Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2698▼ 542 respecto a la semana anterior
Críticas / altas1273▼ 220 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)254▼ 248 respecto a la semana anterior
–

264 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (5.9)0.87%—Ietf Public KEY Cryptography Standards #1Microchip Libraries FOR Applications19/1/20219/7/2026
Bleichenbacher's attack on PKCS #1 v1.5 padding for RSA in Microchip Libraries for Applications 2018-11-26 All up to 2018-11-26. The vulnerability can allow one to use Bleichenbacher's oracle attack to decrypt an encrypted ciphertext by making successive queries to the server using the vulnerable library, resulting in…
ModificadaCrítica (9.1)7.0%—Altran PicotcpMicrochip Mplab Harmony11/12/202017/6/2026
An issue was discovered in picoTCP 1.7.0. The code for processing the IPv6 headers does not validate whether the IPv6 payload length field is equal to the actual size of the payload, which leads to an Out-of-Bounds read during the ICMPv6 checksum calculation, resulting in either Denial-of-Service or Information…
ModificadaMedia (5.5)0.52%—Intel MicrocodeNetapp Clustered Data OntapNetapp HCI Compute Node BiosNetapp HCI Storage Node Bios+1312/11/202017/6/2026
Improper isolation of shared resources in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (5.5)0.44%—Intel MicrocodeNetapp Clustered Data OntapNetapp HCL Compute Node BiosNetapp HCI Storage Node Bios+312/11/202017/6/2026
Improper removal of sensitive information before storage or transfer in some Intel(R) Processors may allow an authenticated user to potentially enable information disclosure via local access.
ModificadaMedia (6.8)0.60%—Microchip Cryptoauthlib22/10/202017/6/2026
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 1 of 2).
ModificadaMedia (6.8)0.60%—Microchip Cryptoauthlib22/10/202017/6/2026
Microchip CryptoAuthentication Library CryptoAuthLib prior to 20191122 has a Buffer Overflow (issue 2 of 2).
ModificadaCrítica (9.1)2.0%—Microchip Advanced Software Framework 422/10/202017/6/2026
Atmel Advanced Software Framework (ASF) 4 has an Integer Overflow.
ModificadaAlta (7.5)1.2%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
The Secure Monitor in Microchip Atmel ATSAMA5 products use a hardcoded key to encrypt and authenticate secure applets.
ModificadaAlta (7.5)1.3%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
CMAC verification functionality in Microchip Atmel ATSAMA5 products is vulnerable to vulnerable to timing and power analysis attacks.
ModificadaAlta (7.5)1.2%—Microchip Atsama5d21c-cu FirmwareMicrochip Atsama5d21c-cur FirmwareMicrochip Atsama5d22c-cn FirmwareMicrochip Atsama5d22c-cnr Firmware+7214/9/202017/6/2026
Microchip Atmel ATSAMA5 products in Secure Mode allow an attacker to bypass existing security mechanisms related to applet handling.
ModificadaAlta (7.1)2.3%—Gnome Libcroco12/5/202017/6/2026
libcroco through 0.6.13 has excessive recursion in cr_parser_parse_any_core in cr-parser.c, leading to stack consumption.
ModificadaMedia (6.5)1.3%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to authlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to kernlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to daemonlog.php.
ModificadaMedia (6.5)1.1%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to the syslog.php.
ModificadaMedia (6.5)1.2%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow Directory Traversal via the FileName parameter to messagelog.php.
ModificadaMedia (6.1)0.67%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices allow stored XSS via the newUserName parameter on the "User Creation, Deletion and Password Maintenance" screen (when creating a new user).
ModificadaAlta (7.5)0.91%—Microchip Syncserver S100 FirmwareMicrochip Syncserver S200 FirmwareMicrochip Syncserver S250 FirmwareMicrochip Syncserver S300 Firmware+117/2/202017/6/2026
Symmetricom SyncServer S100 2.90.70.3, S200 1.30, S250 1.25, S300 2.65.0, and S350 2.80.1 devices mishandle session validation, leading to unauthenticated creation, modification, or elimination of users.
ModificadaMedia (6.5)0.70%—Microchip Atmsamb11 Blusdk Smart10/2/202017/6/2026
The Bluetooth Low Energy implementation on Microchip Technology BluSDK Smart through 6.2 for ATSAMB11 devices does not properly restrict link-layer data length on reception, allowing attackers in radio range to cause a denial of service (crash) via a crafted packet.
ModificadaMedia (4.7)0.47%—Microchip Atmel ToolboxAthena-scs IdprotectCryptsoft S/A Idflex VTecsec Armored Card+13/10/201917/6/2026
Smart cards from the Athena SCS manufacturer, based on the Atmel Toolbox 00.03.11.05 and the AT90SC chip, contain a timing side channel in ECDSA signature generation. This allows a local attacker, able to measure the duration of hundreds to thousands of signing operations, to compute the private key used. The issue…
ModificadaCrítica (9.8)71%💥 ExploitBelkin Crock-pot Smart Slow Cooker With Wemo Firmware10/6/201917/6/2026
The Belkin Wemo Enabled Crock-Pot allows command injection in the Wemo UPnP API via the SmartDevURL argument to the SetSmartDevInfo action. A simple POST request to /upnp/control/basicevent1 can allow an attacker to execute commands without authentication.
ModificadaMedia (6.5)13%💥 ExploitGnome LibcrocoOpensuse Leap12/6/201717/6/2026
The cr_parser_parse_selector_core function in cr-parser.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (infinite loop and CPU consumption) via a crafted CSS file.
ModificadaMedia (6.5)3.8%—Gnome LibcrocoOpensuse Leap12/6/201717/6/2026
The cr_tknzr_parse_comment function in cr-tknzr.c in libcroco 0.6.12 allows remote attackers to cause a denial of service (memory allocation error) via a crafted CSS file.
ModificadaAlta (7.8)2.0%—Gnome Libcroco19/4/201717/6/2026
The cr_tknzr_parse_rgb function in cr-tknzr.c in libcroco 0.6.11 and 0.6.12 has an "outside the range of representable values of type long" undefined behavior issue, which might allow remote attackers to cause a denial of service (application crash) or possibly have unspecified other impact via a crafted CSS file.…
ModificadaMedia (5.5)2.0%—Gnome Libcroco19/4/201717/6/2026
The cr_input_new_from_uri function in cr-input.c in libcroco 0.6.11 and 0.6.12 allows remote attackers to cause a denial of service (heap-based buffer over-read) via a crafted CSS file.
Orbitaley — Vulnerabilidades