fc6a-24-kc FirmwareIdec Kit-fc6a-24-pc FirmwareIdec Kit-fc6a-24-ra FirmwareIdec Kit-fc6a-24-ra-hg1g Firmware+87 | 4/9/2024 | 17/6/2026 | Cleartext transmission of sensitive information vulnerability exists in multiple IDEC PLCs. If an attacker sends a specific command to PLC's serial communication port, user credentials may be obtained. As a result, the program of the PLC may be obtained, and the PLC may be manipulated. | |
| Analizada | Alta (7.5) | 0.39% | — | Teldat M1 Firmware | 26/6/2024 | 17/6/2026 | Incorrect access control in Teldat M1 v11.00.05.50.01 allows attackers to obtain sensitive information via a crafted query string. | |
| Modificada | Media (5.5) | 1.9% | — | Fujitsu Esprimo D556/2 FirmwareFujitsu Esprimo D6011 FirmwareFujitsu Esprimo D6012 FirmwareFujitsu Esprimo D7010 Firmware+183 | 7/12/2023 | 17/6/2026 | A LogoFAIL issue was discovered in BmpDecoderDxe in Insyde InsydeH2O with kernel 5.2 before 05.28.47, 5.3 before 05.37.47, 5.4 before 05.45.47, 5.5 before 05.53.47, and 5.6 before 05.60.47 for certain Lenovo devices. Image parsing of crafted BMP logo files can copy data to a specific address during the DXE phase of… | |
| Modificada | Media (4.7) | 0.11% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 11/8/2023 | 17/6/2026 | Race condition in firmware for some Intel(R) Ethernet Controllers and Adapters E810 Series before version 1.7.2.4 may allow an authenticated user to potentially enable denial of service via local access. | |
| Modificada | Media (4.4) | 0.19% | — | Intel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 FirmwareIntel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Controller X710-am2 Firmware+11 | 16/2/2023 | 17/6/2026 | Out-of-bounds write in firmware for some Intel(R) Ethernet Network Controllers and Adapters E810 Series before version 1.7.0.8 and some Intel(R) Ethernet 700 Series Controllers and Adapters before version 9.101 may allow a privileged user to potentially enable denial of service via local access. | |
| Modificada | Crítica (9.8) | 1.1% | — | Festo BUS Module Cpx-e-ep FirmwareFesto BUS Node Cpx-fb32 FirmwareFesto BUS Node Cpx-fb33 FirmwareFesto BUS Node Cpx-fb36 Firmware+95 | 1/12/2022 | 17/6/2026 | In multiple products by Festo a remote unauthenticated attacker could use functions of an undocumented protocol which could lead to a complete loss of confidentiality, integrity and availability. | |
| Modificada | Crítica (9.8) | 2.6% | — | Festo Controller Cecc-x-m1 FirmwareFesto Controller Cecc-x-m1-mv FirmwareFesto Controller Cecc-x-m1-mv-s1 FirmwareFesto Controller Cecc-x-m1-ys-l1 Firmware+4 | 13/6/2022 | 17/6/2026 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-refresh-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection. | |
| Modificada | Crítica (9.8) | 2.6% | — | Festo Controller Cecc-x-m1 FirmwareFesto Controller Cecc-x-m1-mv FirmwareFesto Controller Cecc-x-m1-mv-s1 FirmwareFesto Controller Cecc-x-m1-ys-l1 Firmware+4 | 13/6/2022 | 17/6/2026 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-acknerr-request" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection. | |
| Modificada | Crítica (9.8) | 2.9% | — | Festo Controller Cecc-x-m1 FirmwareFesto Controller Cecc-x-m1-mv FirmwareFesto Controller Cecc-x-m1-mv-s1 FirmwareFesto Controller Cecc-x-m1-ys-l1 Firmware+4 | 13/6/2022 | 17/6/2026 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-off" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection. | |
| Modificada | Crítica (9.8) | 2.9% | — | Festo Controller Cecc-x-m1 FirmwareFesto Controller Cecc-x-m1-mv FirmwareFesto Controller Cecc-x-m1-mv-s1 FirmwareFesto Controller Cecc-x-m1-ys-l1 Firmware+4 | 13/6/2022 | 17/6/2026 | In Festo Controller CECC-X-M1 product family in multiple versions, the http-endpoint "cecc-x-web-viewer-request-on" POST request doesn’t check for port syntax. This can result in unauthorized execution of system commands with root privileges due to improper access control command injection. | |
