Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2737▼ 486 respecto a la semana anterior
Críticas / altas1302▼ 188 respecto a la semana anterior
Nueva explotación activa (KEV)3▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)227▼ 275 respecto a la semana anterior
–

247 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaAlta (7)0.13%—Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096au Firmware+3221/11/201917/6/2026
Race condition due to the lack of resource lock which will be concurrently modified in the memcpy statement leads to out of bound access in Snapdragon Auto, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT, Snapdragon Mobile, Snapdragon Voice & Music,…
ModificadaAlta (7.8)0.22%—Qualcomm Apq8009 FirmwareQualcomm Apq8017 FirmwareQualcomm Apq8053 FirmwareQualcomm Apq8096 Firmware+5121/11/201917/6/2026
Out-of-bounds memory access in Qurt kernel function when using the identifier to access Qurt kernel buffer to retrieve thread data. in Snapdragon Auto, Snapdragon Compute, Snapdragon Connectivity, Snapdragon Consumer Electronics Connectivity, Snapdragon Consumer IOT, Snapdragon Industrial IOT, Snapdragon IoT,…
ModificadaAlta (7.8)0.47%—Asus Zenfone AR Firmware14/11/201917/6/2026
The Asus ZenFone AR Android device with a build fingerprint of asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys contains a pre-installed app with a package name of com.asus.splendidcommandagent app (versionCode=1510200105, versionName=1.2.0.21_180605) that allows other pre-installed…
ModificadaAlta (7.8)0.45%—Asus Zenfone AR Firmware14/11/201917/6/2026
The Asus ASUS_A002_2 Android device with a build fingerprint of asus/WW_ASUS_A002_2/ASUS_A002_2:7.0/NRD90M/14.1610.1802.18-20180321:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed…
ModificadaAlta (7.8)0.45%—Asus Zenfone AR Firmware14/11/201917/6/2026
The Asus ASUS_A002 Android device with a build fingerprint of asus/WW_ASUS_A002/ASUS_A002:7.0/NRD90M/14.1600.1805.51-20180626:user/release-keys contains a pre-installed app with a package name of com.asus.loguploaderproxy app (versionCode=1570000020, versionName=7.0.0.4_170901) that allows other pre-installed apps to…
ModificadaMedia (6.8)0.34%—Lenovo 20f1 FirmwareLenovo 20f2 FirmwareLenovo 20jq FirmwareLenovo 20jr Firmware+14419/8/201917/6/2026
A vulnerability was reported in various BIOS versions of older ThinkPad systems that could allow a user with administrative privileges or physical access the ability to update the Embedded Controller with unsigned firmware.
ModificadaAlta (8.8)1.6%—Epson Ds-570w FirmwareEpson Ds-780n FirmwareEpson Ep-10va FirmwareEpson Ep-30va Firmware+549/1/201917/6/2026
HTTP header injection vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A…
ModificadaMedia (6.1)0.98%—Epson Ds-570w FirmwareEpson Ds-780n FirmwareEpson Ep-10va FirmwareEpson Ep-30va Firmware+549/1/201917/6/2026
Open redirect vulnerability in SEIKO EPSON printers and scanners (DS-570W firmware versions released prior to 2018 March 13, DS-780N firmware versions released prior to 2018 March 13, EP-10VA firmware versions released prior to 2017 September 4, EP-30VA firmware versions released prior to 2017 June 19, EP-707A…
ModificadaCrítica (9.8)1.4%—Technicolor Tc7110.ar Firmware25/12/201817/6/2026
Technicolor TC7110.AR STD3.38.03 devices allow remote attackers to discover Wi-Fi credentials via iso.3.6.1.4.1.2863.205.10.1.30.4.1.14.1.3.32 and iso.3.6.1.4.1.2863.205.10.1.30.4.2.4.1.2.32 SNMP requests.
ModificadaCrítica (9.8)1.6%—Technicolor Cga0111 FirmwareTechnicolor Cga0101 FirmwareTechnicolor Dpc3928sl FirmwareTechnicolor Tc7110.ar Firmware+423/12/201817/6/2026
Technicolor CGA0111 CGA0111E-ES-13-E23E-c8000r5712-170217-0829-TRU, CWA0101 CWA0101E-A23E-c7000r5712-170315-SKC, DPC3928SL D3928SL-PSIP-13-A010-c3420r55105-170214a, TC7110.AR STD3.38.03, TC7110.B STC8.62.02, TC7110.D STDB.79.02, TC7200.d1I TC7200.d1IE-N23E-c7000r5712-170406-HAT, and TC7200.TH2v2 SC05.00.22 devices…
ModificadaAlta (7.8)11%—HP T8x44 FirmwareHP 3aw51a FirmwareHP A9u28b FirmwareHP D3a82a Firmware+26613/8/201817/6/2026
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a static buffer overflow, which could allow remote code execution.