| Modificada | Alta (7.5) | 0.90% | — | Siemens Simatic CFU DIQ FirmwareSiemens Simatic CFU PA FirmwareSiemens Simatic S7-300 CPU FirmwareSiemens Simatic S7-400h V6 Firmware+8 | 12/4/2022 | 17/6/2026 | The PROFINET (PNIO) stack, when integrated with the Interniche IP stack, improperly handles internal resources for TCP segments where the minimum TCP-Header length is less than defined. This could allow an attacker to create a denial of service condition for TCP services on affected devices by sending specially… | |
| Modificada | Alta (8.1) | 0.92% | — | Kalkitech Sync241-m1 FirmwareKalkitech Sync241-m2 FirmwareKalkitech Sync241-m4 FirmwareKalkitech Sync261-m1 Firmware+16 | 6/1/2022 | 17/6/2026 | A security vulnerability originally reported in the SYNC2101 product, and applicable to specific sub-families of SYNC devices, allows an attacker to download the configuration file used in the device and apply a modified configuration file back to the device. The attack requires network access to the SYNC device and… | |
| Modificada | Media (6.7) | 0.25% | — | Intel Ethernet Controller V710-at2 FirmwareIntel Ethernet Controller X710-tm4 FirmwareIntel Ethernet Controller X710-at2 FirmwareIntel Ethernet Controller Xxv710-am2 Firmware+7 | 17/11/2021 | 17/6/2026 | Out-of-bounds write in the firmware for Intel(R) Ethernet 700 Series Controllers before version 8.2 may allow a privileged user to potentially enable an escalation of privilege via local access. | |
| Modificada | Media (4.4) | 0.23% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 17/11/2021 | 17/6/2026 | Improper input validation in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.6.0.6 may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Media (4.4) | 0.23% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 17/11/2021 | 17/6/2026 | Improper access control in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to potentially enable a denial of service via local access. | |
| Modificada | Media (4.4) | 0.23% | — | Intel Ethernet Network Controller E810-xxvam2 FirmwareIntel Ethernet Network Controller E810-cam1 FirmwareIntel Ethernet Network Controller E810-cam2 Firmware | 17/11/2021 | 17/6/2026 | Protection mechanism failure in the firmware for the Intel(R) Ethernet Network Controller E810 before version 1.5.5.6 may allow a privileged user to enable a denial of service via local access. | |
| Modificada | Media (6.1) | 0.83% | — | Cisco Integrated Management ControllerCisco UCS ManagerCisco Encs 5100 FirmwareCisco Encs 5400 Firmware+21 | 6/5/2021 | 17/6/2026 | A vulnerability in the web-based management interface of Cisco Integrated Management Controller (IMC) Software could allow an unauthenticated, remote attacker to redirect a user to a malicious web page. This vulnerability is due to improper input validation of the parameters in an HTTP request. An attacker could… | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Improper buffer restrictions in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Insufficient access control in the firmware of the Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.38% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | A logic issue in the firmware of the Intel(R) Ethernet 700 Series Controllers may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. | |
| Modificada | Media (6.7) | 0.34% | — | Intel V710-at2 FirmwareIntel X710-tm4 FirmwareIntel X710-at2 FirmwareIntel Xxv710-am2 Firmware+4 | 12/11/2020 | 17/6/2026 | Protection mechanism failure in Intel(R) Ethernet 700 Series Controllers before version 7.3 may allow a privileged user to potentially enable escalation of privilege and/or denial of service via local access. |