ModificadaCrítica (9.8)12%—HP T8x44 FirmwareHP 3aw51a FirmwareHP A9u28b FirmwareHP D3a82a Firmware+26613/8/201817/6/2026
A security vulnerability has been identified with certain HP Inkjet printers. A maliciously crafted file sent to an affected device can cause a stack buffer overflow, which could allow remote code execution.
ModificadaAlta (7.2)4.4%—Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+19421/11/201717/6/2026
Buffer overflow in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allows attacker with remote Admin access to the system to execute arbitrary code with AMT execution privilege.
ModificadaAlta (7.8)0.56%—Intel Manageability Engine FirmwareIntel Active Management Technology FirmwareAsus Z170-premium FirmwareAsus Z170-deluxe Firmware+19421/11/201717/6/2026
Multiple buffer overflows in Active Management Technology (AMT) in Intel Manageability Engine Firmware 8.x/9.x/10.x/11.0/11.5/11.6/11.7/11.10/11.20 allow attacker with local access to the system to execute arbitrary code with AMT execution privilege.
ModificadaMedia (5.3)7.3%💥 PoCSiemens Apogee PXC FirmwareSiemens Apogee PXC Modular FirmwareSiemens Talon TC Compact FirmwareSiemens Talon TC Modular Firmware23/10/201717/6/2026
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. A directory traversal vulnerability could allow a remote attacker with network access to the integrated web server (80/tcp and 443/tcp) to obtain information on the structure of the file system…
ModificadaAlta (7.5)25%—Siemens Apogee PXC FirmwareSiemens Apogee PXC Modular FirmwareSiemens Talon TC Compact FirmwareSiemens Talon TC Modular Firmware23/10/201717/6/2026
A vulnerability has been identified in Siemens APOGEE PXC and TALON TC BACnet Automation Controllers in all versions <V3.5. An attacker with network access to the integrated web server (80/tcp and 443/tcp) could bypass the authentication and download sensitive information from the device.
ModificadaCrítica (9.8)1.6%—Dataprobe Ibootbar Firmware7/4/201716/6/2026
Dataprobe iBootBar (with 2007-09-20 and possibly later beta firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCCOOKIE cookie.
ModificadaCrítica (9.8)1.6%—Dataprobe Ibootbar Firmware7/4/201716/6/2026
Dataprobe iBootBar (with 2007-09-20 and possibly later released firmware) allows remote attackers to bypass authentication, and conduct power-cycle attacks on connected devices, via a DCRABBIT cookie.
ModificadaMedia (4.9)0.36%—Huawei Quidway S5300 FirmwareHuawei Quidway S9300 FirmwareHuawei S5700 FirmwareHuawei S12700 Firmware+33/10/201617/6/2026
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 makes it easier for…
ModificadaMedia (4.9)0.49%—Huawei S9300 FirmwareHuawei S12700 FirmwareHuawei Quidway S9300 FirmwareHuawei AR Firmware+33/10/201617/6/2026
Huawei AR routers with software before V200R007C00SPC100; Quidway S9300 routers with software before V200R009C00; S12700 routers with software before V200R008C00SPC500; S9300, Quidway S5300, and S5300 routers with software before V200R007C00; and S5700 routers with software before V200R007C00SPC500 make it easier for…
ModificadaMedia (6.5)0.99%—Huawei AR FirmwareHuawei Netengine 16ex Firmware26/9/201617/6/2026
Format string vulnerability in Huawei AR100, AR120, AR150, AR200, AR500, AR550, AR1200, AR2200, AR2500, AR3200, and AR3600 routers with software before V200R007C00SPC900 and NetEngine 16EX routers with software before V200R007C00SPC900 allows remote authenticated users to cause a denial of service via format string…
ModificadaMedia (4)1.1%—Huawei AR Firmware24/11/201517/6/2026
Directory traversal vulnerability in the SFTP server in Huawei AR 120, 150, 160, 200, 500, 1200, 2200, 3200, and 3600 routers with software before V200R006SPH003 allows remote authenticated users to access arbitrary directories via unspecified vectors.